Skip to content
Threat Feed

Product

Multicluster Engine for Kubernetes

4 briefs RSS
critical advisory

Red Hat Multicluster Engine Confused Deputy Vulnerability

An authenticated tenant can exploit CVE-2026-73266 in the Red Hat Multicluster Engine clusterclaims-controller to perform a cross-tenant cluster join, enabling the unauthorized injection of workloads and policies.

Multicluster Engine for Kubernetes cve-2026-73266 kubernetes privilege-escalation multitenancy cloud-native vulnerability cve-2026-66794 supply-chain
4t 1c updated
critical threat

Denial of Service Vulnerability in Red Hat Multicluster Engine for Kubernetes

A vulnerability in Red Hat Multicluster Engine for Kubernetes allows an unauthenticated remote attacker to trigger a denial of service condition by exploiting a software flaw.

exploited multicluster engine for Kubernetes denial-of-service kubernetes cloud-native vulnerability privilege-escalation cloud-security cve
2t updated
critical advisory

CVE-2026-16242: Konnectivity Proxy-Server Authentication Bypass

A critical authentication bypass vulnerability, CVE-2026-16242, exists in the Konnectivity proxy-server configuration for hosted control planes, allowing a remote unauthenticated attacker to connect as an agent and potentially proxy, inspect, modify, or drop control-plane-to-node traffic due to improper client certificate validation.

Logging Subsystem for Red Hat OpenShift +2 kubernetes cloud vulnerability authentication-bypass redhat
4t 1c
critical advisory

Red Hat Advanced Cluster Management and Multicluster Engine Vulnerability Allows Remote Code Execution or DoS

A remote, authenticated attacker can exploit a vulnerability in Red Hat Advanced Cluster Management and Multicluster engine for Kubernetes to execute arbitrary program code or cause a denial of service condition.

Advanced Cluster Management +1 kubernetes rce dos redhat
2r 2t