Vendor

Red Hat

As of , 9 Red Hat vulnerabilities are on CISA's list of exploited vulnerabilities, 4 of them used in ransomware campaigns; 2 were added in 2026. Patch first: CVE-2010-0738.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2010-0738Authentication BypassRed Hat JBossPatch this weekRansomware use; Metasploit module; EPSS 0.80; verified Exploit-DB entry0.80
2CVE-2010-1871Linux JBoss Seam 2 Remote Code ExecutionRed Hat JBoss Seam 2Patch this weekMetasploit module; EPSS 0.83; verified Exploit-DB entry0.83
3CVE-2021-3560Incorrect AuthorizationRed Hat PolkitPatch this weekMetasploit module; verified Exploit-DB entry0.24
4CVE-2015-3246Race ConditionRed Hat LibuserPatch this weekMetasploit module; verified Exploit-DB entry0.08
5CVE-2015-5287Privilege EscalationRed Hat Automatic Bug Reporting ToolPatch this weekMetasploit module; verified Exploit-DB entry0.05
6CVE-2021-4034Out-of-Bounds Read and WriteRed Hat PolkitPatch this weekRansomware use; Metasploit module; EPSS 0.940.94
7CVE-2010-1428Information DisclosureRed Hat JBossPatch this weekRansomware use; Metasploit module; EPSS 0.610.61
8CVE-2017-12149Remote Code ExecutionRed Hat JBoss Application ServerPatch this weekRansomware use; Metasploit module; EPSS 0.910.91
9CVE-2018-14667Expression Language InjectionRed Hat JBoss RichFaces FrameworkPatch this weekEPSS 0.740.74

Products

  • JBoss2 entries
  • Polkit2 entries
  • Automatic Bug Reporting Tool1 entry
  • JBoss Application Server1 entry
  • JBoss RichFaces Framework1 entry
  • JBoss Seam 21 entry
  • Libuser1 entry

Added each year

1232021: 2220212022: 3320222023: 2220232024: nonenone20242025: nonenone20252026: 222026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20212
20223
20232
2024none
2025none
20262

Used in ransomware

Changes CISA made to these entries

  1. CVE-2021-4034 Red Hat PolkitRansomware use: Unknown to Known.

Every change we recorded