Apache cloudstack
This hub aggregates every CVE we track for Apache cloudstack, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
51
CVEs tracked
9
Critical
25
High
0
In CISA KEV
Severity distribution
HIGH25MEDIUM16CRITICAL9LOW1
Monthly trend
3
1
0
1
0
0
0
0
5
0
0
0
0
2
0
0
0
0
0
7
0
0
20
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Apache cloudstack.
- CVE-2026-59654Apache CloudStack: DoS caused by database connections leak7.5
- CVE-2026-47359Apache CloudStack: OS Command Injection due to unsanitized mount command8.8
- CVE-2026-50112Apache CloudStack: RCE and SSRF in direct download, metalink and NFS templates8.8
- CVE-2026-50222Apache CloudStack: Improper access control in Userdata reference APIs7.5
- CVE-2026-59085Apache CloudStack: Server-Side Request Forgery (SSRF) vulnerability in webhook module9.1
- CVE-2026-59655Apache CloudStack: Unauthenticated OAuth provider client-secret disclosure7.5
- CVE-2026-59657Apache CloudStack: Sensitive Information Disclosure via Cleartext Storage in AsyncJob7.5
- CVE-2026-59780Apache CloudStack: LDAP provider configuration disclosure7.5
- CVE-2026-59799Apache CloudStack: Missing Privilege Check in Two-Factor Authentication Disable Flow8.8
- CVE-2026-61397Apache CloudStack: OAuth2 Token Cross-Request Leak7.5
- CVE-2026-61398Apache CloudStack: Cross-Site Scripting (XSS) Vulnerability in Instance Reset Password Function in UI9.1
- CVE-2026-61399Apache CloudStack: Cross-Site Scripting (XSS) Vulnerability in Lock User Function in UI4.8
- CVE-2026-61400Apache CloudStack: Get and Run Diagnostics Command Injection8.8
- CVE-2026-61422Apache CloudStack: Authenticated pre-validation SSRF in registerTemplate4.3
- CVE-2026-62440Apache CloudStack: Improper access control in Kubernetes Service (CKS) cluster manipulation9.1
Product normalization is registry-driven with AI assist and human review. How it works