CVE-2026-18355
Product added on 2026-09-08.
Red Hat Directory Server 12.4 e4s for RHEL 9View the record on cve.org →Report an error on this page →
What changed, and when
2 editsPublished
1 day after publicationProduct addedSee this edit in the CVE record history (commit 027e8cadabf5)
- Now lists Red Hat Directory Server 12.4 e4s for RHEL 9and 1 more
- Now lists Red Hat Directory Server 11.9 for RHEL 8
- Now lists Red Hat Enterprise Linux 8.6 Extended Update Support long-life add-on
same dayExcluded: likely not a real changeSee this edit in the CVE record history (commit 5ac3a04f7408)
- Now lists Red Hat Enterprise Linux 10.0 Extended Update Support
- Now lists Red Hat Enterprise Linux 9.6 Extended Update Support
Why we filtered it out: support or installation label under already affected red hat/red hat enterprise linux 10; the record does not establish whether this newly names affected scope or refines the existing product listing.
same dayProduct addedSee this edit in the CVE record history (commit 1c56a3678d0a)
- Now lists Red Hat Directory Server 12.2 e4s for RHEL 9and 1 more
- Now lists Red Hat Directory Server 11.7 e4s for RHEL 8
- Now lists Red Hat Enterprise Linux 8.4 Extended Update Support long-life add-onand 2 more
- and 2 more of the 8 products in this edit
same dayExcluded: likely not a real changeSee this edit in the CVE record history (commit 5b089778644a)
- Now lists Red Hat Enterprise Linux 7 Extended Lifecycle Support
Why we filtered it out: probable relabelling of red hat/red hat enterprise linux 7, not a newly affected product.
no further change since that editLatest data
“Product added” is a product the record names now and did not name when it was published. Where a publisher renamed or replaced a product, the new name appears here and the record may no longer list the old one.
Every change links to the publisher's own edit. Verify one yourself →
What this page can and cannot tell you
A date here is the first day we saw the new value; the publisher may have changed it earlier without our copy catching it. Edits after 2026-09-08 are not shown.
11 differences were filtered out as likely false positives. They are marked on the timeline, counted in no figure, and shown so you can disagree.
No GitHub advisory names this CVE, so no advisory changes are shown.
Does a change here mean the vendor got it wrong?
A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.