Skip to main content
Mallory
Back to stories
widely-deployed-product-advisoryopen-source-dependency-vulnerability

Multiple Vulnerabilities Disclosed in Red Hat Hardened Images RPMs

Updated 12d agoFirst seen Apr 22, 20265 sources

dCERT issued advisories for multiple vulnerabilities affecting Red Hat Hardened Images RPMs, identifying the issue in notices 2026-1205 and 2026-1246. The advisories indicate that security flaws were found in RPM packages used within Red Hat hardened container images, potentially exposing systems that rely on those images to a range of risks depending on the affected packages and deployed workloads.

The publication of two separate dCERT notices suggests ongoing or updated vendor guidance around the same product area, and organizations using Red Hat hardened images should review the referenced advisories, determine which RPMs and image versions are affected, and prioritize remediation through updated packages or rebuilt images. Security teams should also verify downstream dependencies in container registries and production environments to ensure vulnerable image layers are replaced.

Share:
Multiple Vulnerabilities Disclosed in Red Hat Hardened Images RPMs
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the earliest known activity through the most recent confirmed update.

5 EVENTS
Apr 22, 202626d ago

dCERT publishes advisory 2026-1205 on Red Hat Hardened Images RPM vulnerabilities

dCERT issued advisory 2026-1205 concerning multiple vulnerabilities affecting Red Hat Hardened Images RPMs. No additional technical details or remediation information are provided in the reference.

Apr 27, 202621d ago

dCERT publishes follow-up advisory 2026-1246 on the same Red Hat RPM issues

dCERT later published advisory 2026-1246 covering multiple vulnerabilities in Red Hat Hardened Images RPMs, indicating a subsequent update or additional notice on the same issue set. The reference does not include further specifics on the vulnerabilities or fixes.

Apr 28, 202620d ago

dCERT publishes advisory 2026-1264 on libxslt DoS flaws in Red Hat RPMs

dCERT published advisory 2026-1264 covering multiple vulnerabilities in Red Hat Hardened Images RPMs related to libxslt. The advisory states the flaws could allow denial of service, adding new technical specificity to the ongoing issue.

dCERT - Advisory 2026-1264 - Red Hat Hardened Images RPMs (libxslt): Multiple Vulnerabilities allow Denial of Service
May 4, 202614d ago

dCERT publishes advisory 2026-1307 on Red Hat Hardened Images RPM vulnerabilities

dCERT published advisory 2026-1307 covering multiple vulnerabilities affecting Red Hat Hardened Images RPMs. The reference provides no additional synopsis or remediation details beyond identifying it as a new advisory in the ongoing issue set.

dCERT - Advisory 2026-1307 - Red Hat Hardened Images RPMs: Multiple Vulnerabilities
May 6, 202612d ago

dCERT publishes advisory 2026-1343 on fontconfig flaws in Red Hat RPMs

dCERT published advisory 2026-1343 covering vulnerabilities in Red Hat Hardened Images RPMs related to fontconfig. The advisory indicates the flaws could allow code execution or denial of service, adding new technical detail to the ongoing issue set.

dCERT - Advisory 2026-1343 - Red Hat Hardened Images RPMs (fontconfig): Vulnerability allows code execution or DoS
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

2 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Multiple Vulnerabilities Disclosed in Red Hat Hardened Images RPMs | Mallory