Red Hat released a series of Important security advisories for Grafana across RHEL 8, 9, and 10 support channels, updating packages to remediate multiple vulnerabilities inherited from bundled Go components. The fixes span builds including 9.2.10-30.el8_10, 9.0.9-12.el9_2, 9.2.10-27.el9_4, 10.2.6-21.el9_6, 10.2.6-21.el9_7, 10.2.6-24.el10_0, and 10.2.6-25.el10_1, with packages published for x86_64, aarch64, ppc64le, and s390x. Red Hat said the updates address flaws such as CVE-2026-32282, a symlink-following issue in Go Root.Chmod, CVE-2026-32283, a denial-of-service bug in crypto/tls triggered by repeated TLS 1.3 key updates, and CVE-2026-32280, a certificate-chain building denial-of-service issue.
Additional Grafana updates for newer RHEL 9.6 and RHEL 10 channels also fixed web and identity-handling issues in Go networking libraries. Red Hat identified CVE-2026-39821 in golang.org/x/net/idna as a privilege-escalation flaw caused by incorrect Punycode label processing, alongside CVE-2026-27136 and CVE-2026-25681 in golang.org/x/net/html, which can enable cross-site scripting and potentially arbitrary code execution through HTML parsing bypasses. The latest affected Grafana builds include 10.2.6-22.el9_6 and 10.2.6-27.el10_2, extending remediation across SAP, AUS, EUS, Extended Life Cycle, and other long-term Red Hat support streams.

See real exploitation activity before you spend the cycle.
23 events from the most recent confirmed update back to the earliest known activity.
On 2026-08-06, Red Hat published RHSA-2026:51112, an Important advisory for Grafana on Red Hat Enterprise Linux 9.6 channels. The update released Grafana 10.2.6-22.el9_6 packages fixing CVE-2026-39821, CVE-2026-27136, and CVE-2026-25681 in bundled golang.org/x/net components.
On 2026-07-29, Red Hat published RHSA-2026:47714, an Important advisory for Grafana on Red Hat Enterprise Linux 9.4 channels. The update released Grafana 9.2.10-27.el9_4 packages rebuilt with golang 1.25.9 to fix CVE-2025-68121, CVE-2026-32281, CVE-2026-32282, CVE-2026-32283, and CVE-2026-32280.
On 2026-07-29, Red Hat published RHSA-2026:47722, an Important advisory for Grafana on Red Hat Enterprise Linux 9.2 channels. The update released Grafana 9.0.9-12.el9_2 packages rebuilt with golang 1.25.9 to fix CVE-2025-68121, CVE-2026-32281, CVE-2026-32282, CVE-2026-32283, and CVE-2026-32280.
On 2026-07-06, Red Hat published RHSA-2026:35827, an Important Grafana advisory for Red Hat Enterprise Linux 10. The update released Grafana 10.2.6-27.el10_2 packages to address CVE-2026-39821, a privilege-escalation flaw in golang.org/x/net/idna.
On 2026-05-26, Red Hat published RHSA-2026:20556, an Important advisory for Grafana on Red Hat Enterprise Linux 9.6 channels. The update released Grafana 10.2.6-21.el9_6 packages fixing CVE-2026-32282, CVE-2026-32283, and CVE-2026-32280.
On 2026-05-20, Red Hat published RHSA-2026:19714, an Important advisory for rhc-worker-playbook on Red Hat Enterprise Linux 10.0. The update released rhc-worker-playbook 0.2.3-5.el10_0 packages to fix CVE-2026-32282, CVE-2026-32283, and CVE-2026-32280.
On 2026-05-19, Red Hat published RHSA-2026:19134, an Important advisory for Grafana on Red Hat Enterprise Linux 10.2 channels. The update released Grafana 10.2.6-26.el10_2 packages to fix Grafana information-disclosure flaw CVE-2026-27877 and Go vulnerabilities CVE-2026-32282 and CVE-2026-32283.
On 2026-05-19, Red Hat published RHSA-2026:19352, an Important advisory for Grafana on Red Hat Enterprise Linux 9.8 channels. The update released Grafana 10.2.6-22.el9_8 packages to fix Grafana information-disclosure flaw CVE-2026-27877 and Go vulnerabilities CVE-2026-32282 and CVE-2026-32283.
On 2026-05-18, Red Hat published RHSA-2026:18032, an Important advisory for Grafana on Red Hat Enterprise Linux 10.0 Extended Update Support and related channels. The update released Grafana 10.2.6-24.el10_0 packages fixing CVE-2026-32282, CVE-2026-32283, and CVE-2026-32280.
