RHSA-2026:2995HighCVSS 9.8

Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.62 SP3 security update

Published
February 23, 2026
Last Modified
July 8, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2025-9230 — openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap CVE-2025-15467 — openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing CVE-2025-55753 — mod_md: Apache HTTP Server: mod_md (ACME), unintended retry intervals CVE-2025-58098 — httpd: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... CVE-2025-65082 — httpd: Apache HTTP Server: CGI environment variable override CVE-2025-66200 — httpd: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo CVE-2025-69419 — openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing

🔗 References (11)