# Red Hat vulnerabilities & exploitation

**CISA KEV** · **Ransomware**

> As of 2026-10-05, Threadlinqs tracks 36 Red Hat CVEs, 8 in the CISA Known Exploited Vulnerabilities catalog, 1 used in ransomware campaigns, linked to 51 tracked threat campaigns and 12 named threat actors.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 36 Red Hat CVEs published between 2014-09-15 and 2026-10-15. The busiest month was 2026-09 (10 new CVEs). 8 of them (22%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 36 of 36 tracked Red Hat CVEs.

- [CVE-2014-6271](https://intel.threadlinqs.com/cve/CVE-2014-6271) — CRITICAL 9.8 · KEV · EPSS 100% · 2014-09-24
- [CVE-2017-8291](https://intel.threadlinqs.com/cve/CVE-2017-8291) — HIGH 7.8 · KEV · EPSS 97% · 2017-04-27
- [CVE-2016-5195](https://intel.threadlinqs.com/cve/CVE-2016-5195) — HIGH 7 · KEV · Ransomware · EPSS 93.9% · 2016-11-10
- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437) — CRITICAL 9.8 · KEV · EPSS 93.1% · 2016-06-07
- [CVE-2022-0847](https://intel.threadlinqs.com/cve/CVE-2022-0847) — HIGH 7.8 · KEV · EPSS 92.8% · 2022-03-07
- [CVE-2021-4034](https://intel.threadlinqs.com/cve/CVE-2021-4034) — HIGH 7.8 · KEV · EPSS 87.8% · 2022-01-28
- [CVE-2023-4911](https://intel.threadlinqs.com/cve/CVE-2023-4911) — HIGH 7.8 · KEV · EPSS 81.4% · 2023-10-03
- [CVE-2023-32373](https://intel.threadlinqs.com/cve/CVE-2023-32373) — HIGH 8.8 · KEV · EPSS 0% · 2023-06-23
- [CVE-2024-6387](https://intel.threadlinqs.com/cve/CVE-2024-6387) — HIGH 8.1 · EPSS 99.5% · 2024-07-01
- [CVE-2026-75887](https://intel.threadlinqs.com/cve/CVE-2026-75887) — HIGH 7.5 · EPSS 0.4% · 2026-09-23
- [CVE-2026-86344](https://intel.threadlinqs.com/cve/CVE-2026-86344) — HIGH 7.5 · EPSS 0.3% · 2026-10-01
- [CVE-2026-71473](https://intel.threadlinqs.com/cve/CVE-2026-71473) — HIGH 8.5 · EPSS 0.3% · 2026-08-12
- [CVE-2026-17059](https://intel.threadlinqs.com/cve/CVE-2026-17059) — MEDIUM 6.5 · EPSS 0.2% · 2026-07-24
- [CVE-2026-12515](https://intel.threadlinqs.com/cve/CVE-2026-12515) — MEDIUM 4.3 · EPSS 0.2% · 2026-06-17
- [CVE-2025-11395](https://intel.threadlinqs.com/cve/CVE-2025-11395) — MEDIUM 5.5 · EPSS 0.2% · 2026-09-15
- [CVE-2026-92248](https://intel.threadlinqs.com/cve/CVE-2026-92248) — HIGH 7.8 · EPSS 0.2% · 2026-09-15
- [CVE-2026-7867](https://intel.threadlinqs.com/cve/CVE-2026-7867) — HIGH 7.8 · EPSS 0.2% · 2026-08-06
- [CVE-2026-18090](https://intel.threadlinqs.com/cve/CVE-2026-18090) — MEDIUM 6.1 · EPSS 0.2% · 2026-09-08
- [CVE-2026-71846](https://intel.threadlinqs.com/cve/CVE-2026-71846) — MEDIUM 6.5 · EPSS 0.1% · 2026-08-12
- [CVE-2026-81893](https://intel.threadlinqs.com/cve/CVE-2026-81893) — MEDIUM 4.7 · EPSS 0.1% · 2026-08-27
- [CVE-2026-86564](https://intel.threadlinqs.com/cve/CVE-2026-86564) — LOW 3.3 · EPSS 0.1% · 2026-09-08
- [CVE-2026-80158](https://intel.threadlinqs.com/cve/CVE-2026-80158) — MEDIUM 5.5 · EPSS 0.1% · 2026-08-26
- [CVE-2026-16517](https://intel.threadlinqs.com/cve/CVE-2026-16517) — LOW 2.9 · EPSS 0.1% · 2026-07-21
- [CVE-2026-4480](https://intel.threadlinqs.com/cve/CVE-2026-4480) — HIGH 8.5 · EPSS 0.1% · 2026-05-26
- [CVE-2026-56208](https://intel.threadlinqs.com/cve/CVE-2026-56208) — HIGH 7.6 · 2026-06-19
- [CVE-2026-96280](https://intel.threadlinqs.com/cve/CVE-2026-96280) — HIGH 7.5 · 2026-09-27
- [CVE-2026-3195](https://intel.threadlinqs.com/cve/CVE-2026-3195) — HIGH 7.4 · 2026-06-19
- [CVE-2026-56209](https://intel.threadlinqs.com/cve/CVE-2026-56209) — HIGH 7.1 · 2026-06-19
- [CVE-2026-56210](https://intel.threadlinqs.com/cve/CVE-2026-56210) — HIGH 7.1 · 2026-06-19
- [CVE-2026-56211](https://intel.threadlinqs.com/cve/CVE-2026-56211) — HIGH 7.1 · 2026-06-19
- [CVE-2026-96281](https://intel.threadlinqs.com/cve/CVE-2026-96281) — MEDIUM 6.2 · 2026-09-27
- [CVE-2026-3196](https://intel.threadlinqs.com/cve/CVE-2026-3196) — MEDIUM 5.5 · 2026-06-19
- [CVE-2026-6426](https://intel.threadlinqs.com/cve/CVE-2026-6426) — MEDIUM 4.4 · 2026-08-10
- [CVE-2026-96283](https://intel.threadlinqs.com/cve/CVE-2026-96283) — LOW 3.3 · 2026-09-27
- [CVE-2026-96282](https://intel.threadlinqs.com/cve/CVE-2026-96282) — LOW 3.1 · 2026-09-27
- [CVE-2026-96284](https://intel.threadlinqs.com/cve/CVE-2026-96284) — LOW 2.5 · 2026-09-27

