CVE-2026-79655 – Red Hat Enterprise Linux 10

CVSS 7.8 IMPORTANT Zero Day – Immediate Deployment

“This update closes paths to domain privilege escalation, arbitrary code execution, credential theft, and root-level file overwrite.”

Red Hat Enterprise Linux 10 is affected by one Critical and seven High-severity vulnerabilities across FreeIPA, NetworkManager, RPM, sos, Emacs TRAMP, BlueZ, and libvirt. CVE-2026-11861 can let an authenticated Active Directory user bypass FreeIPA trust protections and escalate privileges inside the FreeIPA domain. The CVSS score is 9.6, which is Critical severity. CVE-2026-13097 can enable Kerberos service impersonation and potentially full domain compromise; its CVSS score is 8.7, High severity.

The remaining High-severity issues include WPA-Enterprise credential theft, arbitrary code execution during RPM build processing, root-context file creation or overwrite through sos clean, local shell command execution in Emacs TRAMP, Bluetooth-triggered memory corruption, and libvirt heap corruption. CVE-2026-19685 scores 7.1; CVE-2026-78367 scores 7.0; CVE-2026-79655, CVE-2026-79992, and CVE-2026-18917 each score 7.8; and CVE-2026-80186 scores 7.6. Public proof-of-concept material is available for CVE-2026-78367 and CVE-2026-79655.

Key Details

Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
CWE Classification
CWE-59
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.