This week demands immediate action from every Linux system administrator because a massive wave of security patches just dropped across all major distributions. Critical vulnerabilities in Samba and the core kernel now allow attackers to execute remote code or escalate privileges without any user interaction. Web servers, mail daemons, and foundational crypto libraries like OpenSSL also receive urgent fixes that directly protect encrypted traffic from man-in-the-middle attacks. You must run the correct package manager commands for your exact release right now since skipping these updates leaves your entire infrastructure wide open to automated ransomware campaigns.
Massive weekly Linux security updates hit Samba, kernels, and web stacks hard
This week's batch of Linux security updates is a massive wave of patches that targets critical flaws in Samba, the kernel, OpenSSL, and dozens of web servers. System administrators managing RHEL, Debian, Ubuntu, Fedora, or any other distribution need to prioritize these installations immediately because unpatched systems face severe risks of remote code execution and privilege escalation. The volume of advisories across AlmaLinux, Oracle Linux, Rocky Linux, Slackware, SUSE, and others suggests a coordinated push to close vulnerabilities that attackers are actively exploiting in the wild. Running your package manager right now is not optional if you want to keep your infrastructure secure.
Critical Samba and kernel flaws drive urgent Linux security updates
Samba has critical vulnerabilities in AlmaLinux and RHEL that allow remote code execution or privilege escalation, so those packages must be updated before anything else. The kernel sees massive updates across every distribution this week. Slackware specifically targets the rxrpc networking module, while Ubuntu pushes separate kernels for NVIDIA Tegra, Raspberry Pi, Azure FIPS, and low latency builds. SUSE is rolling out live patches for SLES 15 SP4 through SP7, which means some systems can get fixed without a reboot, but others still need downtime. Skipping these kernel updates leaves the base system exposed to memory corruption exploits that have been around long enough for attackers to write automated tools against them. I've seen admins skip Samba patches because they thought it was just file sharing, until ransomware hit and encrypted everything on the network. Do not make that mistake this week.
Web servers, mail daemons, and browsers face widespread fixes
Apache httpd and Nginx are getting patched across Fedora, Slackware, Ubuntu, RHEL, Oracle, Alma, and Rocky. Exim and Dovecot see fixes in Debian, Fedora, and Ubuntu, which affects anyone running mail servers. Postfix updates land in Fedora and Ubuntu. Firefox, Thunderbird, and Chromium get security bumps everywhere. If you run a web server or handle email traffic, these are the packages that keep your infrastructure from becoming an open door for attackers. The sheer number of browser updates also means desktop users need to refresh their systems soon, as rendering engines often hide zero-day exploits in plain sight. Delaying these installations leaves services vulnerable to cross-site scripting and authentication bypasses that can compromise user data without any interaction required.
OpenSSL, GnuTLS, and crypto libraries get major updates
OpenSSL, GnuTLS, and compat-openssl10 or 11 updates appear in almost every distribution list. PHP 8.2, 8.3, and 8.4 get security bumps in RHEL, Rocky, Oracle, and Fedora. .NET 10.0 lands in RHEL and Rocky. Ruby 4.0 appears in Fedora and Rocky. Libsoup gets hammered with updates in SUSE, RHEL, Debian, Ubuntu, and Slackware. These libraries underpin secure communication, so leaving them outdated breaks the trust chain for encrypted traffic. Attackers can exploit weak crypto implementations to decrypt sensitive data or perform man-in-the-middle attacks on internal networks. Updating these packages ensures that TLS handshakes and certificate validation work as intended across all your services.
Distribution-specific paths for RHEL, Debian, Ubuntu, Fedora, and more
RHEL has a huge list including OpenSSH, Fence-agents, OVN, OpenShift, and Kpatch-patches alongside the core updates. Debian brings Sudo, Node.js, GIMP, FRRouting, Exim4, GSASL, Request Tracker5, and Tomcat9 to the table. Ubuntu pushes XZ Utils, MySQL, Apache Commons Lang, GoBGP, Pip, Twisted, and Libwww-perl in this cycle. Fedora covers Suricata, Perl, Vim, Unbound, HPLIP, Nextcloud, Rust-sequoia, Keylime, and NASM for both version 43 and 44. SUSE adds Busybox, Putty, Strongswan, Hplip, Xorg, Grafana, MariaDB, PostgreSQL18, Salt, Glibc, Python-Pillow, Evince, and Cloudflared to the mix. Slackware rounds out the week with Proftpd, TigerVNC, Net-Tools, Libinput, and Dnsmasq. Each distribution has its own advisory numbering system, so check the specific IDs for your release to ensure you are pulling the right packages from the repositories.

Latest Security Patches by Distribution
Here’s a complete breakdown of recent security updates for AlmaLinux, Debian GNU/Linux, Fedora Linux, Oracle Linux, Red Hat Enterprise Linux, Rocky Linux, Slackware Linux, SUSE Linux, and Ubuntu Linux.
AlmaLinux
AlmaLinux recently deployed urgent security errata across its standard production repositories to fix critical flaws in widely used software. These patches directly address dangerous vulnerabilities in CIFSwitch, Samba, Apache HTTP Server, and OpenSSL while also resolving remote code execution risks within Vim and Ruby. System administrators managing PHP version 10 or the real-time kernel on version 8 must apply these updates quickly since unpatched systems remain highly vulnerable to denial of service attacks and memory corruption exploits. Keeping infrastructure regularly updated remains the only reliable defense against escalating network threats.
