Oracle Linux 10 Cockpit Vulnerabilities Lead to Remote Code Execution Risks

Oracle Linux 10 Cockpit Vulnerabilities Lead to Remote Code Execution Risks

First seen 19 Jul 2026, 08:42 UTC Linuxsecurity 71% similarity 74.0

Article Content

Browse articles
ThreatCluster

Oracle has released important updates for Oracle Linux 10 Cockpit, addressing vulnerabilities that could lead to remote code execution. The updates include fixes for CVE-2026-4802 and CVE-2026-4800, which affect various components of the Cockpit management interface. Specifically, CVE-2026-4802 involves SSH argument injection, while CVE-2026-4800 relates to the Cockpit Image Builder. Both vulnerabilities were confirmed and patches are now available. Users of Oracle Linux 10 are advised to update their systems promptly to mitigate these risks. The updates were published on July 17, 2026, and are critical for maintaining system security.

Key Points: • Oracle Linux 10 Cockpit updates address critical remote code execution vulnerabilities. • CVE-2026-4802 involves SSH argument injection, posing significant risks to affected systems. • Users are urged to apply the updates immediately to protect against potential exploits.

ThreatCluster AI

Timeline

2026-01-21
CVE-2025-13465 published
A vulnerability affecting Oracle Linux was disclosed, allowing potential security risks.
Linuxsecurity
2026-03-31
CVE-2026-4800 published
Oracle disclosed another vulnerability related to the Cockpit Image Builder, increasing security concerns.
Linuxsecurity
2026-07-17
Oracle releases updates for Cockpit vulnerabilities
Oracle issued important updates for Cockpit in Oracle Linux 10, addressing CVE-2026-4802 and CVE-2026-4800.
Linuxsecurity

Community

Browse all →