Our automated tracking framework flagged that CISA added CVE-2015-5287 (Red Hat Automatic Bug Reporting Tool) to the Known Exploited Vulnerabilities (KEV) catalog on August 30, 2026. A KEV listing is CISA’s official confirmation that the flaw is being exploited in the wild — U.S. federal agencies must patch it by a fixed deadline. Here is what our data shows.
What CISA Reported
CISA describes the flaw as follows: “Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.”
Under Binding Operational Directive rules, U.S. federal agencies must remediate CVE-2015-5287 by September 9, 2026 — a 14-day window. Private organizations are not bound by the deadline, but CISA treats it as the benchmark for how urgently a confirmed-exploited flaw should be patched.
The Details
| CVE | CVE-2015-5287 |
| Vendor / product | Red Hat Automatic Bug Reporting Tool |
| Vulnerability | Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability |
| CVSS base score | 7.8 |
| Added to KEV | August 26, 2026 |
| Days public before listing (NVD → KEV lag) | 3915 |
| Federal patch deadline | September 9, 2026 |
| Known ransomware use | No |
How This Compares to Red Hat’s Track Record
This one was public for 3915 days before CISA confirmed exploitation — longer than Red Hat’s 3915-day median, a vulnerability that sat exploitable in the open. Red Hat currently ranks #1 on our KEV Lag leaderboard.
| Red Hat in the CISA KEV catalog | Value |
|---|---|
| Tracked KEV entries | 9 |
| Median lag (public → KEV listing) | 3915 days |
| 0-day rate (exploited at or before disclosure) | 0% |
| Entries tied to known ransomware campaigns | 3 |
For perspective, the median across all 1684 tracked KEV entries is 267 days — Red Hat’s exploited vulnerabilities are flagged slower than the catalog average.
Other Recent Red Hat KEV Additions
The most recent Red Hat vulnerabilities CISA has confirmed as actively exploited, from our tracker:
| CVE | Product | Added to KEV | Lag (days) | Ransomware |
|---|---|---|---|---|
| CVE-2015-3246 | Libuser | August 26, 2026 | 4033 | No |
| CVE-2018-14667 | JBoss RichFaces Framework | September 28, 2023 | 1787 | No |
| CVE-2021-3560 | Polkit | May 12, 2023 | 450 | No |
| CVE-2021-4034 | Polkit | June 27, 2022 | 150 | No |
| CVE-2010-1428 | JBoss | May 25, 2022 | 4410 | ⚠️ Yes |
What This Means for Defenders
CISA has added CVE-2015-5287, a privilege escalation vulnerability in the Red Hat Automatic Bug Reporting Tool, to its Known Exploited Vulnerabilities (KEV) catalog. The CVE has a CVSS base score of 7.8. Federal agencies must patch by September 9, 2026; all organizations should prioritize patching before then. Its addition to KEV confirms active exploitation.
The vulnerability was made public 3915 days before its KEV listing on August 26, 2026, indicating a persistent threat. There’s no known ransomware use for CVE-2015-5287, but its privilege escalation nature means attackers can use it for deeper network infiltration and lateral movement. It’s a risk to organizations using the Red Hat Automatic Bug Reporting Tool.
For systems where immediate patching isn’t feasible, restrict network access to vulnerable systems, implement strong access controls, and monitor for unusual activity related to the Automatic Bug Reporting Tool. Prompt action is essential to mitigate exploitation risk.
Related Coverage
- Critical Microsoft SharePoint Flaw CVE-2026-50522 (CVSS 9.8) Added to CISA KEV (July 2026)
- WordPress’s CVE-2026-63030 Was Exploited in 4 Days — Well Under Its 420-Day Median (July 2026)
How We Track This
This report was generated from our CISA KEV Lag Tracker, which syncs the official CISA KEV catalog daily and records the date each CVE is added. For every entry we retrieve the original NVD publication date and compute the lag in calendar days. No dates or figures on this page are estimated or taken from third-party sources — they come directly from CISA and NVD records.