- CIFSwitch (CVE-2026-46243) Patches Released
- ALSA-2026:22325: thunderbird security update (Important)
- ALSA-2026:22553: libexif security update (Moderate)
- ALSA-2026:22312: openssl security update (Moderate)
- ALSA-2026:22721: expat security update (Important)
- ALSA-2026:22644: samba security update (Important)
- ALSA-2026:22140: httpd:2.4 security update (Important)
- ALSA-2026:22315: compat-openssl10 security update (Moderate)
- ALSA-2026:22643: thunderbird security update (Important)
- ALSA-2026:22145: .NET 10.0 security update (Important)
- ALSA-2026:22711: vim security update (Moderate)
- ALSA-2026:22314: openssl security update (Moderate)
- ALSA-2026:22730: vim security update (Moderate)
- ALSA-2026:23231: unbound security update (Important)
- ALSA-2026:22715: expat security update (Important)
- ALSA-2026:23102: delve security update (Important)
- ALSA-2026:22717: vim security update (Moderate)
- ALSA-2026:22551: mod_http2 security update (Moderate)
- ALSA-2026:20606: ruby4.0 security update (Important)
- ALSA-2026:22963: samba security update (Critical)
- ALSA-2026:23258: kernel security update (Important)
- ALSA-2026:23388: php security update (Important)
- ALSA-2026:23259: kernel-rt security update (Important)
Debian GNU/Linux
Debian and Freexian have issued a series of urgent security advisories to address severe flaws across dozens of widely used software packages. These critical updates patch dangerous vulnerabilities that could allow attackers to execute arbitrary code, bypass authentication mechanisms, or steal sensitive user data. System administrators should immediately upgrade essential tools like Sudo, Apache2, Dovecot, and Node.js to prevent privilege escalation and cross-site scripting attacks. Rolling out these patches quickly remains vital for maintaining system integrity and protecting against widespread exploitation attempts.
- [DSA 6312-1] symfony security update
- [DLA 4610-1] git-lfs security update
- [DLA 4612-1] sentry-python security update
- [DLA 4611-1] keystone security update
- [DSA 6316-1] chromium security update
- [DSA 6315-1] cyborg security update
- [DSA 6314-1] swift security update
- [DSA 6313-1] dovecot security update
- [DLA 4613-1] python-aiohttp security update
- ELA-1741-1 imagemagick security update
- ELA-1734-1 nodejs security update
- ELA-1744-1 p7zip-rar security update
- ELA-1743-1 p7zip-rar update
- ELA-1742-1 p7zip security update
- [DSA 6318-1] gst-plugins-good1.0 security update
- [DSA 6317-1] symfony security update
- ELA-1745-1 imagemagick security update
- [DSA 6319-1] yelp security update
- [DSA 6320-1] php-twig security update
- ELA-1739-1 linux-6.1 security update
- ELA-1738-1 linux-5.10 security update
- [DSA 6321-1] ceph security update
- ELA-1746-1 corosync security update
- [DLA 4614-1] sudo security update
- ELA-1748-1 gimp security update (by )
- ELA-1747-1 gimp security update (by )
- [DSA 6322-1] frr security update
- [DLA 4616-1] haveged security update
- [DLA 4615-1] exim4 security update
- ELA-1749-1 exim4 security update (by )
- [DLA 4618-1] gsasl security update
- [DLA 4617-1] dovecot security update
- ELA-1750-1 gsasl security update (by )
- ELA-1751-1 dovecot security update
- [DSA 6324-1] request-tracker5 security update
- [DSA 6323-1] apache2 security update
- [DLA 4619-1] tomcat9 security update
Fedora Linux
Fedora administrators need to install a fresh wave of critical security patches across both version 43 and version 44 right away. These urgent updates tackle dangerous flaws in dozens of widely used tools including web browsers, email clients, database servers, and core system libraries. You will find fixes for zero day exploits, privilege escalation holes, and various rendering bugs that could otherwise compromise your entire network infrastructure. Delaying this installation leaves your systems exposed to serious threats so please prioritize the upgrade process immediately.
- Fedora 43 Update: chromium-148.0.7778.215-1.fc43
- Fedora 43 Update: suricata-7.0.16-1.fc43
- Fedora 43 Update: mingw-objfw-1.5.4-1.fc43
- Fedora 43 Update: objfw-1.5.4-1.fc43
- Fedora 43 Update: nginx-mod-vts-0.2.4-10.fc43
- Fedora 43 Update: nginx-mod-naxsi-1.6-18.fc43
- Fedora 43 Update: nginx-mod-fancyindex-0.6.0-5.fc43
- Fedora 43 Update: perl-Crypt-PasswdMD5-1.4.3-1.fc43
- Fedora 43 Update: nginx-mod-brotli-1.0.0~rc-10.fc43
- Fedora 43 Update: nginx-mod-modsecurity-1.0.4-11.fc43
- Fedora 43 Update: nginx-mod-headers-more-0.39-10.fc43
- Fedora 43 Update: nginx-1.30.2-1.fc43
- Fedora 44 Update: chromium-148.0.7778.215-1.fc44
- Fedora 44 Update: suricata-8.0.5-1.fc44
- Fedora 44 Update: mingw-objfw-1.5.4-1.fc44
- Fedora 44 Update: objfw-1.5.4-1.fc44
- Fedora 44 Update: perl-Crypt-PasswdMD5-1.4.3-1.fc44
- Fedora 44 Update: libsoup3-3.6.6-8.fc44
- Fedora 43 Update: vim-9.2.530-1.fc43
- Fedora 43 Update: libpng-1.6.58-1.fc43
- Fedora 43 Update: perl-Catalyst-Plugin-Authentication-0.10026-1.fc43
- Fedora 43 Update: unbound-1.25.1-1.fc43
- Fedora 43 Update: dovecot-2.4.4-1.fc43
- Fedora 43 Update: postfix-3.10.10-1.fc43
- Fedora 44 Update: samba-4.24.3-1.fc44
- Fedora 44 Update: freeipa-4.13.1-12.fc44
- Fedora 44 Update: hplip-3.26.4-2.fc44
- Fedora 44 Update: perl-Catalyst-Plugin-Authentication-0.10026-1.fc44
- Fedora 44 Update: postfix-3.10.10-1.fc44
- Fedora 44 Update: dovecot-2.4.4-1.fc44
- Fedora 43 Update: hplip-3.26.4-2.fc43
- Fedora 43 Update: python-wsgidav-4.3.4-1.fc43
- Fedora 44 Update: xorg-x11-server-21.1.23-1.fc44
