Red Hat released Important security updates for Red Hat Ansible Automation Platform 2.5 and 2.6, addressing a broad set of vulnerabilities across ansible-core, automation-controller, automation-gateway, automation-platform-ui, pulpcore, urllib3, pip, receptor, and multiple Go libraries. The advisories, RHSA-2026:42078 and RHSA-2026:42079, cover issues ranging from arbitrary code execution and privilege escalation to denial of service, information disclosure, MITM and proxy-bypass conditions. Notable flaws include CVE-2026-8643, a pip wheel-installation path traversal bug that can overwrite files outside the intended directory; CVE-2026-12701, a pulpcore path traversal vulnerability that can let an authenticated administrator write files outside the export directory; and CVE-2026-44432, a urllib3 decompression flaw that can drive excessive CPU and memory consumption.
Red Hat also tied the updates to multiple Go HTML parsing and certificate-handling vulnerabilities affecting products in the platform stack. CVE-2026-25681 and CVE-2026-27136 in golang.org/x/net/html can let crafted HTML bypass sanitization and trigger cross-site scripting, with potential downstream code-execution impact in some application contexts, while CVE-2026-27145 in Go's crypto/x509 can cause quadratic CPU consumption during TLS hostname verification with a malicious certificate. Red Hat said fixes were issued across affected Ansible Automation Platform builds and related product variants, including Ansible Inside and Ansible Developer, and advised customers to apply the updated packages and follow platform release documentation for upgrade steps.

See real exploitation activity before you spend the cycle.
42 events from the most recent confirmed update back to the earliest known activity.
Red Hat released Ansible Automation Platform 2.5.20260804, updating Automation Controller to 4.6.31, Automation Hub to 4.10.17, Event-Driven Ansible to 2.9.0, and Receptor to 1.6.7. The release addressed multiple security vulnerabilities across Automation Controller, execution environments, Automation Hub, Ansible Lightspeed, and Receptor, including CVE-2026-11332, CVE-2026-34993, CVE-2026-59869, CVE-2026-9595, CVE-2026-13149, CVE-2026-44545, CVE-2026-59939, CVE-2026-40898, and CVE-2026-27145.
Red Hat published Important advisory RHSA-2026:50336 for Red Hat Ansible Automation Platform 2.6, delivering security and bug-fix updates across automation-controller, automation-eda-controller, automation-gateway-proxy, aiohttp, daphne, Pillow, pyasn1, and receptor dependencies. The advisory remediated multiple flaws including CVE-2026-48526, CVE-2026-12383, CVE-2026-18141, CVE-2026-33811, CVE-2026-34993, CVE-2026-44545, CVE-2026-55380, CVE-2026-55379, CVE-2026-54060, CVE-2026-54059, CVE-2026-59197, CVE-2026-59886, CVE-2026-59885, and CVE-2026-40898.
Red Hat fixed CVE-2026-27145 in receptor for Red Hat Ansible Automation Platform 2.5 on RHEL 8 and RHEL 9 via RHSA-2026:50319.
Red Hat published RHSA-2026:48151 for Cryostat 4 on RHEL 9, fixing golang.org/x/net/html issues CVE-2026-25681 and CVE-2026-27136 in multiple Cryostat components.
Red Hat published Important security advisory RHSA-2026:42132 for Red Hat Ansible Automation Platform 2.6 container release images, making updated images available across multiple architectures. The advisory addressed 16 CVEs, including CVE-2026-12701, CVE-2026-25681, CVE-2026-27136, CVE-2026-44432, and CVE-2026-8643, affecting components such as controller, gateway, hub, receptor, operators, and execution environments.
Red Hat's CVE pages document July 20 fixes in Ansible Automation Platform 2.5 and 2.6 for CVE-2026-44432, CVE-2026-8643, CVE-2026-25681, CVE-2026-27136, and CVE-2026-27145.
Red Hat released fixes for the pulpcore path traversal vulnerability CVE-2026-12701 across affected Red Hat Ansible Automation Platform and Red Hat Satellite versions.
Red Hat published Important advisory RHSA-2026:42079 for Red Hat Ansible Automation Platform 2.6, shipping security and bug-fix updates that remediate multiple flaws across ansible-core, automation-controller, automation-platform-ui, pulpcore, receptor, urllib3, and Go libraries.
Red Hat published Important advisory RHSA-2026:42078 for Red Hat Ansible Automation Platform 2.5, delivering fixes for multiple vulnerabilities including CVE-2026-11332, CVE-2026-8643, CVE-2026-44432, CVE-2026-6321, CVE-2026-12701, CVE-2026-25681, and CVE-2026-27136.
