Redhat vendor intelligence

Redhat Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Redhat products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse KEVs Full KEV feed
Total KEVs
1
Known exploited vulnerability affecting Redhat products
In CISA KEV
1
Records also listed in the official catalog
Beyond CISA KEV
0
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
Redhat KEVs with sensor-observed exploitation activity

Review Redhat exploitation against the products you run

Review exploited Redhat vulnerabilities against the products you run. CISA KEV coverage is shown below.

100%
Covered by CISA
0%
Beyond CISA
1
Product families

Attested Redhat vulnerabilities

1 known exploited vulnerability in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2015-3246

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which...

libuser Confirmed In CISA 26 Aug 2026

Showing 1 of 1 on this page (1 Redhat known exploited vulnerability).

Recurring weakness patterns

Permissions, privileges, and access controls and time-of-check time-of-use (toctou) race condition account for two mapped occurrences across this Redhat KEV portfolio.

Browse all KEVs →