VYPR
Vypr IntelligenceAI-generatedAug 26, 2026· 2 CVEs

Red Hat: 2 Actively-Exploited Flaws Added to CISA KEV

CISA has added two Red Hat vulnerabilities to its Known Exploited Vulnerabilities Catalog, confirming their active exploitation in the wild and urging immediate remediation.

Key findings

  • Two Red Hat vulnerabilities, CVE-2015-3246 and CVE-2015-5287, added to CISA KEV.
  • Both flaws are confirmed to be under active exploitation by threat actors.
  • No ransomware association has been reported for these specific CVEs.
  • Immediate patching and remediation are critical to defend against active threats.
  • CISA KEV listing mandates action for federal agencies and advises all organizations.

CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog with two Red Hat flaws, CVE-2015-3246 and CVE-2015-5287, both confirmed to be under active exploitation. The addition of a vulnerability to the KEV catalog signifies that threat actors are actively leveraging these weaknesses, making them critical targets for immediate patching and mitigation efforts across federal agencies and strongly recommended for all organizations.

This batch of actively exploited vulnerabilities includes:

Neither of these vulnerabilities has been publicly associated with ransomware campaigns, according to the available information. However, their active exploitation status underscores the severe risk they pose to unpatched systems.

Organizations running affected Red Hat products must prioritize patching these vulnerabilities without delay. CISA’s KEV catalog serves as a definitive list of security flaws that pose significant risk, and compliance with its directives is mandatory for U.S. federal civilian executive branch agencies. All other organizations are strongly advised to review their systems for these vulnerabilities and apply necessary updates to protect against ongoing threats.

AI-written article. Grounded in 2 CVE records listed below.