Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.17.1 security update
🔗 CVE IDs covered (63)
📋 Description
CVE-2026-10090 — multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped ClusterRoleBinding and become cluster-admin via Application Subscription
CVE-2026-13676 — fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization
CVE-2026-14362 — github.com/hashicorp/memberlist: HashiCorp memberlist: Denial of Service via push/pull state handling
CVE-2026-18874 — volsync-addon-controller: volsync-addon-controller: annotation values rendered into YAML via text/template without escaping allows YAML injection into Subscription
CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass
CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries
CVE-2026-33377 — grafana: Grafana: Privilege escalation via dashboard overwrite
CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API
CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint
CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering
CVE-2026-44740 — github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation
CVE-2026-44990 — sanitize-html: sanitize-html: Stored Cross-Site Scripting via HTML sanitizer bypass
CVE-2026-45623 — postcss: PostCSS: Information disclosure and denial of service via crafted CSS input
CVE-2026-46384 — github.com/hamba/avro/v2: github.com/linkedin/goavro/v2: Integer Overflow in Avro Decoder
CVE-2026-46385 — github.com/hamba/avro/v2: github.com/linkedin/goavro/v2: CPU Exhaustion in Avro Decoder via Unbounded Block-Count Iteration
CVE-2026-46600 — golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing
CVE-2026-47219 — find-my-way: find-my-way: Denial of Service vulnerability in HTTP/2 server
CVE-2026-48586 — thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data
CVE-2026-53488 — github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin
CVE-2026-54272 — ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification
CVE-2026-55677 — github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy
CVE-2026-55969 — thrift: github.com/apache/thrift: Apache Thrift: Denial of Service via integer overflow or wraparound
CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input
CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents
CVE-2026-64927 — multicloud-operators-channel: multicloud-operators-channel: cross-namespace Secret and ConfigMap mutation via spec.secretRef.namespace confused deputy
CVE-2026-66780 — submariner-operator: submariner-operator: flat broker trust model grants every spoke full CRUD on all endpoints, secrets, and endpointslices in broker namespace
CVE-2026-66781 — submariner-operator: submariner-operator: IPsec PSK stored cleartext in Submariner CR spec
CVE-2026-66792 — multicloud-operators-subscription: multicloud-operators-subscription: IsClusterAdmin() trusts user-settable annotations on managed clusters
CVE-2026-66793 — governance-policy-addon-controller: governance-policy-addon-controller: arbitrary container image override via ManagedClusterAddOn annotation enables RCE on spoke
CVE-2026-66797 — cluster-backup-operator: cluster-backup-operator: Velero Restore includes cluster-scoped RBAC resources with no exclusion — tampered backup yields hub cluster-admin
CVE-2026-66798 — cluster-backup-operator: cluster-backup-operator: Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods
CVE-2026-66799 — cluster-backup-operator: cluster-backup-operator: Restore.spec.namespaceMapping pass-through enables cross-namespace Secret/ConfigMap placement
CVE-2026-66800 — cluster-backup-operator: cluster-backup-operator: CleanupAll triggers unguarded cluster-wide mass-delete via operator ServiceAccount
CVE-2026-66804 — console: console: authenticated SSRF via /ansibletower allows arbitrary host access with full response disclosure
CVE-2026-66805 — console: console: stored DOM XSS via unescaped pod logs in document.write
CVE-2026-66878 — multicloud-operators-subscription: multicloud-operators-subscription: FetchChannelReferences honours Channel.spec.secretRef.namespace enabling cross-namespace Secret exfiltration
CVE-2026-67213 — nanoid: nanoid: Denial of Service via infinite loop in random ID generation
CVE-2026-67214 — nanoid: nanoid: Denial of Service via negative size input in non-secure module functions
CVE-2026-67567 — multicloud-operators-subscription: multicloud-operators-subscription: HelmRelease chart applied with controller SA without GVK or namespace restriction
CVE-2026-69153 — postcss: PostCSS: Information disclosure via crafted sourceMappingURL
CVE-2026-69192 — ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass
CVE-2026-70398 — multicloud-integrations: multicloud-integrations: GitOpsCluster.spec.argoServer.argoNamespace writes spoke bearer tokens to attacker-chosen namespace
CVE-2026-70495 — search-v2-operator: search-v2-operator: cluster-wide impersonate on users/groups shared across 4 pods grants hub system:masters
CVE-2026-70496 — search-v2-operator: search-v2-operator: operator ClusterRole is cluster-admin equivalent via impersonate, RBAC write, CSR approve, and ManifestWork
CVE-2026-71467 — acm-search-v2-api-rhel9: search-v2-api: Authentication bypass on /federated via Upgrade: websocket header spoofing
CVE-2026-71468 — acm-search-v2-api-rhel9: search-v2-api: Cross-user bearer-token reuse via global federation-config cache
CVE-2026-71469 — acm-search-v2-api-rhel9: search-v2-api: Unbounded tokenReviews cache allows unauthenticated memory-exhaustion DoS
