[UPDATE] [hoch] Red Hat Enterprise Linux (pcp): Mehrere Schwachstellen
Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux (pcp) ausnutzen, um beliebigen Programmcode auszuführen, um seine Privilegien zu erhöhen, um Sicherheitsvorkehrungen zu umgehen, und um einen Denial of Service Angriff durchzuführen.
CSIRTS triage
- What
- Multiple vulnerabilities in Performance Co-Pilot enable arbitrary code execution, privilege escalation, authentication bypass, and denial of service.
- Who is affected
- Red Hat Enterprise Linux systems running vulnerable versions of pcp.
- Urgency
- High; multiple attack vectors including remote code execution warrant timely patching.
- Action
- Apply Red Hat security updates for pcp to address CVE-2026-16524, CVE-2026-16526, CVE-2026-16527, and CVE-2026-16529.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch pcp
Get an email when a new pcp advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2868
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-165240.65% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-165260.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-165270.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-165290.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-16524 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16526 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16527 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16529 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highCVE-2026-16529: A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted networ…nvd
- highCVE-2026-16527: An unauthenticated remote attacker can bypass access controls by sending crafted requests to t…nvd
- highCVE-2026-16526: A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker w…nvd
- highCVE-2026-16524: A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via…nvd
More from CERT-Bund (BSI) Security Advisories
- medium[NEU] [mittel] Microsoft Edge: Schwachstelle ermöglicht Cross-Site Scripting2026-09-14
- medium[NEU] [mittel] Citrix Systems Workspace App Windows: Mehrere Schwachstellen ermöglichen nicht spezifizierten A…2026-09-14
- medium[NEU] [mittel] wpa_supplicant: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen2026-09-14
- medium[NEU] [mittel] WP Royal Royal Elementor Addons: Schwachstelle ermöglicht Offenlegung von Informationen2026-09-14
- low[UPDATE] [niedrig] 7-Zip: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen2026-09-14