Skip to content
Threat Feed

Tag

Cloud-Native

29 briefs RSS
high advisory

Remote Code Execution Vulnerability in SUSE NeuVector

An OS command injection vulnerability in the packet-capture filter component of SUSE NeuVector allows for unauthenticated remote code execution on affected Kubernetes nodes.

NeuVector vulnerability rce kubernetes cloud-native
1t
critical advisory

CVE-2026-100706: Path Traversal in Kyverno Policy apiCall Processing

Kyverno versions before 1.19.1 contain a path traversal vulnerability in apiCall urlPath processing, enabling namespace-restricted users to perform unauthorized cluster-wide object manipulation via URL-encoded segments.

kyverno +2 path-traversal kubernetes privilege-escalation vulnerability cloud-native
2t 1c
high advisory

Unauthenticated Information Disclosure in OpenShift Console via CatalogdHandler

A misconfiguration in the OpenShift Console CatalogdHandler allows unauthenticated remote attackers to leak internal operator-catalog data and relay requests into the catalogd namespace.

OpenShift Console vulnerability cloud-native identity-management
1t 1c
high advisory

Command Injection Vulnerability in KubeEdge NodeUpgradeJob

An authenticated remote code execution vulnerability (CVE-2026-62371) in the KubeEdge v1alpha2 API allows attackers to inject shell commands via the NodeUpgradeJob resource.

KubeEdge +1 vulnerability rce cloud-native
1t 1c
medium advisory

Detection of Unauthorized Interactive Kubernetes API Probing

Adversaries performing hands-on-keyboard enumeration within compromised containers are detected by correlating interactive process execution with forbidden Kubernetes API audit responses.

Kubernetes +1 execution discovery cloud-native container-security container threat-detection
3t updated
high advisory

Authentication Bypass in Trigger.dev via GitHub App Installation Binding

Trigger.dev versions before 4.6.0 contain an authentication bypass vulnerability allowing attackers to hijack GitHub App installations and gain unauthorized repository access by manipulating state cookies and installation identifiers.

Trigger.dev authentication-bypass github-integration cloud-native
1t 1c
high advisory

Information Disclosure Vulnerability in multicluster-observability-addon

A configuration reference vulnerability in the multicluster-observability-addon allows a managed cluster identity to bypass namespace restrictions and exfiltrate sensitive hub-level secrets.

multicluster-observability-addon vulnerability cloud-native kubernetes
1t 1c
high advisory

Authentication Bypass in KubeEdge CloudCore Node Task Reporting

KubeEdge CloudCore versions through 1.23.1 contain an authentication bypass vulnerability allowing unauthenticated remote attackers to manipulate node upgrade status reports via port 10002.

KubeEdge CloudCore vulnerability cloud-native kubernetes
1c
critical advisory

Unauthenticated Remote Access in argocd-mcp via CVE-2026-82456

The argocd-mcp component version 0.8.0 insecurely binds its HTTP transport to all network interfaces and lacks authentication for MCP sessions when an API token is present, allowing remote attackers to perform unauthorized Argo CD resource modifications.

argocd-mcp vulnerability remote-code-execution cloud-native cicd
2t 1c
critical advisory

Unauthenticated Mutating Operations in Argo Rollouts Dashboard

Argo Rollouts dashboard versions 1.10.0 and earlier expose sensitive, mutating operations without authentication, authorization, or CSRF protection when bound to all network interfaces.

Argo Rollouts vulnerability cloud-native kubernetes
1t 1c
high advisory

Multiple Vulnerabilities in SUSE Rancher

SUSE Rancher contains multiple vulnerabilities that enable unauthenticated attackers to trigger denial of service, perform unauthorized information disclosure, and bypass security controls.

Rancher vulnerability cloud-native suse
2t
critical advisory

Lighthouse Cross-Namespace Resource Injection Vulnerability

A vulnerability in Submariner Lighthouse allows a compromised spoke cluster to inject unauthorized EndpointSlices and ServiceImports into peer cluster namespaces, leading to potential privilege escalation.

Lighthouse cloud-native kubernetes privilege-escalation submariner
1t 1c
high advisory

Red Hat Advanced Cluster Management Lighthouse Component DNS Hijacking

A vulnerability in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes allows a compromised spoke cluster to perform Man-in-the-Middle attacks via malicious EndpointSlice advertisements.

Advanced Cluster Management for Kubernetes kubernetes vulnerability cloud-native cve
2t 1c
high advisory

Privilege Escalation in HashiCorp Vault Secrets Operator

A vulnerability in the HashiCorp Vault Secrets Operator allows a remote, authenticated attacker to escalate privileges, leading to potential unauthorized data disclosure or manipulation within Kubernetes environments.

Vault Secrets Operator privilege-escalation kubernetes cloud-native cve
1t 1c
high threat

CVE-2026-66782: Token Exposure in Submariner Operator

The Submariner operator exposes long-lived service account tokens within Custom Resource specifications, allowing attackers with RBAC access to gain full control over mesh network resources.

exploited Submariner operator credential-access kubernetes cloud-native
1t 1c
high advisory

Broken Access Control in Rainbond API

Rainbond through version 6.9.7 contains an Insecure Direct Object Reference (IDOR) vulnerability (CVE-2026-72741) in the CheckToken function, allowing authenticated attackers to access or modify resources of other enterprise tenants.

Rainbond idor cloud-native broken-access-control
1r 1t 1c
critical advisory

Red Hat Multicluster Engine Confused Deputy Vulnerability

An authenticated tenant can exploit CVE-2026-73266 in the Red Hat Multicluster Engine clusterclaims-controller to perform a cross-tenant cluster join, enabling the unauthorized injection of workloads and policies.

