CVE-2026-15709 – Red Hat Enterprise Linux 10

CVSS 7.5 IMPORTANT Zero Day – Immediate Deployment

“These flaws can break sandbox boundaries, crash exposed services, and corrupt critical system memory.”

Red Hat has released updates for five High-severity vulnerabilities affecting Red Hat Enterprise Linux 10. The fixes address a PipeWire sandbox escape, two remotely triggered libsoup denial-of-service flaws, an xdgmime heap buffer overflow, and a QEMU out-of-bounds write. Potential impacts include code execution outside a sandbox, service disruption, memory corruption, information disclosure, and privilege escalation.

CVE-2026-5674 has a CVSS score of 8.8, High severity. CVE-2026-15709 has a CVSS score of 7.5, High severity. CVE-2026-15711 has a CVSS score of 7.5, High severity. CVE-2026-16118 has a CVSS score of 7.1, High severity. CVE-2026-3842 has a CVSS score of 7.8, High severity. Public proof-of-concept code is identified for the two libsoup WebSocket denial-of-service vulnerabilities.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-409
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.