- Fedora 44 Update: python-wsgidav-4.3.4-1.fc44
- Fedora 44 Update: roundcubemail-1.7.1-1.fc44
- Fedora 44 Update: xorg-x11-server-Xwayland-24.1.12-1.fc44
- Fedora 44 Update: pie-1.4.5-1.fc44
- Fedora 43 Update: pie-1.4.5-1.fc43
- Fedora 43 Update: roundcubemail-1.6.16-1.fc43
- Fedora 43 Update: libsoup3-3.6.6-3.fc43
- Fedora 44 Update: transmission-4.1.2-1.fc44
- Fedora 44 Update: libre-4.8.1-1.fc44
- Fedora 44 Update: python-starlette-0.52.1-2.fc44
- Fedora 44 Update: nextcloud-33.0.4-1.fc44
- Fedora 44 Update: perl-Cpanel-JSON-XS-4.41-1.fc44
- Fedora 44 Update: rubygem-yard-0.9.40-2.fc44
- Fedora 44 Update: rust-sequoia-sq-1.3.1-12.fc44
- Fedora 44 Update: rust-sequoia-wot-0.15.2-1.fc44
- Fedora 44 Update: rust-sequoia-chameleon-gnupg-0.13.1-13.fc44
- Fedora 44 Update: rust-sequoia-octopus-librnp-1.11.1-7.fc44
- Fedora 44 Update: rust-sequoia-sop-0.37.3-4.fc44
- Fedora 44 Update: rust-sequoia-cert-store-0.7.3-1.fc44
- Fedora 44 Update: perl-Dist-Build-0.028-1.fc44
- Fedora 44 Update: perl-Crypt-Argon2-0.031-1.fc44
- Fedora 44 Update: perl-ExtUtils-Builder-Compiler-0.036-1.fc44
- Fedora 44 Update: perl-ExtUtils-Builder-0.020-1.fc44
- Fedora 43 Update: transmission-4.1.2-1.fc43
- Fedora 43 Update: freeipa-4.13.1-7.fc43
- Fedora 43 Update: samba-4.23.8-1.fc43
- Fedora 43 Update: libre-4.8.1-1.fc43
- Fedora 43 Update: python-starlette-0.52.1-2.fc43
- Fedora 43 Update: nextcloud-33.0.4-1.fc43
- Fedora 43 Update: perl-Cpanel-JSON-XS-4.41-1.fc43
- Fedora 43 Update: rubygem-yard-0.9.37-5.fc43
- Fedora 43 Update: rust-sequoia-wot-0.15.2-1.fc43
- Fedora 43 Update: rust-sequoia-sq-1.3.1-12.fc43
- Fedora 43 Update: rust-sequoia-chameleon-gnupg-0.13.1-13.fc43
- Fedora 43 Update: rust-sequoia-sop-0.37.3-4.fc43
- Fedora 43 Update: rust-sequoia-octopus-librnp-1.11.1-7.fc43
- Fedora 43 Update: rust-sequoia-cert-store-0.7.3-1.fc43
- Fedora 43 Update: perl-ExtUtils-Builder-Compiler-0.036-1.fc43
- Fedora 43 Update: perl-Dist-Build-0.028-1.fc43
- Fedora 43 Update: perl-ExtUtils-Builder-0.020-1.fc43
- Fedora 43 Update: perl-Crypt-Argon2-0.031-1.fc43
- Fedora 43 Update: jpegxl-0.11.2-1.fc43
- Fedora 43 Update: perl-libwww-perl-6.83-1.fc43
- Fedora 43 Update: perl-HTTP-Tiny-0.094-1.fc43
- Fedora 43 Update: cockpit-362-1.fc43
- Fedora 43 Update: thunderbird-149.0.1-3.fc43
- Fedora 44 Update: firefox-151.0.3-1.fc44
- Fedora 44 Update: webkitgtk-2.52.4-1.fc44
- Fedora 44 Update: rust-1.96.0-1.fc44
- Fedora 44 Update: libinput-1.31.3-1.fc44
- Fedora 43 Update: keylime-7.14.2-1.fc43
- Fedora 43 Update: perl-CryptX-0.089-1.fc43
- Fedora 43 Update: libssh2-1.11.1-6.fc43
- Fedora 44 Update: nasm-3.01-3.fc44
- Fedora 44 Update: keylime-7.14.2-1.fc44
- Fedora 44 Update: perl-CryptX-0.089-1.fc44
Oracle Linux
Oracle recently issued a comprehensive set of security advisories for its enterprise Linux distributions to patch critical flaws in essential system components. The latest releases address widespread vulnerabilities across core libraries and services by updating Apache httpd, the standard Linux kernel, GnuTLS, compat-openssl10, and Podman on versions eight and nine. A separate advisory batch focuses on the Unbreakable Enterprise Kernel alongside common software packages like Thunderbird, PHP 8.2, and core utilities to harden multiple operating system releases. System administrators should prioritize these patches immediately since unaddressed weaknesses could expose production environments to serious exploitation risks.
- ELSA-2026-22140 Important: Oracle Linux 8 httpd:2.4 security update
- ELSA-2026-22315 Moderate: Oracle Linux 8 compat-openssl10 security update
- ELSA-2026-21706 Important: Oracle Linux 8 kernel security update
- ELBA-2026-21706-1 Oracle Linux 8 kernel bug fix update
- ELBA-2026-50292 Oracle Linux 9 podman bug fix update
- ELSA-2026-20611 Important: Oracle Linux 8 gnutls security update
- ELSA-2026-50293 Important: Unbreakable Enterprise kernel security update
- OLAMBA-2026-0014 Oracle Linux 8 ol-automation-manager bug fix update
- ELSA-2026-50293 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update
- ELSA-2026-50294 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update
- ELSA-2026-50294 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update
- ELSA-2026-50294 Important: Oracle Linux 8 Unbreakable Enterprise kernel security update
- ELSA-2026-22643 Important: Oracle Linux 8 thunderbird security update
- ELSA-2026-22305 Important: Oracle Linux 8 php:8.2 security update
- ELSA-2026-22721 Important: Oracle Linux 8 expat security update
- ELSA-2026-50299 Important: Oracle Linux 8 Unbreakable Enterprise kernel security update
- ELSA-2026-50299 Important: Oracle Linux 8 Unbreakable Enterprise kernel security update
- ELBA-2026-50300 Oracle Linux 8 crash bug fix update
- ELBA-2026-50296 Oracle Linux 8 sos bug fix update
- ELSA-2026-50299 Important: Oracle Linux 7 Unbreakable Enterprise kernel security update
Red Hat Enterprise Linux
Red Hat recently rolled out several batches of security advisories that target multiple RHEL releases alongside niche update channels. System administrators need to apply these critical fixes right away since they resolve dangerous flaws in essential tools like PHP, Python, Java, OpenSSL, Firefox, OpenSSH, Samba, and the Linux kernel. The patches cover everything from container platforms to virtual networking utilities across RHEL versions eight through ten. You should check your server environments immediately because unpatched systems remain exposed to moderate and critical vulnerabilities.
