Red Hat released Important security updates for Red Hat Ansible Automation Platform versions 2.5, 2.6, and 2.7, remediating a broad set of vulnerabilities across automation-controller, automation-gateway, automation-platform-ui, automation-controller-cli, and bundled dependencies. The advisories cover issues including remote code execution, path traversal, server-side request forgery with credential leakage, command injection, HTTP request smuggling, arbitrary file overwrite/read, environment variable exfiltration, and denial of service. Affected offerings also include Red Hat Ansible Inside and Red Hat Ansible Developer on RHEL 8, 9, and 10 across multiple architectures.
The updates include fixes for specific third-party flaws such as CVE-2026-34993 in aiohttp that could lead to arbitrary code execution through untrusted input to CookieJar.load(), CVE-2026-59886 in pyasn1 that can trigger CPU and memory exhaustion via crafted ASN.1 REAL values, and CVE-2026-39373 in JWCrypto that enables memory exhaustion through compressed JWE tokens. Red Hat also addressed CVE-2026-44705 in the Node.js tmp package for RHEL 10 and, in Ansible Automation Platform 2.7, patched CVE-2026-52902 in automation-controller-cli and CVE-2026-15307 in Django. Updated package versions include automation-controller 4.6.32 and 4.7.16, automation-controller-cli 4.8.6, python3.12-aiohttp 3.14.3, python3.12-django 5.2.17, python3.12-gitpython 3.1.59, and python3.12-jwcrypto 1.5.8.

See real exploitation activity before you spend the cycle.
7 events from the most recent confirmed update back to the earliest known activity.
On 2026-08-24, Red Hat released Important advisory RHSA-2026:59137 for Red Hat Ansible Automation Platform 2.7, Red Hat Ansible Inside 1.5, and Red Hat Ansible Developer 1.4. The advisory fixed CVE-2026-52902, a YAML !include path traversal issue, and CVE-2026-15307, a Django GeoDjango remote code execution flaw.
On 2026-08-24, Red Hat released Important advisory RHSA-2026:59136 for Red Hat Ansible Automation Platform 2.6, Red Hat Ansible Inside 1.4, and Red Hat Ansible Developer 1.3. The update addressed multiple flaws in automation-controller, automation-platform-ui, and bundled dependencies including aiohttp, Django, GitPython, JWCrypto, pyasn1, daphne, and form-data.
On 2026-08-24, Red Hat released Important advisory RHSA-2026:59135 for Red Hat Ansible Automation Platform 2.5 and Red Hat Ansible Developer 1.2. The update shipped fixes for multiple vulnerabilities across automation-controller, automation-gateway, and bundled dependencies including aiohttp, Django, GitPython, pyasn1, JWCrypto, and tmp.
The tmp npm package fixed CVE-2026-44705 in version 0.2.6, addressing a path traversal issue that let attackers escape the intended temporary directory via unsanitized prefix, postfix, or dir values. The flaw affected versions prior to 0.2.6.
pyasn1 fixed CVE-2026-59886 in version 0.6.4, resolving excessive CPU and memory consumption triggered by crafted ASN.1 REAL values in the univ.Real type. The flaw affected versions prior to 0.6.4.
AIOHTTP version 3.14.0 fixed CVE-2026-34993, an arbitrary code execution vulnerability caused by using CookieJar.load() with untrusted input. The issue affected versions prior to 3.14.0.
JWCrypto fixed CVE-2026-39373 in version 1.5.7, addressing a denial-of-service issue where crafted ZIP-compressed JWE tokens could expand and exhaust memory. The flaw affected versions prior to 1.5.7 and was tied to incomplete remediation of CVE-2024-28102.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcedocs.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.