{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/argo-cd--3.6.0-rc1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:peering-manager:peering_manager:*:*:*:*:*:*:*:*","cpe:2.3:o:amazon:freertos:*:*:*:*:*:*:*:*","cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":3.5,"id":"CVE-2024-28113"},{"cvss":8.1,"id":"CVE-2024-28114"},{"cvss":8.8,"id":"CVE-2024-28115"},{"cvss":8.8,"id":"CVE-2024-28116"},{"cvss":8.8,"id":"CVE-2026-55797"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Argo CD (\u003c= 10.6.1)","Argo CD (\u003e= 2.11.0, \u003c= 2.14.21)","Argo CD (\u003e= 3.0.0, \u003c 3.3.15)","Argo CD (\u003e= 3.4.0, \u003c 3.4.10)","Argo CD (\u003e= 3.5.0, \u003c 3.5.4)","Argo CD (= 3.6.0-rc1)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","cloud","kubernetes"],"_cs_type":"advisory","_cs_vendors":["Argo Project"],"content_html":"\u003cp\u003eArgo CD, a popular continuous delivery tool for Kubernetes, is impacted by a set of critical vulnerabilities identified as CVE-2024-28113, CVE-2024-28114, CVE-2024-28115, and CVE-2024-28116. These flaws collectively enable unauthenticated or authenticated remote attackers to achieve remote code execution, exfiltrate sensitive configuration data and credentials, bypass existing access control mechanisms, or perform denial of service attacks against the infrastructure.\u003c/p\u003e\n\u003cp\u003eGiven that Argo CD frequently operates with administrative privileges within a Kubernetes cluster to manage deployments, successful exploitation of these vulnerabilities compromises the security posture of the entire target cluster. Security teams should prioritize patching affected instances to prevent attackers from hijacking continuous deployment workflows or extracting secrets stored within Argo CD configuration.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows for full compromise of the Argo CD instance. Attackers can gain code execution, access sensitive Kubernetes secrets or environment variables, and modify delivery pipelines to propagate malicious payloads to production environments. This impact is significant for organizations relying on GitOps workflows, as the integrity of the entire software supply chain is at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching all internet-facing and internal Argo CD deployments to the latest secure version provided by the Argo Project. Verify that access to the Argo CD API and management interface is restricted to authorized administrative users only. Implement egress filtering for the Argo CD pod to prevent unauthorized connections to external C2 infrastructure in the event of partial compromise.\u003c/p\u003e\n","date_modified":"2026-10-09T21:28:53Z","date_published":"2026-10-08T19:20:51Z","id":"https://feed.craftedsignal.io/briefs/2026-10-argo-cd-vulnerabilities/","summary":"Argo CD is affected by multiple vulnerabilities including CVE-2024-28113, CVE-2024-28114, CVE-2024-28115, and CVE-2024-28116, which allow for remote code execution, unauthorized information disclosure, and security control bypasses.","title":"Multiple Vulnerabilities in Argo CD","url":"https://feed.craftedsignal.io/briefs/2026-10-argo-cd-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Argo CD (= 3.6.0-Rc1)","version":"https://jsonfeed.org/version/1.1"}