CVE coverage

AlmaLinux 8 CVE tracker

Noxen pulls AlmaLinux 8 CVE data from the same upstream sources Red Hat publishes against (RHEL 8 binary-compatible). NVD provides the upstream advisory; OSV's Red Hat ecosystem feed provides the rpm-level fix versions. AlmaLinux 8 has active maintenance through May 2029, so security errata land on the same cadence as RHEL 8.

Live

Headline numbers

  • Total CVE records (all distros)Loading…
  • Last buildLoading…
  • OSV records (RH ecosystem + others)Loading…
  • NVD records (cross-platform)Loading…

How matching works

What Noxen does for an AlmaLinux 8 host

  1. Reads /etc/os-release to confirm AlmaLinux 8 (RHEL 9 binary-compatible).
  2. Reads rpm -qa for installed packages, including epoch and release.
  3. Filters the local feed cache to OSV records tagged with ecosystem AlmaLinux:8 / Red Hat:8, plus NVD records whose CPE matches the installed packages.
  4. Compares installed vs fix versions using rpm version semantics (epoch:version-release).
  5. Emits findings only where the installed version is strictly older than the fix.

Live listings

Top recent critical CVEs (Red Hat ecosystem (RHEL / Rocky / AlmaLinux))

Most-recently-published critical CVEs in the Red Hat ecosystem (RHEL / Rocky / AlmaLinux). Auto-deduped to one row per CVE ID. Snapshot baked at ; live re-fetch on page load.

CVESev.CVSSSummaryPackageFix inPublished
RLSA-2026:76763critical9.1Important: dovecot security, bug fix, and enhancement updatedovecot1:2.3.16-16.el8_10
RLSA-2026:75673critical9.1Important: mariadb-connector-c security updatemariadb-connector-c0:3.2.6-2.el9_8
RLSA-2026:75674critical9.1Important: mariadb-connector-c security updatemariadb-connector-c0:3.1.11-3.el8_10
RLSA-2026:73979critical9.3Critical: freerdp security updatefreerdp2:3.10.3-12.el10_2.13
RLSA-2026:74084critical9.6Critical: webkit2gtk3 security updatewebkit2gtk30:2.54.0-1.el8_10
RLSA-2026:72279critical9.8Critical: ipa security, bug fix, and enhancement updateipa0:4.13.4-1.el10_2
RLSA-2026:71487critical9.8Critical: unbound security updateunbound0:1.24.2-3.el9_8.8
RLSA-2026:71419critical9.8Critical: unbound security updateunbound0:1.24.2-7.el10_2.6

Top recent high-severity CVEs (Red Hat ecosystem (RHEL / Rocky / AlmaLinux))

CVESev.CVSSSummaryPackageFix inPublished
RLSA-2026:76737high7.4Important: rust-sequoia-sq security, bug fix, and enhancement updaterust-sequoia-sq0:1.4.0.1-2.el10_2
RLSA-2026:76734high7.4Important: rust-rpm-sequoia security, bug fix, and enhancement updaterust-rpm-sequoia0:1.10.2.1-1.el10_2
RLSA-2026:76743high7.5Important: opentelemetry-collector security updateopentelemetry-collector0:0.158.0-1.el10_2
RLSA-2026:76762high7.5Important: perl-DBI security updateperl-DBI0:1.643-26.el10_2.7
RLSA-2026:76735high7.4Important: rust-sequoia-sqv security updaterust-sequoia-sqv0:1.3.0.2-1.el10_2
RLSA-2026:76733high7.4Important: rust-rpm-sequoia security updaterust-rpm-sequoia0:1.10.2.1-1.el9_8
RLSA-2026:75768high7.3Important: vim security updatevim2:8.2.2637-26.el9_8.23
RLSA-2026:76747high8.8Important: freerdp security updatefreerdp2:2.11.7-14.el8_10

New to severity terminology? CVE, CVSS, CWE, CPE explained.

Notable

Recent CVEs that AlmaLinux 8 fleets care about.

FAQ

Frequently asked about AlmaLinux 8 CVEs

Is AlmaLinux 8 still supported in 2026?

Yes - AlmaLinux 8 tracks RHEL 8's active maintenance phase through May 2029. Security errata continue to land for the full window; the project also publishes its own errata stream cross-referenced with Red Hat's.

How is AlmaLinux 8 different from AlmaLinux 9 for CVE tracking?

Different package version sets, different backport lines. The same upstream CVE typically has separate fix versions in the RHEL 8 channel and the RHEL 9 channel. Noxen reads rpm -qa and /etc/os-release to pick the right ecosystem filter automatically.

How do I check AlmaLinux 8 CVEs on a host?

For a quick check: dnf updateinfo list security. For per-CVE detail with fix versions, Noxen reads rpm package state over SSH and matches against the live ecosystem feed using rpm version semantics (epoch:version-release).

Will Noxen flag a CVE that AlmaLinux 8 has already backported a fix for?

No. Red Hat-family distros backport security fixes without changing the upstream version number - the fix shows up as a higher release field (the part after the dash in epoch:version-release). Noxen compares the installed epoch:version-release against the fixed package version using rpm version semantics, so a host that has applied the backported errata is correctly shown as patched rather than as a false positive.

Which AlmaLinux 8 CVEs should I patch first?

Severity alone is a poor sort key. Noxen ranks findings by exposure first - a high-severity CVE in a package behind an internet-facing service outranks a critical one in a library nothing reaches - then by CVSS and EPSS. The EPSS prioritisation guide walks through the reasoning.

Scan an AlmaLinux 8 fleet with Noxen

Add your AlmaLinux 8 hosts via your existing ~/.ssh/config; Noxen reads rpm package state and matches against the live signed feed. No agent, no SaaS round-trip. $12/month, or $120/year.

← back to the CVE dashboard   AlmaLinux 9 →   Rocky 9 →