
🚨 UPDATE: RED HAT ANSIBLE AUTOMATION PLATFORM — SECOND CRITICAL (CVE-2026-84719) + PUBLISHED FIXES FOR AAP 2.6 / 2.4 Following yesterday’s CVE-2026-84502 Critical post, Red Hat has now published the companion errata and a second Critical controller flaw that operators should treat as part of the same patch cycle. • CVE-2026-84719 — CVSS 9.9 Critical — WorkflowJobTemplate /copy/ deep-copy sanitizer omitted InstanceGroup use_role checks, so a workflow-admin could pin jobs onto unauthorized instance groups, including the control-plane group • CVE-2026-84502 — CVSS 9.9 Critical — remains in scope (previously covered): privilege escalation via the controller API • Fixes published: AAP 2.6 RHSA-2026:71113 (automation-controller 4.7.17); AAP 2.4 RHSA-2026:71115 (automation-controller 4.5.36) • AAP 2.6 carries a large Critical RHSA batch; AAP 2.4 receives the high-impact subset • No confirmed in-the-wild exploitation is called out in the RHSA notes reviewed here ⚠️ Analyst Note: This is an UPDATE to the earlier single-CVE post, not a rehash. The new signal is CVE-2026-84719 plus the published RHSA fix streams for both supported AAP trains. Controllers that were only tracked against 84502 should still be upgraded using the errata above. Official Red Hat: https://access.redhat.com/errata/RHSA-2026:71113 https://access.redhat.com/errata/RHSA-2026:71115 https://access.redhat.com/security/cve/cve-2026-84719 #RedHat #Ansible #AAP #CVE202684719 #CVE202684502 #Critical #RCE #ThreatIntel #DDW

