Red hat advanced cluster management for kubernetes 2
This hub aggregates every CVE we track for Red hat advanced cluster management for kubernetes 2, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
26
CVEs tracked
3
Critical
11
High
0
In CISA KEV
Severity distribution
HIGH11MEDIUM11CRITICAL3LOW1
Monthly trend
0
0
0
1
0
1
1
0
0
0
1
2
1
0
1
1
1
0
1
5
0
1
1
1
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Red hat advanced cluster management for kubernetes 2.
- CVE-2026-10090Multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped clusterrolebinding and become cluster-admin via application subscription9.9
- CVE-2026-16242Hypershift: konnectivity proxy-server accepts agent connections without validating client certificates9.4
- CVE-2026-11332Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution7.8
- CVE-2026-33812Excessive memory allocation when decoding malicious SFNT in golang.org/x/image6.1
- CVE-2026-32280Unexpected work during chain building in crypto/x5097.5
- CVE-2026-32288Unbounded allocation for old GNU sparse in archive/tar5.5
- CVE-2026-32289JsBraceDepth Context Tracking Bugs (XSS) in html/template6.1
- CVE-2026-33810Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x5098.2
- CVE-2026-33748BuildKit Git URL subdir component can cause access to restricted files7.5
- CVE-2025-11065Github.com/go-viper/mapstructure/v2: go-viper's mapstructure may leak sensitive information in logs in github.com/go-viper/mapstructure5.3
- CVE-2025-14874Nodemailer: nodemailer: denial of service via crafted email address header7.5
- CVE-2025-13033Nodemailer: nodemailer: email to an unintended domain can occur due to interpretation conflict7.5
- CVE-2025-10894Nx: nx/devkit: malicious versions of nx and plugins published to npm9.6
- CVE-2025-7195Operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd6.4
- CVE-2025-8556Github.com/cloudflare/circl: circl-fourq: missing and wrong validation can lead to incorrect results3.7
Product normalization is registry-driven with AI assist and human review. How it works