- RHSA-2026:22142: Important: php:8.3 security update
- RHSA-2026:22143: Important: php:8.2 security update
- RHSA-2026:22141: Moderate: go-fdo-client and go-fdo-server security update
- RHSA-2026:22134: Important: fence-agents security update
- RHSA-2026:22136: Important: webkitgtk4 security update
- RHSA-2026:22147: Low: qemu-kvm security update
- RHSA-2026:22130: Important: rhc security update
- RHSA-2026:22144: Important: python security update
- RHSA-2026:22135: Important: fence-agents security update
- RHSA-2026:22139: Important: java-1.8.0-ibm security update
- RHSA-2026:22132: Important: resource-agents security update
- RHSA-2026:22131: Important: resource-agents security update
- RHSA-2026:22133: Important: resource-agents security update
- RHSA-2026:22110: Important: ovn25.03 security update
- RHSA-2026:22111: Important: ovn25.09 security update
- RHSA-2026:22305: Important: php:8.2 security update
- RHSA-2026:22304: Important: postgresql-jdbc security update
- RHSA-2026:22309: Important: rhc security update
- RHSA-2026:22325: Important: thunderbird security update
- RHSA-2026:22323: Moderate: libsoup security update
- RHSA-2026:22312: Moderate: openssl security update
- RHSA-2026:22314: Moderate: openssl security update
- RHSA-2026:22313: Moderate: compat-openssl11 security update
- RHSA-2026:22316: Moderate: libsoup security update
- RHSA-2026:22334: Important: kernel security update
- RHSA-2026:22330: Important: fence-agents security update
- RHSA-2026:22329: Important: openssh security update
- RHSA-2026:22328: Important: java-21-ibm-semeru-certified-jdk security update
- RHSA-2026:22326: Moderate: Satellite 6.19.1 Async Update
- RHSA-2026:22324: Important: firefox security update
- RHSA-2026:22317: Moderate: libsoup security update
- RHSA-2026:22315: Moderate: compat-openssl10 security update
- RHSA-2026:22145: Important: .NET 10.0 security update
- RHSA-2026:22146: Important: PackageKit security update
- RHSA-2026:22140: Important: httpd:2.4 security update
- RHSA-2026:22424: Important: tigervnc security update
- RHSA-2026:22420: Moderate: libxml2 security update
- RHSA-2026:22408: Important: firefox security update
- RHSA-2026:22410: Important: firefox security update
- RHSA-2026:22564: Important: openssh update
- RHSA-2026:22553: Moderate: libexif security update
- RHSA-2026:22528: Moderate: mod_http2 security update
- RHSA-2026:22644: Important: samba security update
- RHSA-2026:22643: Important: thunderbird security update
- RHSA-2026:22649: Important: php8.4 security update
- RHSA-2026:22648: Important: openssh security update
- RHSA-2026:22468: Important: openssh security update
- RHSA-2026:22619: Important: Red Hat Data Grid 8.6.1 security update
- RHSA-2026:22456: Important: tigervnc security update
- RHSA-2026:22453: Important: Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 update is now available (RHBQ 3.33.1.GA)
- RHSA-2026:22450: Important: osbuild-composer security update
- RHSA-2026:22409: Important: firefox security update
- RHSA-2026:22712: Important: firefox security update
- RHSA-2026:22711: Moderate: vim security update
- RHSA-2026:22710: Moderate: libsoup security update
- RHSA-2026:22733: Important: osbuild-composer security update
- RHSA-2026:22716: Moderate: libsoup security update
- RHSA-2026:22714: Important: osbuild-composer security update
- RHSA-2026:22713: Important: rhc security update
- RHSA-2026:22709: Important: osbuild-composer security update
- RHSA-2026:22708: Important: firefox security update
- RHSA-2026:22529: Moderate: libexif security update
- RHSA-2026:22551: Moderate: mod_http2 security update
- RHSA-2026:21655: Important: OpenShift Container Platform 4.18.43 packages and security update
- RHSA-2026:22847: Important: firefox security update
- RHSA-2026:22730: Moderate: vim security update
- RHSA-2026:21702: Important: OpenShift Container Platform 4.20.24 bug fix and security update
- RHSA-2026:21701: Moderate: OpenShift Container Platform 4.20.24 packages and security update
- RHSA-2026:22900: Important: kernel-rt security update
- RHSA-2026:22717: Moderate: vim security update
- RHSA-2026:21656: Important: OpenShift Container Platform 4.18.43 bug fix and security update
- RHSA-2026:22721: Important: expat security update
- RHSA-2026:22715: Important: expat security update
- RHSA-2026:23102: Important: delve security update
- RHSA-2026:22987: Important: fence-agents security update
- RHSA-2026:22963: Critical: samba security update
- RHSA-2026:22957: Important: libcap security update
- RHSA-2026:22940: Important: kernel security update
- RHSA-2026:22937: Important: image-builder security update
- RHSA-2026:23254: Important: tigervnc security update
- RHSA-2026:23231: Important: unbound security update
- RHSA-2026:23222: Important: libsndfile security update
- RHSA-2026:23221: Important: libsndfile security update
- RHSA-2026:23103: Important: delve security update
- RHSA-2026:22969: Important: fence-agents security update
- RHSA-2026:23259: Important: kernel-rt security update
- RHSA-2026:23395: Important: kernel security update
- RHSA-2026:22964: Important: kernel security update
- RHSA-2026:23360: Important: bind9.16 security update
- RHSA-2026:23228: Important: image-builder security update
- RHSA-2026:21695: Important: OpenShift Container Platform 4.12.91 bug fix and security update
- RHSA-2026:21690: Important: OpenShift Container Platform 4.13.67 bug fix and security update
- RHSA-2026:23388: Important: php security update
- RHSA-2026:23329: Important: kernel security update
- RHSA-2026:23332: Moderate: mysql security update
- RHSA-2026:23230: Important: expat security update
- RHSA-2026:23229: Important: redis security update
- RHSA-2026:23224: Important: kernel security update
- RHSA-2026:23258: Important: kernel security update
- RHSA-2026:23223: Important: libsndfile security update
- RHSA-2026:23255: Important: tigervnc security update
- RHSA-2026:22970: Important: fence-agents security update
- RHSA-2026:23237: Important: kernel security update
- RHSA-2026:23496: Important: tigervnc security update
- RHSA-2026:23469: Important: kpatch-patch-5_14_0-284_104_1, kpatch-patch-5_14_0-284_117_1, kpatch-patch-5_14_0-284_134_1, kpatch-patch-5_14_0-284_148_1, and kpatch-patch-5_14_0-284_158_1 ...
