Red Hat released important asynchronous security updates for Red Hat Satellite 6.16 and 6.17, shipping Satellite 6.16.8 for RHEL 8 and 9 and Satellite 6.17.8 for RHEL 9. The advisories remediate five vulnerabilities in bundled components: CVE-2026-25990 in Pillow, CVE-2026-27727 in mchange-commons-java used by candlepin, CVE-2025-69534 in python-markdown, CVE-2026-27459 in pyOpenSSL, and CVE-2026-33176 in Ruby Active Support. Affected products include Satellite, Satellite Capsule, and Extended Update Support variants for the supported RHEL releases.
Red Hat also fixed several Satellite-specific security issues, including cleartext proxy password exposure in Virt-who Configuration, certificate and key artifacts left in the rhsm cache, and enforcement of HTTPS-only global registration. The Active Support flaw, CVE-2026-33176, could trigger denial of service because large scientific-notation strings such as 1e10000 cause BigDecimal to expand them into massive decimal values, consuming excessive memory and CPU; Red Hat said the issue was addressed in Satellite 6.16 and 6.17 through advisories RHSA-2026:14874 and RHSA-2026:14873.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-07, Red Hat published RHSA-2026:14874, an Important security advisory for Red Hat Satellite 6.16 on RHEL 8 and RHEL 9. The async update released Satellite 6.16.8 and fixed five vulnerabilities, including CVE-2026-33176 in Active Support, plus several Satellite-specific issues such as cleartext proxy password exposure, rhsm cache certificate/key artifacts, and enforcing HTTPS during global registration.
On 2026-05-07, Red Hat published RHSA-2026:14873, an Important security advisory for Red Hat Satellite 6.17 on RHEL 9. The async update released Satellite 6.17.8 and fixed five vulnerabilities, including CVE-2026-33176 in Active Support, along with multiple Satellite-specific bugs such as HTTPS-only global registration, rhsm cache certificate/key exposure, and cleartext proxy password display.
A denial-of-service vulnerability in Active Support affecting versions prior to 8.1.2.1, 8.0.4.1, and 7.2.3.1 was patched in those upstream versions. The issue stemmed from scientific-notation strings such as `1e10000` being expanded into extremely large decimal values, causing excessive memory and CPU consumption during formatting.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.