CISA KEV Alert 8/26/2026, 10:55:12 PM

CISA flags Red Hat ABRT flaw CVE-2015-5287 as actively exploited

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

CISA has added CVE‑2015‑5287 to its Known Exploited Vulnerabilities (KEV) catalogue. The vulnerability affects Red Hat’s Automatic Bug Reporting Tool (ABRT) and is named the Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability. It allows a local user with certain permissions to escalate privileges through a symlink attack on a file with a predictable name.

CVE‑2015‑5287 is a local privilege‑escalation flaw in ABRT. An attacker who can write to a predictable file location can create a symlink that causes ABRT to write or execute with elevated privileges, leading to full root access. The vulnerability has a CVSS v3 score of 7.8, rated HIGH. A patch is available via Red Hat advisory RHSA‑2015‑2505. The flaw requires local access and the ability to write to a predictable file location used by ABRT during problem reporting.

Because the entry is in the KEV catalogue, active exploitation in the wild has been confirmed. No public reports link this flaw to ransomware campaigns at this time. CISA has set a remediation deadline of 9 September 2026 for federal civilian executive branch (FCEB) agencies to address the issue. The KEV catalogue is maintained by CISA to highlight vulnerabilities that are being actively exploited in the wild throughout.

CISA requires agencies to apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26‑04 Prioritizing Security Updates Based on Risk and CISA’s “Forensics Triage Requirements”. For cloud services, follow the applicable BOD 26‑04 guidance or discontinue use of the product if mitigations cannot be applied. Stakeholders must evaluate each asset’s internet exposure and adhere to BOD 26‑04 patching guidelines.

For full details, see the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2015-5287 and the CISA KEV catalogue.

View CISA KEV Entry

Article by CyberSIXT