## Products affected

Threadlinqs normalises CPE and CNA product records across all 36 CVEs; 66 distinct Red Hat products are affected. The most frequently affected (top 20):

- Enterprise Linux 9 — 23 CVEs
- Enterprise Linux 10 — 22 CVEs
- Enterprise Linux 8 — 18 CVEs
- Enterprise Linux 7 — 16 CVEs
- Enterprise Linux 6 — 11 CVEs
- OpenShift Container Platform 4 — 8 CVEs
- Hardened Images — 7 CVEs
- Enterprise Linux — 5 CVEs
- Enterprise Linux Eus — 5 CVEs
- Enterprise Linux AI (RHEL AI) 3 — 4 CVEs
- Enterprise Linux Desktop — 3 CVEs
- Enterprise Linux For Ibm Z Systems — 3 CVEs
- Enterprise Linux Server Aus — 3 CVEs
- Enterprise Linux Server Tus — 3 CVEs
- Advanced Cluster Management for Kubernetes 2 — 2 CVEs
- Ceph Storage 5 — 2 CVEs
- Enterprise Linux For Ibm Z Systems Eus — 2 CVEs
- Enterprise Linux For Power Little Endian — 2 CVEs
- Enterprise Linux For Power Little Endian Eus — 2 CVEs
- Enterprise Linux Server — 2 CVEs

## Threat activity

51 tracked threat campaigns reference Red Hat products or exploit Red Hat CVEs; the 25 most recent are listed.

