{"id":"RHSA-2026:68258","summary":"Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update","modified":"2026-09-29T10:57:32.090459824Z","published":"2026-09-22T10:19:07Z","upstream":["CVE-2026-41284","CVE-2026-68569","CVE-2026-73581","CVE-2026-75973","CVE-2026-76183","CVE-2026-77791","CVE-2026-78383","CVE-2026-78437","CVE-2026-79677","CVE-2026-86350","CVE-2026-87022"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:68258"},{"type":"ARTICLE","url":"https://images.redhat.com/"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-68569"},{"type":"ARTICLE","url":"https://access.redhat.com/security/updates/classification/"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-41284"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-79677"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-76183"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-78437"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-86350"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-87022"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-78383"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-77791"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-73581"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-75973"},{"type":"ARTICLE","url":"https://access.redhat.com/security/cve/CVE-2026-77756"},{"type":"ADVISORY","url":"https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_68258.json"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2476518"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-41284"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41284"},{"type":"ARTICLE","url":"https://lists.apache.org/thread/2nvqjr7ovjmvx2vbhb7s61ycd5msc8qc"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2524160"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-68569"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68569"},{"type":"ARTICLE","url":"https://lists.apache.org/thread/8robqo76q0osxgw0b5lcwgz0hcf9h4zc"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2539356"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-73581"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73581"},{"type":"ARTICLE","url":"https://lists.apache.org/thread/r0dj3h1pbn4wv96fhsfrnz3t6874t6do"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2539354"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-75973"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75973"},{"type":"ARTICLE","url":"https://lists.apache.org/thread/njjcdkkzqyzx4n3ffc4ffjmyh5mpl1gr"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2539355"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-76183"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76183"},{"type":"ARTICLE","url":"https://lists.apache.org/thread/45mxk8nj2q8pkhct6lfxkvtm2jpywrsp"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2539396"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-77791"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77791"},{"type":"ARTICLE","url":"https://lists.apache.org/thread/mb1pjjooqytrl6hbvbt3rw1lqwlon4cz"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2539486"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-78383"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78383"},{"type":"ARTICLE","url":"https://lists.apache.org/thread/tyqcqk99g7ghgk22641vf67vghcyswnw"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2539533"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-78437"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78437"},{"type":"ARTICLE","url":"https://lists.apache.org/thread/qkmsos3s8chn5053qr466rzwv6sk5gjg"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2539616"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-79677"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-79677"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2026/09/23/27"},{"type":"ARTICLE","url":"https://lists.apache.org/thread/bzwps6ck4szf2hmksbbon3syyl9qnkv8"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2539370"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-86350"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86350"},{"type":"ARTICLE","url":"https://lists.apache.org/thread/mss45z99lcdd5dtpgcn45dy82f3toswc"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2539373"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-87022"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87022"},{"type":"ARTICLE","url":"https://lists.apache.org/thread/ypvlkjqsq0480fnk9jm6h9qllddwlw4w"}],"affected":[{"package":{"name":"tomcat11","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/tomcat11"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:11.0.26-0.1.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:68258.json"}},{"package":{"name":"tomcat11-admin-webapps","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/tomcat11-admin-webapps"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:11.0.26-0.1.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:68258.json"}},{"package":{"name":"tomcat11-common","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/tomcat11-common"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:11.0.26-0.1.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:68258.json"}},{"package":{"name":"tomcat11-docs-webapp","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/tomcat11-docs-webapp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:11.0.26-0.1.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:68258.json"}},{"package":{"name":"tomcat11-el-6.0-api","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/tomcat11-el-6.0-api"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:11.0.26-0.1.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:68258.json"}},{"package":{"name":"tomcat11-jsp-4.0-api","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/tomcat11-jsp-4.0-api"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:11.0.26-0.1.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:68258.json"}},{"package":{"name":"tomcat11-lib","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/tomcat11-lib"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:11.0.26-0.1.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:68258.json"}},{"package":{"name":"tomcat11-servlet-6.1-api","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/tomcat11-servlet-6.1-api"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:11.0.26-0.1.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:68258.json"}},{"package":{"name":"tomcat11-user-instance","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/tomcat11-user-instance"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:11.0.26-0.1.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:68258.json"}},{"package":{"name":"tomcat11-webapps","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/tomcat11-webapps"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:11.0.26-0.1.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:68258.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"}]}