On 2026-04-29, Red Hat published RHSA-2026:11507, an Important Grafana security advisory for Red Hat Enterprise Linux 8. The update delivered Grafana 9.2.10-30.el8_10 packages fixing CVE-2026-32282, CVE-2026-32283, and CVE-2026-32280.
On 2026-04-29, Red Hat published RHSA-2026:11712, an Important advisory for Grafana on Red Hat Enterprise Linux 10. The update released Grafana 10.2.6-25.el10_1 packages to remediate CVE-2026-32282 and CVE-2026-32283 across RHEL 10, EUS, 4-year update, and Extended Life Cycle channels.
On 2026-04-29, Red Hat published RHSA-2026:11711, an Important advisory for Grafana on Red Hat Enterprise Linux 9. The update released Grafana 10.2.6-21.el9_7 packages to fix Go flaws CVE-2026-32282 and CVE-2026-32283 across multiple RHEL 9 channels and architectures.
On 2026-03-05, Red Hat published RHSA-2026:3854, an Important Grafana security advisory for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions and related 4-year update channels. The update released Grafana 7.5.11-13.el9_0 packages for multiple architectures to fix Go vulnerabilities CVE-2025-61729, CVE-2025-61728, and CVE-2025-61726.
On 2026-03-05, Red Hat published RHSA-2026:3833, an Important Grafana security advisory for Red Hat Enterprise Linux 9.6 channels. The update released Grafana 10.2.6-18.el9_6 packages to fix Go vulnerabilities CVE-2025-61729, CVE-2025-61728, CVE-2025-61726, and CVE-2025-68121.
On 2026-03-05, Red Hat published RHSA-2026:3835, an Important Grafana security advisory for Red Hat Enterprise Linux 9.4 support channels. The update released Grafana 9.2.10-25.el9_4 packages to fix Go vulnerabilities CVE-2025-61729, CVE-2025-61728, and CVE-2025-61726.
On 2026-03-05, Red Hat published RHSA-2026:3836, an Important Grafana security advisory for Red Hat Enterprise Linux 9.2 channels including SAP Solutions and Extended Life Cycle offerings. The update released Grafana 9.0.9-10.el9_2 packages to fix Go vulnerabilities CVE-2025-61729, CVE-2025-61728, and CVE-2025-61726.
On 2026-03-05, Red Hat published RHSA-2026:3838, an Important Grafana security advisory for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Telecommunications Update Service offerings. The update released Grafana 7.5.15-9.el8_8 packages to fix Go denial-of-service vulnerabilities CVE-2025-61729, CVE-2025-61728, and CVE-2025-61726.
On 2026-03-05, Red Hat published RHSA-2026:3880, an Important Grafana security advisory for multiple Red Hat Enterprise Linux 8.6 service channels. The update released Grafana 7.5.11-9.el8_6 packages to fix Go vulnerabilities CVE-2025-61729, CVE-2025-61728, and CVE-2025-61726.
On 2026-03-05, Red Hat published RHSA-2026:3879, an Important Grafana security advisory for Red Hat Enterprise Linux 8.4 support channels. The update released Grafana 7.3.6-12.el8_4 packages to fix Go vulnerabilities CVE-2025-61729 and CVE-2025-61726.
On 2026-02-24, Red Hat published RHSA-2026:3188, an Important Grafana security advisory for Red Hat Enterprise Linux 8 and RHEL 8.10 Extended Life Cycle. The update released Grafana 9.2.10-28.el8_10 packages to fix CVE-2025-61728, CVE-2025-61726, and CVE-2025-68121 in bundled Go components.
On 2026-02-18, Red Hat's CVE record for CVE-2026-21721 stated the Grafana dashboard-permissions privilege-escalation flaw was also addressed through RHSA-2026:3078 for RHEL 10.0 Extended Update Support and RHSA-2026:3529 for RHEL 9.6 Extended Update Support. The flaw let a user with dashboard permission-management rights on one dashboard read or modify permissions on other dashboards in the same organization.
On 2026-02-18, Red Hat published RHSA-2026:2920, an Important Grafana security advisory for Red Hat Enterprise Linux 9. The update released Grafana 10.2.6-18.el9_7 packages for multiple RHEL 9 variants and architectures, fixing Grafana privilege-escalation flaw CVE-2026-21721 and four Go vulnerabilities including CVE-2025-68121.
On 2026-02-18, Red Hat published RHSA-2026:2914, an Important Grafana security advisory for Red Hat Enterprise Linux 10. The update released Grafana 10.2.6-22.el10_1 packages for multiple RHEL 10 variants and architectures, fixing Grafana privilege-escalation flaw CVE-2026-21721 and four Go vulnerabilities including CVE-2025-68121.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 43 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
23 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.