- RHSA-2026:23468: Important: kpatch-patch-5_14_0-570_17_1, kpatch-patch-5_14_0-570_39_1, kpatch-patch-5_14_0-570_66_1, and kpatch-patch-5_14_0-570_94_1 security update
- RHSA-2026:23470: Important: kpatch-patch-4_18_0-553_109_1, kpatch-patch-4_18_0-553_40_1, kpatch-patch-4_18_0-553_53_1, kpatch-patch-4_18_0-553_72_1, and kpatch-patch-4_18_0-553_85_1 secu ...
- RHSA-2026:23471: Important: kpatch-patch-4_18_0-477_107_1, kpatch-patch-4_18_0-477_120_1, kpatch-patch-4_18_0-477_130_1, kpatch-patch-4_18_0-477_89_1, and kpatch-patch-4_18_0-477_97_1 se ...
- RHSA-2026:23417: Important: flatpak security update
- RHSA-2026:23418: Important: flatpak security update
- RHSA-2026:23419: Important: flatpak security update
- RHSA-2026:23420: Important: flatpak security update
Rocky Linux
Rocky Linux administrators managing versions eight through ten need to apply a broad wave of critical security patches right away. These advisories target essential components like PHP, Apache httpd, OpenSSL, and the system kernel while also updating widely used utilities such as Vim, Thunderbird, and Podman. The updates close dangerous gaps in the code that could otherwise lead to full system compromise. Administrators must install these fixes without delay to keep their networks secure and fully compliant with current industry standards.
- RLSA-2026:22142: Important: php:8.3 security update
- RLSA-2026:22143: Important: php:8.2 security update
- RLSA-2026:22305: Important: php:8.2 security update
- RLSA-2026:22140: Important: httpd:2.4 security update
- RLSA-2026:20612: Important: gnutls security update
- RLSA-2026:22304: Important: postgresql-jdbc security update
- RLSA-2026:19213: Moderate: systemd security update
- RLSA-2026:22312: Moderate: openssl security update
- RLSA-2026:22313: Moderate: compat-openssl11 security update
- RLSA-2026:19173: Important: podman security update
- RLSA-2026:20693: Moderate: mysql8.4 security update
- RLSA-2026:20600: Important: wireshark security update
- RLSA-2026:21380: Important: firefox security update
- RLSA-2026:21754: Important: .NET 9.0 security update
- RLSA-2026:21286: Important: .NET 8.0 security update
- RLSA-2026:20594: Moderate: glibc security update
- RLSA-2026:21433: Important: httpd security update
- RLSA-2026:21757: Important: flatpak security update
- RLSA-2026:21676: Important: cockpit security update
- RLSA-2026:21557: Important: kernel security update
- RLSA-2026:20606: Important: ruby4.0 security update
- RLSA-2026:20567: Important: qt6-qtdeclarative security update
- RLSA-2026:21755: Important: flatpak security update
- RLSA-2026:22315: Moderate: compat-openssl10 security update
- RLSA-2026:22730: Moderate: vim security update
- RLSA-2026:22721: Important: expat security update
- RLSA-2026:23102: Important: delve security update
- RLSA-2026:22528: Moderate: mod_http2 security update
- RLSA-2026:22715: Important: expat security update
- RLSA-2026:20613: Important: gnutls security update
- RLSA-2026:22711: Moderate: vim security update
- RLSA-2026:22529: Moderate: libexif security update
- RLSA-2026:22314: Moderate: openssl security update
- RLSA-2026:22937: Important: image-builder security update
- RLSA-2026:22145: Important: .NET 10.0 security update
- RLSA-2026:22141: Moderate: go-fdo-client and go-fdo-server security update
- RLSA-2026:22450: Important: osbuild-composer security update
- RLSA-2026:22325: Important: thunderbird security update
- RLSA-2026:22649: Important: php8.4 security update
- RLSA-2026:22717: Moderate: vim security update
- RLSA-2026:23230: Important: expat security update
- RLSA-2026:22551: Moderate: mod_http2 security update
- RLSA-2026:22553: Moderate: libexif security update
- RLSA-2026:23228: Important: image-builder security update
- RLSA-2026:23231: Important: unbound security update
- RLSA-2026:23388: Important: php security update
- RLSA-2026:23360: Important: bind9.16 security update
- RLSA-2026:22643: Important: thunderbird security update
Slackware Linux
Slackware Linux administrators need to apply several urgent security patches right away after the release of multiple critical vulnerability fixes across core system components. The kernel update specifically targets dangerous flaws within the rxrpc networking module while a separate advisory covers essential upgrades for HTTPd, Proftpd, TigerVNC, Net-Tools, and Xorg-Server. You should also apply the rolling current branch patches for libinput and dnsmasq immediately to prevent potential exploitation of known security weaknesses that could compromise your entire network infrastructure. Delaying these installations leaves servers exposed so regular maintenance routines must prioritize these official Slackware Security Team advisories without hesitation.
- kernel (SSA:2026-152-01)
- httpd (SSA:2026-154-01)
- proftpd (SSA:2026-154-03)
- tigervnc (SSA:2026-154-05)
- net-tools (SSA:2026-154-02)
- xorg-server (SSA:2026-154-04)
- libinput (SSA:2026-155-02)
- dnsmasq (SSA:2026-155-01)
SUSE Linux
SUSE recently pushed out several major update cycles that tackle dozens of dangerous security flaws across its openSUSE and enterprise Linux platforms. You really need to apply these patches immediately since the unpatched vulnerabilities could easily let attackers run arbitrary code or steal system access. The updates span everything from the core kernel and database engines to printing utilities and Python libraries. Administrators should prioritize these installations across all supported versions because delayed deployment leaves critical services like OpenSSH, Grafana, and MariaDB exposed to well-documented exploits that could compromise entire networks.