Red Hat Enterprise Linux 10 fixed CVE-2026-27145 in rhc via RHSA-2026:39005.
Red Hat Enterprise Linux 10 published RHSA-2026:37072 for CVE-2026-27136 in podman, marking the component fixed with the justification that vulnerable code was not present.
Red Hat published Bugzilla entry 2480757 for CVE-2026-27136, documenting the golang.org/x/net/html HTML parsing bypass and associated product remediations.
Red Hat last modified its CVE-2026-27136 advisory as product remediation details expanded.
Red Hat fixed CVE-2026-8643 in python3.14-pip for Red Hat Enterprise Linux 10 via RHSA-2026:36193 and for Red Hat Enterprise Linux 9 via RHSA-2026:36315.
Red Hat Enterprise Linux 10 fixed CVE-2026-25681 in grafana via RHSA-2026:35827.
Red Hat Enterprise Linux 10 fixed CVE-2026-27145 in golang-github-openprinting-ipp-usb via RHSA-2026:35832.
Red Hat Enterprise Linux 10 fixed CVE-2026-27145 in opentelemetry-collector via RHSA-2026:34357.
Red Hat Ansible Automation Platform 2.6 fixed CVE-2026-8643 in de-minimal-rhel9, de-supported-rhel9, and gateway-rhel9 via RHSA-2026:34374.
Red Hat Ansible Automation Platform 2.6 for RHEL 9 fixed CVE-2026-44432 in python3.12-urllib3 via RHSA-2026:34160.
Red Hat Enterprise Linux 10 fixed CVE-2026-25681 in opentelemetry-collector via RHSA-2026:34357.
Red Hat published Bugzilla entry 2480761 for CVE-2026-25681, documenting the golang.org/x/net/html parsing issue and noting remediations across multiple products.
Red Hat last modified its CVE records for CVE-2026-44432, CVE-2026-8643, and CVE-2026-25681 in late June and early July as remediation details were added.
Red Hat Enterprise Linux 8 fixed CVE-2026-44432 in python3.12-urllib3 via RHSA-2026:32992.
Red Hat Enterprise Linux 10 fixed CVE-2026-27145 in golang via RHSA-2026:29980, addressing a crypto/x509 hostname-verification denial-of-service issue triggered by certificates with many DNS SAN entries.
Red Hat published Important advisory RHSA-2026:24762 for Red Hat Ansible Automation Platform 2.6, delivering security and bug-fix updates across automation-controller, automation-gateway-proxy, automation-platform-ui, python-click, python3.12-cryptography, python3.12-pillow, and receptor. The advisory remediated multiple flaws including CVE-2026-39892, CVE-2026-30922, CVE-2026-32280, CVE-2026-32282, CVE-2026-32283, CVE-2026-39363, CVE-2026-4800, CVE-2026-33891, CVE-2026-4926, CVE-2026-40175, CVE-2026-7246, and CVE-2026-40192.
Red Hat published CVE-2026-8643, an Important pip wheel-installation path traversal flaw that can overwrite arbitrary files via crafted entry-point names and may lead to code execution.
Red Hat made public CVE-2026-27136, an Important golang.org/x/net/html vulnerability in which parsing and rendering crafted HTML can produce an unexpected tree and enable XSS.
The initial vulnerability description for CVE-2026-25681 in golang.org/x/net/html was recorded by OSIDB Bzimport, documenting an HTML parsing issue that can enable XSS and possible code execution in some contexts.
Red Hat made public CVE-2026-44432, an Important urllib3 denial-of-service flaw caused by excessive decompression and connection draining behavior that can consume CPU and memory.
Red Hat published Bugzilla entry 2430472 for CVE-2026-23490, describing a pyasn1 denial-of-service flaw caused by malformed RELATIVE-OID input leading to memory exhaustion. The record notes fixes in pyasn1 0.6.2 and tracks remediations across Red Hat Enterprise Linux, Ansible Automation Platform, OpenShift Container Platform, and OpenStack Platform.
Red Hat published Important advisory RHSA-2026:13512 for Red Hat Ansible Automation Platform 2.5, delivering security and bug-fix updates across automation-controller, automation-gateway, automation-gateway-proxy, receptor, and bundled Python libraries. The advisory addressed multiple vulnerabilities including CVE-2026-6266, CVE-2026-27606, CVE-2026-25679, CVE-2026-30922, CVE-2026-27459, and CVE-2026-32597, and also applied to Red Hat Ansible Inside 1.3 and Red Hat Ansible Developer 1.2.
