De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et un déni de service à distance.
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et un déni de service à distance.
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et un déni de service à distance.
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et un déni de service à distance.
CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability CVE-2019-1068 Microsoft SQL Server Remote Code Execution Vulnerability CVE-2021-23758 Ajax.NET Professional Deserialization of Untrusted Data Vulnerability CVE-2022-0995 Linux Kernel Out-of-Bounds Write Vulnerability…
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.9, CVEs: CVE-2026-67567, Summary: A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller processes Helm chart templates using its own elevated ServiceAccount privileges without proper validation. This enables the…
CISA added CVE-2015-5287 to the Known Exploited Vulnerabilities catalog. Affected product: Red Hat Automatic Bug Reporting Tool. Remediation due date: 2026-09-09.
Red Hat heeft meerdere kwetsbaarheden verholpen in Keycloak. De kwetsbaarheid met CVE-2026-18963 kan een ongeauthenticeerde externe aanvaller in staat stellen om elke gebruikersaccount over te nemen door een wachtwoordreset af te dwingen. Door deze kwetsbaarheid valt het e-mailverificatieproces bij wachtwoordreset te omzeilen en wachtwoorden van gebruikers te wijzigen. In Keycloak zijn daarnaast kwetsbaarheden aanwezig in de Fine-Grained Admin Permissions (FGAP) v2, waardoor bepaalde beheerders…
Classification: Severe, Solution: Not Defined, Exploit Maturity: Not Defined, CVSSv3.1: 9.9, CVEs: CVE-2026-66788, CVE-2026-66787, Summary: Flaws were found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. See also: https://access.redhat.com/security/cve/cve-2026-66787
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et un déni de service à distance.
Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.3, CVEs: CVE-2026-66794, Summary: A flaw was found in the cluster-proxy-addon component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks.
Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.9, CVEs: CVE-2026-70496, CVE-2026-71470, CVE-2026-76139, Summary: Several vulnerabilities fixed. See also: https://access.redhat.com/security/cve/cve-2026-71470, See also: https://access.redhat.com/security/cve/CVE-2026-76139
Classification: Severe, Solution: Not Defined, Exploit Maturity: Not Defined, CVSSv3.1: 9.6, CVEs: CVE-2026-71365, CVE-2026-12564, Summary: Two vulnerabilities fixed in Red Hat Ansible Automation Platform 2. See also: https://access.redhat.com/security/cve/cve-2026-71365
Classification: Severe, Solution: Not Defined, Exploit Maturity: Not Defined, CVSSv3.1: 9.1, CVEs: CVE-2026-66795, Summary: A flaw was found in the managedcluster-import-controller. Successful exploitation can lead to privilege escalation, enabling the attacker to obtain administrative credentials on the hub cluster.
Classification: Severe, Solution: Not Defined, Exploit Maturity: Not Defined, CVSSv3.1: 9.9, CVEs: CVE-2026-66780, CVE-2026-66783, CVE-2026-66782, CVE-2026-66781, CVE-2026-75924, CVE-2026-75485, CVE-2026-73834, CVE-2026-66793, CVE-2026-71472, CVE-2026-70495, Summary: Multiple vulnerabilities published in Red Hat Advanced Cluster Management for Kubernetes 2
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et un déni de service à distance.
Serial Number: AV26-803Date: August 11, 2026 As of August 5, 2026, Red Hat is affected by a vulnerability in the following product: Red Hat Advanced Cluster Management for Kubernetes 2 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CVE-2026-10090 - Red Hat Customer Portal 2483292 – (CVE-2026-10090) CVE-2026-10090 multicluster-operators-subscription: multicluster-operators-subscription: namespace…
Dnešní vydání našich Postřehů z bezpečnosti přináší informace o tom, jak malware řídil armádu WordPressů přes platformu Steam nebo jak se nechal omámit asistent Google Gemini. Dále si na Root.cz můžete přečíst o balíčcích Red Hatu kradoucí přístupové údaje a o českém projektu Phishguard Sentinel chránící internetové uživatele.
Multiple official @redhat-cloud-services npm packages were compromised with a credential-stealing worm derived from the open-sourced Mini Shai-Hulud malware, targeting cloud credentials, and developer tooling across CI/CD pipelines. Category: Vulnerabilities & Threats
On 1 June 2026, Wiz Research identified a supply chain compromise affecting multiple packages published under the @redhat-cloud-services npm namespace. Investigation revealed that at least 29 package releases contained unauthorized modifications that did not match the correspo...
Following two days of intense competition, Day Three of Pwn2Own Berlin 2026 brought the curtain down on an incredible event. Security researchers delivered their final exploits, pushing enterprise systems to the limit one last time as the race for Master of Pwn came to a close.Day Three added to an already historic event, bringing the final totals to $1,298,250 awarded for 47 unique 0-day vulnerabilities across three days of competition. DEVCORE claimed the title of Master of Pwn with a…
Day Two of Pwn2Own Berlin 2026 and the stakes continue to rise! Security researchers are back on the Pwn2Own stage, pushing enterprise systems to their limits as the competition heats up. More exploits, more surprises, and more standout moments are unfolding, so follow along here for live updates as the race for Master of Pwn intensifies. There were plenty of big targets on the schedule today, including SharePoint, Exchange, and Safari.Following an action-packed Day One where $523,000 was…