- [Red Hat Satellite Foreman template preview authorization flaw (CVE-2026-96659) enables root password theft and code execution](https://intel.threadlinqs.com/threat/TL-2026-2874) — CRITICAL — 2026-10-03
- [Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals 600K+ Payment Cards and Injects Skimmers into 100+ E-Commerce Sites](https://intel.threadlinqs.com/threat/TL-2026-2633) — CRITICAL — 2026-09-23
- [Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti UniFi OS Flaws to Steal Government Data](https://intel.threadlinqs.com/threat/TL-2026-2619) — CRITICAL — 2026-09-22
- [CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables SNAT Privilege Escalation, and AF_ALG Race Condition (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964)](https://intel.threadlinqs.com/threat/TL-2026-2582) — CRITICAL — 2026-09-19
- [CVE-2025-39682 — Linux Kernel net/tls rx_list Zero-Length Record Use-After-Free Added to CISA KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2570) — CRITICAL — 2026-09-18
- [Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)](https://intel.threadlinqs.com/threat/TL-2026-2514) — HIGH — 2026-09-15
- [Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage Campaign](https://intel.threadlinqs.com/threat/TL-2026-2325) — HIGH — 2026-09-04
- [BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suite](https://intel.threadlinqs.com/threat/TL-2026-2266) — CRITICAL — 2026-09-01
- [EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign Adopted by Criminal, North Korean, and Iran-Linked Actors](https://intel.threadlinqs.com/threat/TL-2026-2273) — HIGH — 2026-09-01
- [CVE-2026-53362 ("ipv6_frag_escape"): Linux Kernel IPv6 Fragmentation Flaw Enables Container-to-Host Privilege Escalation, Actively Exploited — Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-2220) — HIGH — 2026-08-29
- [Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web servers](https://intel.threadlinqs.com/threat/TL-2026-2096) — HIGH — 2026-08-21
- [PATCHCORD, SHEETCORD & HACKERAI C2 Agent: New Malware Cluster Targets Afghan Telecom and South Asian Critical Infrastructure (APT36-linked)](https://intel.threadlinqs.com/threat/TL-2026-2006) — HIGH — 2026-08-13
- [Larva-26005 APT Campaign: Xctdoor and CRAT Backdoors Targeting South Korea (2020–2026)](https://intel.threadlinqs.com/threat/TL-2026-1908) — CRITICAL — 2026-08-06
- [CVE-2026-64561 — Zapscape: KVM/x86 Shadow MMU Use-After-Free Allows L1 Guest Escape to Linux Host](https://intel.threadlinqs.com/threat/TL-2026-1919) — HIGH — 2026-08-06
- [CVE-2026-34486: Apache Tomcat EncryptInterceptor Bypass Actively Exploited in SnowLight and AI-Assisted Campaigns](https://intel.threadlinqs.com/threat/TL-2026-1885) — HIGH — 2026-08-05
- [OVSWrap (CVE-2026-64531): Linux kernel Open vSwitch datapath 16-bit nla_len wraparound local privilege escalation with public PoC targeting ~800 x86-64 kernel builds](https://intel.threadlinqs.com/threat/TL-2026-1887) — HIGH — 2026-08-05
- [CVE-2026-31431: Linux Local Privilege Escalation Actively Exploited by UMBRAL BISON Within 24 Hours of Disclosure](https://intel.threadlinqs.com/threat/TL-2026-1831) — HIGH — 2026-08-03
- [CVE-2026-17059: Keycloak Admin REST API Broken Object-Level Authorization Exposes User PII](https://intel.threadlinqs.com/threat/TL-2026-1796) — MEDIUM — 2026-07-31
- [CVE-2026-53264: AI-Assisted Discovery of Linux Kernel net/sched Use-After-Free Enabling Local Root Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-1744) — HIGH — 2026-07-28
- [RefluXFS: Linux Kernel XFS Copy-on-Write Race Condition Local Privilege Escalation (CVE-2026-64600)](https://intel.threadlinqs.com/threat/TL-2026-1629) — HIGH — 2026-07-22
- [Pwn2Own Berlin 2026 Day Three: Zero-Days Demonstrated in VMware ESXi, Microsoft SharePoint, Windows 11, Red Hat Linux, and Anthropic Claude Code](https://intel.threadlinqs.com/threat/TL-2026-1546) — HIGH — 2026-07-19
- [F5OS / Traffix SDC Information Disclosure (CVE-2026-46333) — Linux Kernel ptrace/pidfd_getfd Race Condition, Public PoC (CHARON)](https://intel.threadlinqs.com/threat/TL-2026-1503) — HIGH — 2026-07-18
- [CVE-2026-46215: Linux Kernel DRM GEM_CHANGE_HANDLE Use-After-Free Local Root Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-1504) — HIGH — 2026-07-18
- [Forgotten UEFI Shims Undermine Secure Boot (CVE-2026-8863, CVE-2026-10797)](https://intel.threadlinqs.com/threat/TL-2026-1298) — HIGH — 2026-07-14
- [11-Year-Old Linux UEFI Shim Bootloader Flaws Enable Secure Boot Bypass (CVE-2026-8863, CVE-2026-10797)](https://intel.threadlinqs.com/threat/TL-2026-1340) — HIGH — 2026-07-14

## Threat actors targeting Red Hat

Named threat actors attributed to campaigns that involve Red Hat products or CVEs, with the number of linked campaigns:

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 3 campaigns
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 2 campaigns
- [StrikeShark](https://intel.threadlinqs.com/actor/StrikeShark) — 2 campaigns
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 1 campaign
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1 campaign
- [Kapibala](https://intel.threadlinqs.com/actor/Kapibala) — 1 campaign
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 1 campaign
- [Miasma operator](https://intel.threadlinqs.com/actor/Miasma%20operator) — 1 campaign
- [Mini Shai-Hulud](https://intel.threadlinqs.com/actor/Mini%20Shai-Hulud) — 1 campaign
- [PCPJack](https://intel.threadlinqs.com/actor/PCPJack) — 1 campaign
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 1 campaign
- [Shai-Hulud](https://intel.threadlinqs.com/actor/Shai-Hulud) — 1 campaign

## How to prioritise Red Hat patching

This order follows the data Threadlinqs holds for Red Hat, not a generic severity checklist:

- 8 of 36 Red Hat CVEs (22%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2014-6271](https://intel.threadlinqs.com/cve/CVE-2014-6271), [CVE-2017-8291](https://intel.threadlinqs.com/cve/CVE-2017-8291), [CVE-2016-5195](https://intel.threadlinqs.com/cve/CVE-2016-5195).
- 1 CVE is known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are [CVE-2024-6387](https://intel.threadlinqs.com/cve/CVE-2024-6387) (99.5%), [CVE-2026-75887](https://intel.threadlinqs.com/cve/CVE-2026-75887) (0.4%), [CVE-2026-86344](https://intel.threadlinqs.com/cve/CVE-2026-86344) (0.3%).
- 2 CVEs score Critical and 19 High on CVSS v3 (maximum 9.8, average 6.6); sequence these after KEV and high-EPSS items.
- 8 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/red-hat
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