Multicluster Engine for Kubernetes cve-2026-73266 kubernetes privilege-escalation multitenancy cloud-native vulnerability cve-2026-66794 supply-chain
4t 1c updated
high advisory

CVE-2026-18949: Privilege Escalation via Overly Permissive Service Account in Open Data Hub

A vulnerability in the Open Data Hub odh-dashboard allows an attacker with a compromised Service Account token to escalate to cluster-administrator privileges due to excessive RBAC permissions.

odh-dashboard privilege-escalation cloud-native kubernetes
2t 1c
high advisory

Improper Authorization in Data Science Pipelines (CVE-2026-18620)

An authorization bypass vulnerability in Data Science Pipelines allows restricted tenants to execute containers with elevated privileges by specifying a highly-privileged ServiceAccount in a CreateRun request.

Data Science Pipelines privilege-escalation kubeflow cloud-native
1t 1c
critical threat

Denial of Service Vulnerability in Red Hat Multicluster Engine for Kubernetes

A vulnerability in Red Hat Multicluster Engine for Kubernetes allows an unauthenticated remote attacker to trigger a denial of service condition by exploiting a software flaw.

exploited multicluster engine for Kubernetes denial-of-service kubernetes cloud-native vulnerability privilege-escalation cloud-security cve
2t updated
medium threat

Detection of Container Tunneling and Port Forwarding Tools

Elastic has released a detection rule for its Defend for Containers integration, identifying the use of tunneling and port forwarding tools within Linux containers, indicating potential threat actor activity such as command-and-control, data exfiltration, or lateral movement.

exploited container-security cloud-native command-and-control data-exfiltration lateral-movement linux
1r 2t
high advisory

Potential Kubeletctl Execution Detected in Containers

Detection engineers should be aware of the execution of `kubeletctl` within Linux containers, a tool attackers can leverage for discovery and lateral movement by interacting directly with the Kubelet API, potentially leading to unauthorized access and resource hijacking within a Kubernetes cluster.

Kubernetes +2 container cloud-native execution discovery threat-detection linux
1r 3t
high advisory

Suspicious Process Execution in Containers from Transient Directories

Adversaries exploit containerized environments by executing malicious code or interactive shells from transient, low-trust directories like /tmp or /dev/shm, or using executables with hidden names, to evade detection, establish persistence, and facilitate data exfiltration.

container-security cloud-native kubernetes linux defense-evasion execution command-and-control
1r 4t
high advisory

CRIU Restartable Sequences Vulnerability Allows Container Privilege Escalation

A flaw, CVE-2026-18107, in CRIU's handling of restartable sequences (rseq) during checkpoint/restore allows a malicious process inside a container to hijack CRIU's parasite code injection, enabling the spoofing of process credentials in the checkpoint image and leading to elevated capabilities and zeroed UIDs/GIDs upon restore.

CRIU +3 container-security privilege-escalation linux cloud-native
1t 1c
high advisory

OS Command Injection in AWS CDK NodejsFunction Docker Bundling (CVE-2026-13760)

An OS command injection vulnerability, CVE-2026-13760, in AWS CDK's `aws-cdk-lib` package before version 2.260.0 allows an attacker to execute arbitrary commands on the host running the CDK toolchain by injecting shell metacharacters into dependency version strings within a project's `package.json` file when using Docker-based NodejsFunction bundling.

aws-cdk-lib command-injection supply-chain cloud-native aws-cdk vulnerability
1t 1c
high advisory

CVE-2026-15584 Privilege Escalation in OpenShift incluster-checks Tool

A privilege escalation vulnerability, CVE-2026-15584, in Red Hat OpenShift's incluster-checks tool allows users with standard edit roles to obtain root access on cluster nodes by exploiting privileged debug pods with host filesystem access created in the shared default namespace.

OpenShift +1 privilege-escalation vulnerability red-hat kubernetes cloud-native
1t 1c
critical advisory

Nuclio Controller Vulnerability Leads to Persistent Kubernetes RCE (GHSA-v5px-423j-pf7p)

The Nuclio controller improperly sanitizes user-controlled input (cron trigger event headers and body) before injecting it into `curl` commands executed by Kubernetes CronJobs, allowing remote attackers to perform command injection and achieve remote code execution (RCE) by breaking quoting contexts in header keys or utilizing shell command substitution in event bodies, leading to arbitrary command execution with root privileges and potential persistence within the Kubernetes cluster.

Nuclio <= 1.15.27 remote-code-execution kubernetes cloud-native command-injection persistence critical-vulnerability ghsa
2r 3t 2i
high advisory

Rancher Fleet Unauthenticated Webhook Regex Injection (CVE-2026-44937)

An unauthenticated regex injection vulnerability exists in Rancher Fleet's webhook endpoint when it's configured without a secret, allowing attackers to forge webhook requests using unsanitized repository URL components, which leads to continuous repository re-cloning, causing network and resource exhaustion (Denial of Service) on the management cluster, and potentially service downgrades if the attacker has read access to the target Git repository.

Fleet +3 rancher vulnerability webhook regex-injection denial-of-service cloud-native kubernetes supply-chain
1t
high advisory

CVE-2026-50107: NGINX Gateway Fabric Configuration Injection Vulnerability

An injection vulnerability, CVE-2026-50107, exists in the NGINX configuration generator component of NGINX Gateway Fabric when configured with NGINX Plus or NGINX Open Source as the data plane, allowing authenticated attackers with CRD modification permissions to inject arbitrary NGINX configuration directives via unsanitized user-supplied string values in the access log format setting, leading to control plane compromise and potential defense evasion or system impact.

PoC NGINX Plus +10 config-injection nginx kubernetes cloud-native web-vulnerability cve
2r 1t 5c 2i updated