Vendor
Red Hat
As of , 9 Red Hat vulnerabilities are on CISA's list of exploited vulnerabilities, 4 of them used in ransomware campaigns; 2 were added in 2026. Patch first: CVE-2010-0738.
Patch first
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2010-0738Authentication Bypass | Red Hat JBoss | Patch this weekRansomware use; Metasploit module; EPSS 0.80; verified Exploit-DB entry | 0.80 | ||
| 2 | CVE-2010-1871Linux JBoss Seam 2 Remote Code Execution | Red Hat JBoss Seam 2 | Patch this weekMetasploit module; EPSS 0.83; verified Exploit-DB entry | 0.83 | ||
| 3 | CVE-2021-3560Incorrect Authorization | Red Hat Polkit | Patch this weekMetasploit module; verified Exploit-DB entry | 0.24 | ||
| 4 | CVE-2015-3246Race Condition | Red Hat Libuser | Patch this weekMetasploit module; verified Exploit-DB entry | 0.08 | ||
| 5 | CVE-2015-5287Privilege Escalation | Red Hat Automatic Bug Reporting Tool | Patch this weekMetasploit module; verified Exploit-DB entry | 0.05 | ||
| 6 | CVE-2021-4034Out-of-Bounds Read and Write | Red Hat Polkit | Patch this weekRansomware use; Metasploit module; EPSS 0.94 | 0.94 | ||
| 7 | CVE-2010-1428Information Disclosure | Red Hat JBoss | Patch this weekRansomware use; Metasploit module; EPSS 0.61 | 0.61 | ||
| 8 | CVE-2017-12149Remote Code Execution | Red Hat JBoss Application Server | Patch this weekRansomware use; Metasploit module; EPSS 0.91 | 0.91 | ||
| 9 | CVE-2018-14667Expression Language Injection | Red Hat JBoss RichFaces Framework | Patch this weekEPSS 0.74 | 0.74 |
Products
- JBoss2 entries
- Polkit2 entries
- Automatic Bug Reporting Tool1 entry
- JBoss Application Server1 entry
- JBoss RichFaces Framework1 entry
- JBoss Seam 21 entry
- Libuser1 entry
Added each year
Show the numbers
| Period | entries added |
|---|---|
| 2021 | 2 |
| 2022 | 3 |
| 2023 | 2 |
| 2024 | none |
| 2025 | none |
| 2026 | 2 |