Exploitation timeline
Threadlinqs has recorded 36 Red Hat CVEs published between and . The busiest month was 2026-09 (10 new CVEs). 8 of them (22%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 36 of 36 tracked Red Hat CVEs.
- CVE-2014-6271critical 9.8KEVEPSS 100%
- CVE-2017-8291high 7.8KEVEPSS 97%
- CVE-2016-5195high 7KEVRansomwareEPSS 93.9%
- CVE-2016-4437critical 9.8KEVEPSS 93.1%
- CVE-2022-0847high 7.8KEVEPSS 92.8%
- CVE-2021-4034high 7.8KEVEPSS 87.8%
- CVE-2023-4911high 7.8KEVEPSS 81.4%
- CVE-2023-32373high 8.8KEVEPSS 0%
- CVE-2024-6387high 8.1EPSS 99.5%
- CVE-2026-75887high 7.5EPSS 0.4%
- CVE-2026-86344high 7.5EPSS 0.3%
- CVE-2026-71473high 8.5EPSS 0.3%
- CVE-2026-17059medium 6.5EPSS 0.2%
- CVE-2026-12515medium 4.3EPSS 0.2%
- CVE-2025-11395medium 5.5EPSS 0.2%
- CVE-2026-92248high 7.8EPSS 0.2%
- CVE-2026-7867high 7.8EPSS 0.2%
- CVE-2026-18090medium 6.1EPSS 0.2%
- CVE-2026-71846medium 6.5EPSS 0.1%
- CVE-2026-81893medium 4.7EPSS 0.1%
- CVE-2026-86564low 3.3EPSS 0.1%
- CVE-2026-80158medium 5.5EPSS 0.1%
- CVE-2026-16517low 2.9EPSS 0.1%
- CVE-2026-4480high 8.5EPSS 0.1%
- CVE-2026-56208high 7.6
- CVE-2026-96280high 7.5
- CVE-2026-3195high 7.4
- CVE-2026-56209high 7.1
- CVE-2026-56210high 7.1
- CVE-2026-56211high 7.1
- CVE-2026-96281medium 6.2
- CVE-2026-3196medium 5.5
- CVE-2026-6426medium 4.4
- CVE-2026-96283low 3.3
- CVE-2026-96282low 3.1
- CVE-2026-96284low 2.5
Products affected
Threadlinqs normalises CPE and CNA product records across all 36 CVEs; 66 distinct Red Hat products are affected. The most frequently affected (top 20):
- Enterprise Linux 9 23 CVEs
- Enterprise Linux 10 22 CVEs
- Enterprise Linux 8 18 CVEs
- Enterprise Linux 7 16 CVEs
- Enterprise Linux 6 11 CVEs
- OpenShift Container Platform 4 8 CVEs
- Hardened Images 7 CVEs
- Enterprise Linux 5 CVEs
- Enterprise Linux Eus 5 CVEs
- Enterprise Linux AI (RHEL AI) 3 4 CVEs
- Enterprise Linux Desktop 3 CVEs
- Enterprise Linux For Ibm Z Systems 3 CVEs
- Enterprise Linux Server Aus 3 CVEs
- Enterprise Linux Server Tus 3 CVEs
- Advanced Cluster Management for Kubernetes 2 2 CVEs
- Ceph Storage 5 2 CVEs
- Enterprise Linux For Ibm Z Systems Eus 2 CVEs
- Enterprise Linux For Power Little Endian 2 CVEs
- Enterprise Linux For Power Little Endian Eus 2 CVEs
- Enterprise Linux Server 2 CVEs
Threat activity
51 tracked threat campaigns reference Red Hat products or exploit Red Hat CVEs; the 25 most recent are listed.
- Red Hat Satellite Foreman template preview authorization flaw (CVE-2026-96659) enables root password theft and code executionCRITICAL
- Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals 600K+ Payment Cards and Injects Skimmers into 100+ E-Commerce SitesCRITICAL
- Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti UniFi OS Flaws to Steal Government DataCRITICAL
- CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables SNAT Privilege Escalation, and AF_ALG Race Condition (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964)CRITICAL
- CVE-2025-39682 — Linux Kernel net/tls rx_list Zero-Length Record Use-After-Free Added to CISA KEV CatalogCRITICAL
- Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)HIGH
- Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage CampaignHIGH
- BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware SuiteCRITICAL
- EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign Adopted by Criminal, North Korean, and Iran-Linked ActorsHIGH
- CVE-2026-53362 ("ipv6_frag_escape"): Linux Kernel IPv6 Fragmentation Flaw Enables Container-to-Host Privilege Escalation, Actively Exploited — Added to CISA KEVHIGH
- Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web serversHIGH
- PATCHCORD, SHEETCORD & HACKERAI C2 Agent: New Malware Cluster Targets Afghan Telecom and South Asian Critical Infrastructure (APT36-linked)HIGH
- Larva-26005 APT Campaign: Xctdoor and CRAT Backdoors Targeting South Korea (2020–2026)CRITICAL
- CVE-2026-64561 — Zapscape: KVM/x86 Shadow MMU Use-After-Free Allows L1 Guest Escape to Linux HostHIGH
- CVE-2026-34486: Apache Tomcat EncryptInterceptor Bypass Actively Exploited in SnowLight and AI-Assisted CampaignsHIGH
- OVSWrap (CVE-2026-64531): Linux kernel Open vSwitch datapath 16-bit nla_len wraparound local privilege escalation with public PoC targeting ~800 x86-64 kernel buildsHIGH
- CVE-2026-31431: Linux Local Privilege Escalation Actively Exploited by UMBRAL BISON Within 24 Hours of DisclosureHIGH
- CVE-2026-17059: Keycloak Admin REST API Broken Object-Level Authorization Exposes User PIIMEDIUM
- CVE-2026-53264: AI-Assisted Discovery of Linux Kernel net/sched Use-After-Free Enabling Local Root Privilege EscalationHIGH
- RefluXFS: Linux Kernel XFS Copy-on-Write Race Condition Local Privilege Escalation (CVE-2026-64600)HIGH
- Pwn2Own Berlin 2026 Day Three: Zero-Days Demonstrated in VMware ESXi, Microsoft SharePoint, Windows 11, Red Hat Linux, and Anthropic Claude CodeHIGH
- F5OS / Traffix SDC Information Disclosure (CVE-2026-46333) — Linux Kernel ptrace/pidfd_getfd Race Condition, Public PoC (CHARON)HIGH
- CVE-2026-46215: Linux Kernel DRM GEM_CHANGE_HANDLE Use-After-Free Local Root Privilege EscalationHIGH
- Forgotten UEFI Shims Undermine Secure Boot (CVE-2026-8863, CVE-2026-10797)HIGH
- 11-Year-Old Linux UEFI Shim Bootloader Flaws Enable Secure Boot Bypass (CVE-2026-8863, CVE-2026-10797)HIGH
Threat actors targeting Red Hat
Named threat actors attributed to campaigns that involve Red Hat products or CVEs, with the number of linked campaigns:
How to prioritise Red Hat patching
This order follows the data Threadlinqs holds for Red Hat, not a generic severity checklist:
- 8 of 36 Red Hat CVEs (22%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2014-6271, CVE-2017-8291, CVE-2016-5195.
- 1 CVE is known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are CVE-2024-6387 (99.5%), CVE-2026-75887 (0.4%), CVE-2026-86344 (0.3%).
- 2 CVEs score Critical and 19 High on CVSS v3 (maximum 9.8, average 6.6); sequence these after KEV and high-EPSS items.
- 8 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.