Classification: Critical, Solution: Not Defined, Exploit Maturity: Not Defined, CVSSv3.1: 9.1, CVEs: CVE-2026-18963, Summary: A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining…
Classification: Severe, Solution: Not Defined, Exploit Maturity: Not Defined, CVSSv3.1: 9.6, CVEs: CVE-2026-71365, CVE-2026-12564, Summary: Two vulnerabilities fixed in Red Hat Ansible Automation Platform 2. See also: https://access.redhat.com/security/cve/cve-2026-71365
Classification: Severe, Solution: Not Defined, Exploit Maturity: Not Defined, CVSSv3.1: 9.1, CVEs: CVE-2026-66795, Summary: A flaw was found in the managedcluster-import-controller. Successful exploitation can lead to privilege escalation, enabling the attacker to obtain administrative credentials on the hub cluster.
Classification: Severe, Solution: Not Defined, Exploit Maturity: Not Defined, CVSSv3.1: 9.9, CVEs: CVE-2026-66780, CVE-2026-66783, CVE-2026-66782, CVE-2026-66781, CVE-2026-75924, CVE-2026-75485, CVE-2026-73834, CVE-2026-66793, CVE-2026-71472, CVE-2026-70495, Summary: Multiple vulnerabilities published in Red Hat Advanced Cluster Management for Kubernetes 2
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et un déni de service à distance.
Serial Number: AV26-803Date: August 11, 2026 As of August 5, 2026, Red Hat is affected by a vulnerability in the following product: Red Hat Advanced Cluster Management for Kubernetes 2 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CVE-2026-10090 - Red Hat Customer Portal 2483292 – (CVE-2026-10090) CVE-2026-10090 multicluster-operators-subscription: multicluster-operators-subscription: namespace…
Dnešní vydání našich Postřehů z bezpečnosti přináší informace o tom, jak malware řídil armádu WordPressů přes platformu Steam nebo jak se nechal omámit asistent Google Gemini. Dále si na Root.cz můžete přečíst o balíčcích Red Hatu kradoucí přístupové údaje a o českém projektu Phishguard Sentinel chránící internetové uživatele.
Multiple official @redhat-cloud-services npm packages were compromised with a credential-stealing worm derived from the open-sourced Mini Shai-Hulud malware, targeting cloud credentials, and developer tooling across CI/CD pipelines. Category: Vulnerabilities & Threats
On 1 June 2026, Wiz Research identified a supply chain compromise affecting multiple packages published under the @redhat-cloud-services npm namespace. Investigation revealed that at least 29 package releases contained unauthorized modifications that did not match the correspo...
Following two days of intense competition, Day Three of Pwn2Own Berlin 2026 brought the curtain down on an incredible event. Security researchers delivered their final exploits, pushing enterprise systems to the limit one last time as the race for Master of Pwn came to a close.Day Three added to an already historic event, bringing the final totals to $1,298,250 awarded for 47 unique 0-day vulnerabilities across three days of competition. DEVCORE claimed the title of Master of Pwn with a…
Day Two of Pwn2Own Berlin 2026 and the stakes continue to rise! Security researchers are back on the Pwn2Own stage, pushing enterprise systems to their limits as the competition heats up. More exploits, more surprises, and more standout moments are unfolding, so follow along here for live updates as the race for Master of Pwn intensifies. There were plenty of big targets on the schedule today, including SharePoint, Exchange, and Safari.Following an action-packed Day One where $523,000 was…