Red Hat released RHSA-2026:58550 for webkit2gtk3 on Red Hat Enterprise Linux 9.2 channels, updating the package to 2.52.5-1.el9_2 and addressing a broad set of WebKitGTK vulnerabilities. The patched issues include CVE-2026-43701, an Important-severity sandbox escape that could let a malicious website process restricted content outside the sandbox, along with multiple moderate-severity memory-handling flaws such as CVE-2026-43699, CVE-2026-43716, and CVE-2026-39872 that can be triggered by crafted web content and lead to unexpected process crashes. Red Hat said fixes were issued across supported RHEL 7, 8, and 9 product streams through related errata, while older RHEL 6 pywebkitgtk and webkitgtk packages remain out of support scope and should be assumed affected.
The advisory also bundles CVE-2024-4367, a Mozilla PDF.js flaw caused by a missing type check when handling fonts that can enable arbitrary JavaScript execution in the PDF.js context. Red Hat previously rated that issue Important for affected packages including firefox, thunderbird, webkitgtk4, and webkit2gtk3, and linked remediation to multiple RHSA updates across standard, EUS, AUS, and SAP-focused RHEL channels. The WebKitGTK fixes were tied to upstream security work that improved memory handling and addressed improper access control, reducing risks ranging from browser process crashes and denial of service to potential memory corruption, information disclosure, and sandbox bypass.

See real exploitation activity before you spend the cycle.
17 events from the most recent confirmed update back to the earliest known activity.
On August 24, 2026, Red Hat issued RHSA-2026:58564 for RHEL 7 Extended Lifecycle Support, marking fixes for WebKitGTK vulnerabilities including CVE-2026-39872, CVE-2026-43699, CVE-2026-43701, and CVE-2024-4367 in that product stream.
On August 24, 2026, Red Hat published RHSA-2026:58550 for webkit2gtk3 version 2.52.5-1.el9_2 covering RHEL 9.2 SAP and related channels. The advisory fixed numerous WebKitGTK vulnerabilities, including CVE-2026-39872, and also listed CVE-2024-4367.
Red Hat's CVE pages for CVE-2026-39872, CVE-2026-43699, CVE-2026-43701, and CVE-2026-43716 were last modified on July 27, 2026. The records include severity, CWE mappings, and fixed-product status information.
On July 20, 2026, Red Hat issued RHSA-2026:42088 for RHEL 8 and RHSA-2026:42062 for RHEL 9, fixing WebKitGTK vulnerabilities including CVE-2026-39872, CVE-2026-43699, CVE-2026-43701, and CVE-2026-43716.
Red Hat Bugzilla recorded CVE-2026-43676 on July 14, 2026, tracking a medium-severity WebKitGTK out-of-bounds access flaw. Maliciously crafted web content can cause an unexpected process crash; the issue was addressed through improved bounds checking.
Red Hat Bugzilla shows CVE-2026-39872 was reported on July 14, 2026. The bug tracks a WebKitGTK issue where maliciously crafted web content can trigger an unexpected process crash.
Red Hat's CVE records state that CVE-2026-39872, CVE-2026-43699, CVE-2026-43701, and CVE-2026-43716 were made public on July 10, 2026. These issues affect WebKitGTK and include sandbox bypass and multiple crash-causing memory-safety flaws.
On May 16, 2024, Red Hat issued advisories including RHSA-2024:2881, RHSA-2024:2882, RHSA-2024:2884, RHSA-2024:2886, and RHSA-2024:2888 to address CVE-2024-4367 across multiple RHEL 7, 8, and 9 streams.
Red Hat Bugzilla records that the vulnerability was described by Robb Gatica on May 14, 2024. The entry identifies PDF.js as affected and attributes the issue to a missing type check when handling fonts.
Red Hat's CVE record says CVE-2024-4367 was made public on May 14, 2024. The flaw is a missing type check in PDF.js that can allow arbitrary JavaScript execution in the PDF.js context.
Tenable published a reference-only notice for Red Hat Security Advisory RHSA-2026:59325, classified as an Important security update for RHEL 8 webkit2gtk3. The notice links the advisory to Bugzilla 2280382, 2500519 through 2500540, and 2520320, without identifying CVEs, fixed versions, or impact details.
Tenable referenced Red Hat Security Advisory RHSA-2026:59326 as an Important security update for RHEL 8 webkit2gtk3. The available excerpt links the advisory to Red Hat Bugzilla issues including 2280382, 2500519 through 2500540, and 2520320, but does not specify affected CVEs or fixed versions.
Red Hat issued RHSA-2026:57348 on August 20, 2026 for RHEL 8.4 Advanced Mission Critical Update Support and 8.4 Extended Update Support Long-Life Add-On. The advisory fixed WebKitGTK issues including CVE-2026-39872, CVE-2026-43699, CVE-2026-43701, and CVE-2026-43716.
On August 13, 2026, Red Hat issued RHSA-2026:54572 for RHEL 9.6 Extended Update Support and RHSA-2026:54634 for RHEL 9.4 Update Services for SAP Solutions, extending fixes for the WebKitGTK CVEs to those channels.
Red Hat published RHSA-2024:3783 and RHSA-2024:3784 on June 10, 2024, addressing CVE-2024-4367 in additional RHEL 8 packages.
On May 23, 2024, Red Hat issued RHSA-2024:3338 for RHEL 8.2 Advanced Update Support as another fix for CVE-2024-4367.
Red Hat released RHSA-2024:2911 and RHSA-2024:2913 on May 20, 2024, extending CVE-2024-4367 remediation to additional RHEL 8.4 and RHEL 7 packages.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
12 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourceredhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcecve.org
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.