- SUSE-SU-2026:2149-1: important: Security update for the Linux Kernel (Live Patch 30 for SUSE Linux Enterprise 15 SP5)
- SUSE-SU-2026:2141-1: important: Security update for the Linux Kernel (Live Patch 45 for SUSE Linux Enterprise 15 SP4)
- SUSE-SU-2026:2159-1: important: Security update for the Linux Kernel (Live Patch 36 for SUSE Linux Enterprise 15 SP5)
- SUSE-SU-2026:2172-1: important: Security update for the Linux Kernel (Live Patch 21 for SUSE Linux Enterprise 15 SP6)
- SUSE-SU-2026:2158-1: important: Security update for the Linux Kernel (Live Patch 49 for SUSE Linux Enterprise 15 SP4)
- SUSE-SU-2026:2176-1: important: Security update for the Linux Kernel (Live Patch 2 for SUSE Linux Enterprise 15 SP7)
- SUSE-SU-2026:2202-1: important: Security update for the Linux Kernel
- SUSE-SU-2026:2200-1: important: Security update for the Linux Kernel (Live Patch 22 for SUSE Linux Enterprise 15 SP6)
- SUSE-SU-2026:2204-1: important: Security update for busybox
- SUSE-SU-2026:2199-1: important: Security update for the Linux Kernel (Live Patch 17 for SUSE Linux Enterprise 15 SP6)
- openSUSE-SU-2026:20852-1: important: Security update for roundcubemail
- openSUSE-SU-2026:20849-1: important: Security update for chromium
- openSUSE-SU-2026:20842-1: important: Security update for openjpeg2
- openSUSE-SU-2026:20846-1: important: Security update for python-python-multipart
- openSUSE-SU-2026:20851-1: important: Security update for putty
- openSUSE-SU-2026:20847-1: important: Security update for postgresql-jdbc
- openSUSE-SU-2026:20841-1: important: Security update for apache-commons-lang3, apache-commons-text, apache-commons-configuration2, apache-commons-cli, apache-commons-io, apache-commons-codec
- openSUSE-SU-2026:20845-1: important: Security update for libsoup
- openSUSE-SU-2026:10896-1: moderate: libzypp-17.38.10-1.1 on GA media
- openSUSE-SU-2026:10895-1: moderate: libsolv-demo-0.7.38-1.1 on GA media
- openSUSE-SU-2026:10890-1: moderate: ffmpeg-8-8.1.1-3.1 on GA media
- openSUSE-SU-2026:10892-1: moderate: ignition-2.26.0-4.1 on GA media
- openSUSE-SU-2026:10893-1: moderate: java-26-openjdk-26.0.1.0-1.1 on GA media
- openSUSE-SU-2026:10891-1: moderate: gsasl-2.2.3-1.1 on GA media
- SUSE-SU-2026:2195-1: important: Security update for the Linux Kernel
- SUSE-SU-2026:2197-1: important: Security update for strongswan
- SUSE-SU-2026:2191-1: important: Security update for the Linux Kernel (Live Patch 51 for SUSE Linux Enterprise 15 SP4)
- SUSE-SU-2026:2207-1: important: Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise 15 SP7)
- openSUSE-SU-2026:0181-1: critical: Security update for re
- SUSE-SU-2026:2214-1: important: Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise 15 SP7)
- SUSE-SU-2026:2212-1: important: Security update for the Linux Kernel (Live Patch 39 for SUSE Linux Enterprise 15 SP5)
- SUSE-SU-2026:2215-1: important: Security update for the Linux Kernel
- SUSE-SU-2026:2216-1: important: Security update for the Linux Kernel
- SUSE-SU-2026:2218-1: important: Security update for python3-Twisted
- SUSE-SU-2026:2219-1: important: Security update for python-Twisted
- openSUSE-SU-2026:0182-1: important: Security update for libjxl
- SUSE-SU-2026:2222-1: critical: Security update for hplip
- SUSE-SU-2026:2223-1: important: Security update for xorg-x11-server
- SUSE-SU-2026:2224-1: important: Security update for xorg-x11-server
- SUSE-SU-2026:2226-1: important: Security update for xorg-x11-server
- openSUSE-SU-2026:20857-1: important: Security update for mapserver
- openSUSE-SU-2026:20855-1: important: Security update for ffmpeg-4
- openSUSE-SU-2026:20856-1: important: Security update for shadowsocks-v2ray-plugin
- openSUSE-SU-2026:20854-1: important: Security update for rqlite
- openSUSE-SU-2026:20858-1: critical: Security update for hplip
- openSUSE-SU-2026:10908-1: moderate: cloudflared-2026.5.2-1.1 on GA media
- openSUSE-SU-2026:10904-1: moderate: vorbis-tools-1.4.3-2.1 on GA media
- openSUSE-SU-2026:10909-1: moderate: kubelogin-0.2.18-1.1 on GA media
- openSUSE-SU-2026:10905-1: moderate: LibVNCServer-devel-0.9.15-3.1 on GA media
- openSUSE-SU-2026:10903-1: moderate: libunbound8-1.25.1-1.1 on GA media
- openSUSE-SU-2026:20893-1: important: Security update for cloudflared
- openSUSE-SU-2026:20888-1: important: Security update for apptainer
- openSUSE-SU-2026:20887-1: important: Security update for python-PyMuPDF
- openSUSE-SU-2026:20892-1: important: Security update for yq
- openSUSE-SU-2026:20885-1: moderate: Security update for python-Flask
- openSUSE-SU-2026:20886-1: moderate: Security update for python-CairoSVG
- openSUSE-SU-2026:20877-1: important: Security update for rsync
- openSUSE-SU-2026:20884-1: important: Security update for memcached
- openSUSE-SU-2026:20883-1: important: Security update for busybox
- openSUSE-SU-2026:20878-1: important: Security update for sdbootutil
- openSUSE-SU-2026:20880-1: moderate: Security update for python-pip