Red Hat published Important advisory RHSA-2026:6278 for Red Hat Ansible Automation Platform 2.5, delivering security and bug-fix updates for automation-gateway-proxy and python3.12-pillow. The advisory remediated CVE-2025-68121, CVE-2025-61726, and CVE-2026-25990, applied to AAP 2.5 on RHEL 8 and 9 as well as Red Hat Ansible Inside 1.3 and Red Hat Ansible Developer 1.2, and warned users to download the latest installer to avoid installation or upgrade failures.
Red Hat published Important advisory RHSA-2026:6277 for Red Hat Ansible Automation Platform 2.6, delivering security and bug-fix updates for components including automation-gateway-proxy, automation-platform-ui, and python3.12-pillow. The advisory remediated seven vulnerabilities: CVE-2025-61726, CVE-2025-68121, CVE-2025-69873, CVE-2026-25639, CVE-2026-25990, CVE-2026-27904, and CVE-2026-29074, and warned users to download the latest installer to avoid installation or upgrade failures.
Red Hat published Important advisory RHSA-2026:3958 for Red Hat Ansible Automation Platform 2.6, delivering security and bug-fix updates across automation-controller, automation-gateway, automation-hub, automation-platform-ui, automation-eda-controller, ansible-core, and bundled dependencies. The advisory remediated multiple flaws including CVE-2026-24049, CVE-2026-23490, CVE-2025-13465, CVE-2025-59057, CVE-2026-21884, CVE-2026-22029, CVE-2025-69223, CVE-2026-1312, CVE-2026-1287, CVE-2026-1285, CVE-2026-1207, CVE-2025-14550, CVE-2026-0994, and CVE-2025-61726, and warned users to download the latest installer to avoid installation or upgrade failures.
Red Hat published Important advisory RHSA-2026:3959 for Red Hat Ansible Automation Platform 2.5, delivering security and bug-fix updates across automation-controller, automation-gateway, automation-hub, automation-eda-controller, receptor, and bundled dependencies. The advisory remediated multiple flaws including CVE-2026-24049, CVE-2026-23490, CVE-2026-22029, CVE-2025-69223, CVE-2026-1312, CVE-2026-1287, CVE-2026-1285, CVE-2026-1207, CVE-2025-14550, CVE-2026-0994, and CVE-2025-61726, and warned users to download the latest installer to avoid installation or upgrade failures.
Red Hat published Important advisory RHSA-2026:1497 for Red Hat Ansible Automation Platform 2.4, fixing four denial-of-service and resource-consumption flaws in automation-controller and receptor: CVE-2025-64460, CVE-2025-66471, CVE-2025-69223, and CVE-2025-61729. The update raised automation-controller to 4.5.30 and receptor to 1.6.3 and also applied to Red Hat Ansible Inside 1.2 and Red Hat Ansible Developer 1.1 on RHEL 8 and 9.
Red Hat published Important advisory RHSA-2026:1249 for Red Hat Ansible Automation Platform 2.6, delivering security and bug-fix updates across automation-controller, receptor, automation-gateway, automation-hub, automation-platform-ui, ansible-core, and bundled Python packages. The advisory remediated CVE-2025-53643, CVE-2025-69223, CVE-2025-64460, CVE-2025-66471, CVE-2025-4565, and CVE-2025-61729, and also applied to Red Hat Ansible Inside 1.4 and Red Hat Ansible Developer 1.3 on RHEL 9 and 10.
Red Hat issued RHSA-2022:5234 to fix CVE-2019-20916 in python-virtualenv on Red Hat Enterprise Linux 7. The pip flaw allowed a malicious package server to use a crafted HTTP Content-Disposition header to overwrite arbitrary files when a user installed a wheel from a remote URL.
MITRE published the CWE-22 entry defining improper limitation of a pathname to a restricted directory, the weakness class referenced by several of the later vulnerabilities.
Red Hat published additional errata through August 11 extending fixes for CVE-2026-25681 and CVE-2026-27136 to RHEL Extended Update Support and SAP-focused offerings.
Red Hat published Important advisory RHSA-2026:4460 for Red Hat Ansible Automation Platform 2.4, addressing CVE-2025-61726 in the receptor component. The update also refreshed the platform to Python 3.12, replaced python3.11-prefixed RPMs, and warned users to download the latest installer to avoid installation or upgrade failures.
Red Hat published Important advisory RHSA-2026:1506 for Red Hat Ansible Automation Platform 2.5, shipping security updates for components including automation-controller, automation-gateway, automation-hub, Django, urllib3, and receptor. The advisory remediated CVE-2025-53643, CVE-2025-69223, CVE-2025-64460, CVE-2025-66471, and CVE-2025-61729, and also applied to Red Hat Ansible Inside 1.3 and Red Hat Ansible Developer 1.2 on RHEL 8 and 9.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
32 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcedocs.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcecwe.mitre.org
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.