Red Hat issued Important security and bug-fix updates for OpenShift Container Platform 4.14, 4.15, 4.16, 4.17, and 4.18, including releases 4.14.65, 4.15.64, 4.16.60, 4.17.54, 4.18.39, and 4.18.43. The updates refresh platform packages and container images across x86_64, s390x, ppc64le, and aarch64 deployments, addressing vulnerabilities in OpenSSH, libarchive, libpng, nghttp2, Vim, GRUB2, OpenSSL, sudo, and the Linux kernel.
Affected flaws include CVE-2026-25646, an out-of-bounds read in libpng's png_set_quantize() that can cause an infinite loop and read past a heap buffer, and CVE-2026-28421, in which crafted Vim swap files can trigger heap-buffer overflow and denial of service during recovery. Other remediated issues can enable arbitrary code execution, command injection, information disclosure, memory corruption, or denial of service; Red Hat advised OpenShift administrators to upgrade packages and release images through their appropriate release channels using the web console or OpenShift CLI.

See real exploitation activity before you spend the cycle.
11 events from the most recent confirmed update back to the earliest known activity.
Red Hat documented CVE-2026-4111, an infinite-loop denial-of-service flaw in libarchive's RAR5 decompression path. A crafted RAR5 archive can cause archive_read_data() to consume 100% CPU indefinitely, and Red Hat issued remediation advisories for RHEL, Service Interconnect, and OpenShift Container Platform releases.
Red Hat documented CVE-2026-28417, an OS command-injection vulnerability in Vim's bundled netrw plugin that can be triggered when a user opens a crafted URL, such as an scp:// URL. Vim 9.2.0073 fixes the issue, and Red Hat issued remediation advisories for supported RHEL and OpenShift Container Platform versions.
Red Hat documented CVE-2026-25749, a heap buffer overflow in Vim's get_tagfname() caused by unchecked copying of a user-controlled helpfile value; Vim 9.1.2132 fixes the issue. Red Hat issued remediation advisories for RHEL 7 through 10 and multiple extended-support channels, in addition to OpenShift Container Platform releases.
Red Hat released OpenShift Container Platform 4.18.43 as an Important security and bug-fix update. It fixes the nghttp2 denial-of-service issue CVE-2026-27135, the sudo privilege-escalation issue CVE-2026-35535, and the Linux-kernel local privilege-escalation issue CVE-2026-46300 (Fragnesia).
Red Hat released OpenShift Container Platform 4.17.54 as an Important-rated security and bug-fix update. The update remediates 11 vulnerabilities affecting OpenSSH, libarchive, libpng, nghttp2, Vim, and GRUB2, including arbitrary-code-execution, information-disclosure, and denial-of-service flaws.
Red Hat released OpenShift Container Platform 4.15.64 as an Important-rated security update with updated packages and container images. The release remediates flaws in OpenSSH, libarchive, libpng, nghttp2, Vim, GRUB2, OpenSSL, and the Linux kernel.
Red Hat released the Important-rated OpenShift Container Platform 4.14.65 security update. It fixes vulnerabilities in OpenSSH, libarchive, libpng, nghttp2, Vim, GRUB2, OpenSSL, and the Linux kernel, including CVE-2026-3497, CVE-2026-4111, CVE-2026-4424, CVE-2026-25646, and CVE-2026-31431.
Red Hat released OpenShift Container Platform 4.18.39 as an Important security and bug-fix update. It updates packages and container images to fix OpenSSH CVE-2026-3497 and libarchive CVE-2026-4424 and CVE-2026-5121.
Red Hat released OpenShift Container Platform 4.18.38 as an Important-rated security and bug-fix update with updated packages and container images. The release fixes five libarchive and Vim vulnerabilities, including CVE-2026-4111 and three Vim arbitrary-code-execution flaws: CVE-2026-25749, CVE-2026-28417, and CVE-2026-33412.
Red Hat released OpenShift Container Platform 4.18.5 as an Important-rated security and bug-fix update with updated container images. The release fixes Python path-traversal flaw CVE-2023-6597 and Linux kernel ALSA USB-audio out-of-bounds-access issue CVE-2024-53197, along with other referenced vulnerabilities.
Red Hat released an Important-rated security and bug-fix update for OpenShift Container Platform 4.16. The update remediates nine vulnerabilities in libarchive, libpng, Vim, and GRUB2, including CVE-2026-4111, CVE-2026-4424, CVE-2026-5121, CVE-2026-25646, CVE-2026-33412, CVE-2026-25749, CVE-2026-28417, CVE-2026-28421, and CVE-2025-61662.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
13 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.