- openSUSE-SU-2026:20871-1: important: Security update for python-urllib3_1
- openSUSE-SU-2026:20875-1: important: Security update for ovmf
- openSUSE-SU-2026:20860-1: important: Security update for helm
- openSUSE-SU-2026:20891-1: moderate: Security update for vorbis-tools
- openSUSE-SU-2026:20861-1: important: Security update for python-urllib3
- openSUSE-SU-2026:20863-1: important: Security update for tree-sitter
- openSUSE-SU-2026:20889-1: moderate: Security update for tor
- openSUSE-SU-2026:20864-1: moderate: Security update for evolution-data-server
- openSUSE-SU-2026:10917-1: moderate: libsoup-2_4-1-2.74.3-21.1 on GA media
- openSUSE-SU-2026:10916-1: moderate: libgphoto2-6-2.5.34-1.1 on GA media
- openSUSE-SU-2026:10915-1: moderate: bind-9.20.23-2.1 on GA media
- openSUSE-SU-2026:10919-1: moderate: apache-sshd-2.18.0-1.1 on GA media
- openSUSE-SU-2026:10913-1: moderate: golang-github-v2fly-v2ray-core-5.51.2-1.1 on GA media
- openSUSE-SU-2026:10911-1: moderate: libsoup-3_0-0-3.6.6-5.1 on GA media
- openSUSE-SU-2026:10912-1: moderate: restic-0.18.1-3.1 on GA media
- openSUSE-SU-2026:10910-1: moderate: libjxl-devel-0.11.2-2.1 on GA media
- openSUSE-SU-2026:10914-1: moderate: atril-1.28.4-1.1 on GA media
- SUSE-SU-2026:2252-1: important: Security update for salt
- SUSE-SU-2026:2256-1: important: Security update for salt
- SUSE-SU-2026:2259-1: moderate: Security update for python3-pyOpenSSL
- SUSE-SU-2026:2261-1: moderate: Security update for python-pyOpenSSL
- SUSE-SU-2026:2265-1: moderate: Maintenance update for Multi-Linux Manager 4.3 Release Notes Release Notes
- SUSE-SU-2026:2231-1: important: Security update for glibc
- SUSE-SU-2026:2234-1: important: Security update for python-Pillow
- SUSE-SU-2026:2235-1: important: Security update for evince
- SUSE-SU-2026:2232-1: important: Security update for evince
- SUSE-SU-2026:2236-1: important: Security update for vim
- openSUSE-SU-2026:0188-1: moderate: Security update for tor
- openSUSE-SU-2026:0191-1: moderate: Security update for perl-HTTP-Tiny
- openSUSE-SU-2026:0189-1: moderate: Security update for cacti
- openSUSE-SU-2026:20897-1: moderate: Security update for python-pyOpenSSL
- openSUSE-SU-2026:20902-1: important: Security update for keybase-client
- openSUSE-SU-2026:20895-1: moderate: Security update for libsoup2
- openSUSE-SU-2026:20901-1: important: Security update for postgresql18
- openSUSE-SU-2026:20896-1: important: Security update for xorg-x11-server
- openSUSE-SU-2026:20898-1: important: Security update for frr
- openSUSE-SU-2026:10928-1: moderate: vifm-0.14.4-1.1 on GA media
- openSUSE-SU-2026:10929-1: moderate: weblate-5.17.1-1.1 on GA media
- openSUSE-SU-2026:10927-1: moderate: tomcat11-11.0.22-1.1 on GA media
- openSUSE-SU-2026:10920-1: moderate: cacti-1.2.30+git457.e55c2aea-1.1 on GA media
- openSUSE-SU-2026:10925-1: moderate: tomcat-9.0.118-1.1 on GA media
- openSUSE-SU-2026:10926-1: moderate: tomcat10-10.1.55-1.1 on GA media
- openSUSE-SU-2026:10924-1: moderate: perl-Sereal-Decoder-5.6.0-1.1 on GA media
- openSUSE-SU-2026:10922-1: moderate: grafana-11.6.14+security01-4.1 on GA media
- openSUSE-SU-2026:10923-1: moderate: mcphost-0.34.0-8.1 on GA media
- openSUSE-SU-2026:10921-1: moderate: google-guest-agent-20260529.00-1.1 on GA media
- SUSE-SU-2026:2281-1: important: Security update for unbound
- SUSE-SU-2026:2282-1: critical: Security update for mariadb
- SUSE-SU-2026:2280-1: important: Security update for ignition
- SUSE-SU-2026:2284-1: critical: Security update for mariadb
- SUSE-SU-2026:2285-1: important: Security update for yq
- openSUSE-SU-2026:0192-1: critical: Security update for kanidm
- openSUSE-SU-2026:10938-1: moderate: perl-HTTP-Daemon-6.170.0-1.1 on GA media
- openSUSE-SU-2026:10937-1: moderate: openssh-10.3p1-6.1 on GA media
- openSUSE-SU-2026:10939-1: moderate: perl-IO-Compress-2.220.0-1.1 on GA media
- openSUSE-SU-2026:10936-1: moderate: libopenbabel8-3.2.0-1.1 on GA media
- openSUSE-SU-2026:10935-1: moderate: libmozjs-115-0-115.15.0-9.1 on GA media
- openSUSE-SU-2026:10934-1: moderate: libmariadbd-devel-11.8.8-1.1 on GA media
- openSUSE-SU-2026:10931-1: moderate: ffmpeg-4-4.4.7-3.1 on GA media
- openSUSE-SU-2026:10933-1: moderate: hauler-1.4.3-5.1 on GA media
- openSUSE-SU-2026:10932-1: moderate: grafana-11.6.14+security04-1.1 on GA media
Ubuntu Linux
Ubuntu recently distributed multiple batches of critical security patches that address severe vulnerabilities across dozens of widely deployed system packages and applications. These updates resolve dangerous flaws in foundational software like the Linux kernel, Nginx web server, MySQL database, and Apache HTTP service to stop attackers from escalating privileges or leaking sensitive data. System administrators must apply these fixes promptly because unpatched servers face immediate risks of remote code execution and complete service outages. Keeping core utilities and external tools current remains a fundamental requirement for maintaining secure Linux infrastructure.
