Skip to content
Oracle Linux Vulnerabilities Allow Admin Control via Chained Flaws

Oracle Linux Vulnerabilities Allow Admin Control via Chained Flaws

First seen 14 Sep 2026, 16:02 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 14, 2026 at 16:52 UTC

Oracle Linux has released important fixes for two vulnerabilities, CVE-2026-55193 and CVE-2026-85150, affecting FreeRDP and GStreamer respectively. CVE-2026-55193, published on 2026-08-19, allows attackers to gain admin control through chained flaws related to RPC gateway checks. CVE-2026-85150, published on 2026-09-03, involves a crash in RTSP authentication credential parsing, also enabling potential admin access. Both vulnerabilities affect multiple versions of Oracle Linux and associated packages. Users are urged to check their versions and apply the necessary updates immediately. The vulnerabilities have been classified as important and moderate, respectively, indicating a significant risk to affected systems. The patches are available for various architectures, including x86_64 and aarch64.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-19
CVE-2026-55193 published
Oracle disclosed a vulnerability in FreeRDP allowing admin control through RPC flaws.
Linuxsecurity
2026-09-03
CVE-2026-85150 published
Oracle released details on a vulnerability in GStreamer that allows admin access via RTSP credential parsing.
Linuxsecurity
2026-09-14
Patches released for both CVEs
Oracle Linux released updates for FreeRDP and GStreamer to address the vulnerabilities.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track CVE-2026-55193 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed