Red Hat released JBoss Enterprise Application Platform 8.1.6 as an Important security update for RHEL 8 and RHEL 9, replacing version 8.1.5 and addressing a broad set of vulnerabilities in bundled components including Bouncy Castle, Netty, Apache ActiveMQ Artemis, c3p0, mchange-commons-java, minimatch, WildFly Elytron, and plexus-utils. The advisories cite risks including denial of service, request smuggling, LDAP injection, directory traversal, brute-force exposure, message injection and exfiltration, arbitrary code execution, private key leakage, and cryptographic implementation flaws.
One of the tracked issues, CVE-2026-27904, affects the JavaScript glob-matching library minimatch and can cause denial of service through catastrophic backtracking in nested extglob expressions. Red Hat said the flaw was fixed across multiple products and included in the JBoss EAP updates, alongside other bundled-component remediations delivered through advisories RHSA-2026:18054, RHSA-2026:18055, and RHSA-2026:18059. Customers were advised to apply prior relevant errata, back up installations and data, and then upgrade to the fixed packages.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-18, Red Hat published RHSA-2026:18054, RHSA-2026:18055, and RHSA-2026:18059, releasing JBoss Enterprise Application Platform 8.1.6 as an Important security update replacing 8.1.5 for supported RHEL 8 and RHEL 9 deployments. The update includes fixes for multiple bundled-component vulnerabilities across Bouncy Castle, Netty, Apache ActiveMQ Artemis, c3p0, mchange-commons-java, minimatch, WildFly Elytron, and plexus-utils.
Red Hat Bugzilla documented CVE-2026-27904 as a denial-of-service flaw in minimatch caused by catastrophic backtracking in nested extglob-derived regular expressions. The entry states fixed upstream versions and notes the issue can be triggered through the default minimatch() API.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
redhat.atlassian.net
Open sourceredhat.atlassian.net
Open sourceredhat.atlassian.net
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.