- [USN-8349-1] rsync vulnerabilities
- [USN-8357-1] Qt Declarative vulnerability
- [USN-8055-2] Evolution Data Server vulnerability
- [USN-8350-1] Linux kernel (NVIDIA Tegra) vulnerabilities
- [USN-8351-1] Linux kernel (Low Latency) vulnerabilities
- [LSN-0120-1] Linux kernel vulnerability
- [USN-8361-1] Linux kernel vulnerability
- [USN-8209-2] Little CMS vulnerability
- [USN-8360-1] sslh vulnerability
- [USN-8359-1] NNCP vulnerability
- [USN-8358-1] haveged vulnerability
- [USN-8355-1] SSSD vulnerability
- [USN-8352-1] LibreOffice vulnerability
- [USN-8356-1] GNU SASL vulnerability
- [USN-8354-1] nginx vulnerabilities
- [USN-8353-1] Exim vulnerability
- [USN-8373-1] Linux kernel vulnerabilities
- [USN-8370-1] Linux kernel vulnerabilities
- [USN-8371-1] Linux kernel vulnerabilities
- [USN-8363-1] MySQL vulnerabilities
- [USN-8362-1] XZ Utils vulnerability
- [USN-8282-2] Unbound vulnerabilities
- [USN-8374-1] Linux kernel vulnerabilities
- [USN-8238-2] EditorConfig vulnerability
- [USN-8372-1] age vulnerability
- [USN-8366-1] Luanti vulnerabilities
- [USN-8368-1] libeconf vulnerability
- [USN-8367-1] tar-fs vulnerabilities
- [USN-8369-1] Apache Tomcat Connectors vulnerability
- [USN-8364-1] Apache Commons Lang vulnerability
- [USN-8365-1] Dovecot vulnerabilities
- [USN-8348-1] GoBGP vulnerabilities
- [USN-8344-3] pip vulnerability
- [USN-8130-2] GStreamer Base Plugins vulnerability
- [USN-8375-1] nginx vulnerabilities
- [USN-8363-2] MySQL vulnerabilities
- [USN-8376-1] FRR vulnerabilities
- [USN-8377-1] Template-Toolkit vulnerability
- [USN-8379-1] urllib3 vulnerabilities
- [USN-8380-1] Twisted vulnerability
- [USN-8378-1] libwww-perl vulnerability
- [USN-8382-1] Exim vulnerabilities
- [USN-8384-1] Apache HTTP Server vulnerability
- [USN-8386-1] Nano vulnerabilities
- [USN-8393-1] Linux kernel (Azure FIPS) vulnerabilities
- [USN-8361-2] Linux kernel (FIPS) vulnerability
- [USN-8388-1] Linux kernel vulnerabilities
- [USN-8392-1] Linux kernel vulnerabilities
- [USN-8391-1] Linux kernel (Raspberry Pi) vulnerabilities
- [USN-8390-1] Linux kernel vulnerability
- [USN-8389-1] Linux kernel vulnerabilities
- [USN-8394-1] YARD vulnerability
- [USN-8253-2] Postfix vulnerability
- [USN-8383-1] Tomcat vulnerabilities
- [USN-8385-1] Robocode vulnerabilities
Keep Your Linux System Secure: Safely Applying Critical Updates
Applying these patches requires distribution-specific package management commands. RHEL-based systems typically use dnf update or yum update, while Debian and Ubuntu rely on apt upgrade. SUSE users should run zypper patch to properly address all security advisories, and Slackware administrators can manage updates with upgradepkg or slackpkg. After executing the commands, a reboot is usually necessary for kernel changes to take effect. Finally, review your package manager’s logs to verify that all patches installed successfully and no dependencies were disrupted.
Debian/Ubuntu (apt)
The first thing to do is refresh the local package index; running sudo apt update contacts all configured repositories and pulls in the newest lists of available versions. Skipping this step leaves the system blind to any recent uploads, which explains why “upgrade” sometimes claims there’s nothing to do even after a security advisory has been published. Once the index is current, invoke sudo apt upgrade -y; the -y flag answers every prompt automatically so the process doesn’t pause for user input. This command upgrades all installed packages that have newer versions in the repositories while preserving configuration files.
sudo apt update sudo apt upgrade -y
Fedora/RedHat/Rocky/Alma/Oracle (dnf or yum)
On modern Fedora and recent Red Hat derivatives, dnf is the package manager; older RHEL releases still rely on yum. Begin with a check‑update operation—sudo dnf check-update or sudo yum check-update—to see exactly which packages are awaiting an upgrade. This preview step can be useful for spotting unexpected kernel bumps before they land. To actually apply the updates, run sudo dnf upgrade -y (or sudo yum update if you prefer the older tool). The upgrade command pulls down the new binaries and runs any necessary post‑install scripts, such as rebuilding initramfs when a kernel changes.
sudo dnf check-update sudo dnf upgrade -y
or on older releases
sudo yum check-update sudo yum update
SUSE (zypper)
SUSE’s command line front‑end is called zypper. First execute sudo zypper refresh so that the metadata for all enabled repos gets updated; without this, zypper will happily report “No updates available” even though newer packages sit on the mirror. After a fresh refresh, issue sudo zypper update -y; this upgrades every package to the latest version in the configured repositories and automatically handles service restarts when required.
sudo zypper refresh sudo zypper update -y
Slackware (slackpkg and pkgtool)
Slackware doesn’t have a single unified updater, but the official way to pull updates is through slackpkg. Start with sudo slackpkg update to download the newest package list from the chosen mirror. Then run sudo slackpkg upgrade-all; this command walks through each installed package and replaces it with the most recent build available in the official repository. For users who prefer a more granular approach, specifying a package name after upgrade limits the operation to that single item. When dealing with community‑maintained repositories, pkgtool takes over: a combined sudo pkgtool update && sudo pkgtool upgrade will sync and apply updates from the mirrors listed in /etc/slackpkg/mirrors.
sudo slackpkg update sudo slackpkg upgrade-all
The update queues are full this week, so grab a coffee and let the package managers do their work. If automated patching is in place, verify those jobs ran successfully and check for any service restarts that might have failed. For manual updates, prioritize Samba, OpenSSL, and your web server before moving on to the smaller libraries. Stay safe out there, and try not to be the admin who wakes up to a support ticket because they skipped one critical patch.