CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

[UPDATE] [hoch] Red Hat Enterprise Linux (pcp): Mehrere Schwachstellen

highCVE-2026-16524CVE-2026-16526CVE-2026-16527CVE-2026-16529
Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux (pcp) ausnutzen, um beliebigen Programmcode auszuführen, um seine Privilegien zu erhöhen, um Sicherheitsvorkehrungen zu umgehen, und um einen Denial of Service Angriff durchzuführen.

CSIRTS triage

What
Multiple vulnerabilities in Performance Co-Pilot enable arbitrary code execution, privilege escalation, authentication bypass, and denial of service.
Who is affected
Red Hat Enterprise Linux systems running vulnerable versions of pcp.
Urgency
High; multiple attack vectors including remote code execution warrant timely patching.
Action
Apply Red Hat security updates for pcp to address CVE-2026-16524, CVE-2026-16526, CVE-2026-16527, and CVE-2026-16529.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch pcp

Get an email when a new pcp advisory drops — max one per day, one-click unsubscribe.

Details

Source
CERT-Bund (BSI) Security Advisories (DE · national-cert · site)
Severity
high
Published
2026-09-10
Exploitation
Not in CISA KEV at last sync

Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2868

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-16524coverage & exploitation statusNVD · CVE.org
CVE-2026-16526coverage & exploitation statusNVD · CVE.org
CVE-2026-16527coverage & exploitation statusNVD · CVE.org
CVE-2026-16529coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from CERT-Bund (BSI) Security Advisories