Red Hat released a series of OpenShift Container Platform 4.12 security and bug-fix updates, including versions 4.12.91, 4.12.92, 4.12.93, and 4.12.96, and urged customers to upgrade through their normal release channels. The updates affect deployments across x86_64, ppc64le, s390x, and aarch64 on RHEL 8 and RHEL 9, and primarily ship as refreshed container images, with some releases also including updated packages. Although several advisories were labeled Important or even Critical, Red Hat Product Security rated the overall impact of these OpenShift 4.12 releases as Low.
The fixes span multiple components and vulnerabilities, including OpenSSH, jq, sudo, nghttp2, libxslt/libxml2, the Linux kernel, and virtualization-related flaws such as CVE-2026-53359, a KVM x86 shadow paging use-after-free issue, as well as CVE-2025-10263, an Arm processor privilege-escalation or information-disclosure flaw. Earlier releases also addressed CVE-2026-35385, CVE-2026-39979, CVE-2026-40164, CVE-2026-43037, CVE-2026-1519, CVE-2026-46331, and CVE-2026-46243. One advisory for 4.12.91 contained conflicting text stating Security Fix(es): None while simultaneously listing multiple CVEs, but Red Hat still recommended that all OpenShift 4.12 users apply the updates as they become available.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat announced OpenShift Container Platform 4.12.96 as a bug fix and security update release for OpenShift 4.12, with overall Low security impact. The advisory says the release contains updated container images and references fixes for CVE-2025-10263 and CVE-2026-53359.
Red Hat announced OpenShift Container Platform 4.12.93 as a bug fix and security update release for OpenShift 4.12, rated Low impact. The advisory says the update includes refreshed packages and container images and references fixes for CVE-2026-1519, CVE-2026-46331, and CVE-2026-46243.
Red Hat announced OpenShift Container Platform 4.12.92 as a bug fix and security update for OpenShift 4.12, with Low security impact according to Red Hat Product Security. The release updates packages and container images and lists fixes associated with CVE-2026-35385, CVE-2026-39979, CVE-2026-40164, and CVE-2026-43037.
Red Hat announced OpenShift Container Platform 4.12.91 as a bug fix and security update for the 4.12 release stream, rated Low impact by Red Hat Product Security. The advisory says the release includes updated container images and addresses multiple CVEs including flaws in libxslt/libxml2, OpenSSH, nghttp2, sudo, and the Linux kernel.
Red Hat released OpenShift Container Platform 4.12.88 as a bug-fix and security update with updated container images and packages, rated Low impact by Red Hat Product Security. The update addresses nine CVEs in libpng, Vim, and libarchive, including flaws enabling information disclosure, denial of service, heap corruption, and potential code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.