CVE-2026-71470 — acm-search-v2-rhel9: search-v2-operator: Search CR imageOverride/arguments/envVar flow unsanitized into pods running impersonating SA
CVE-2026-71471 — acm-search-v2-rhel9: search-v2-operator: Hub Search CR Collector.ImageOverride propagated to every spoke as arbitrary container image
CVE-2026-71472 — acm-search-v2-rhel9: search-v2-operator: Shell-command and SQL injection in postgresql-start.sh via CR-supplied WORK_MEM
CVE-2026-71473 — acm-search-v2-rhel9: search-v2-operator: addonfactory.GetValuesFromAddonAnnotation enables arbitrary Helm-values override per spoke
CVE-2026-71474 — insights-client-rhel9: insights-client: Pull-secret bearer token written to logs on non-200 CCX response
CVE-2026-71475 — insights-client-rhel9: insights-client: Spoke-controlled ClusterID injected unencoded into Insights API URL path
CVE-2026-71845 — insights-client: insights-client: CCX_TOKEN bearer credential logged in clear text at startup via setDefault()
CVE-2026-71846 — insights-client: insights-client: ClusterRole grants cluster-wide secrets get/list/watch beyond least privilege
CVE-2026-72508 — multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke ServiceAccounts bound to wildcard RBAC (//*)
CVE-2026-72526 — multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation
CVE-2026-73086 — nanoid: nanoid: Predictable ID generation due to integer overflow
CVE-2026-73122 — multicloud-operators-channel: multicloud-operators-channel: auto-generated Role grants every managed-cluster agent secrets:get,list,watch in Channel namespaces
CVE-2026-73137 — multicloud-operators-subscription: multicloud-operators-subscription: cross-namespace Secret exfiltration via HelmRelease.repo.secretRef.namespace
CVE-2026-73834 — must-gather: must-gather: embedded Secret data in ACM wrapper CRs collected without redaction
CVE-2026-75485 — must-gather: must-gather: cluster Proxy object dumped raw, bypassing inspect redaction of proxy basic-auth credentials
CVE-2026-76827 — search-indexer: search-indexer: UPDATE/DELETE operations not scoped to caller's cluster (cross-tenant data tampering)
🎯 Affected products185
- Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:7033bc8a548375b2c0bab115098017b83166f194b7316de462ee0ef2e9b02dc9_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:81bf840f056f7b39a5e6f03a933356a1702e0a959014313ba0f579c871124389_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:bf841011e85c72f5ac5b5053b934d24ed22ada2d81ccbe06fe1674feaaf0f641_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:d8cf07a883a9e4e1d58289dbf541fd67a48c3751629aee995c51a98048bf2ed4_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:14f7cf32bf88a55240d2051c351eba8d04f331f6370de6a2835cd15aa3cb3c00_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:2d042eb4e9baa8e3e34fb89bfae2794ac3440bc4f2c2ff12fe69f7b1ef31b61d_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:85ecae5864fa41b1c7350b6cc1f0533fcd855c7e7f2d3b34e0b2d5cd5fa189ba_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:bbc88fa78f9bc9dfef03fcea1315d34c8d2e915814815a7767315e44ab10aeed_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:47dcf655e2a500a44a0bd9f9c31cfed86f20b6125166facb20bef51cc6a1c844_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:acad2891c4883d2e325e7aa1739a472e75a9e815b72d6c038df7d0be9494c86b_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:db77a49f51282043f723ff80b6a3b6648f8c53ae02ba03d2eabad9a41333aaa1_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:dc3319a02cad69eeccabe7ff1150dff916117771c090cb928937b1546d565d8a_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:0469ef662fdbd5c07a978f3e36fdf7c6d0be0f628b16f4be584a0f7f1c7f394d_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:b229d45ee93b480823dde5864beb5d93b82c7237f05e724113cb7ff102fcd034_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:b4cc65f0494572e7923ba4e1fb17c18454268749f4fce7a2749fed32d8431b04_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:f82817d29295507e81fc79b76eea85b1e33aa2b34b9ba90aac151fec2e9eac17_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:29e3101280a8a834352695190729938d7669a763e1e2c7fb3fcbaf3a1f61a334_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:68834ddd81b0255d11c611ce0fa4ff6e7109e956fdffd8de6bdff778c0ac2657_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:ca0dbfe344e86c94ed04393b1d28977bce00e43b2e7d17f8965fda413941298f_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:d27a9db2394e1cdf9b47ee40577eac33363a0fef393f75e9720e9497151faf12_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:695ec2d4c1ab04789403f79d0476525cd8407ed07e49a34552287933b98849f9_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:c44138723651e19d03942f8a276ef99c6ef40200d22c19836c8146b1c7add8a2_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:cfb91fc0bb98343b64e990aa640e33fe03abd326e124ca377f18a7c074be0921_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:df6dfcd12d42b95a9a401b7f468079ea61b062aa88a11b4031ebdc869ce4eb6b_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:135445ba2fd137bc1b8c33b8cf4ad3c3b1ad0ee0a73eb984b2f21b77b03966d6_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:20ac0dfcdfc59e594345cd1ecd6c1ac6add039fd25b73a48a369702b94bbd00a_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:93507720a1e26d7632b01f1e9e794cb36f410973673a1416e35c0a126276cb93_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:d8e6dda95e6d670f992dda43297235b45f19a30fa8d12ec1b623aa60fa7fcabd_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-prometheus-rhel9@sha256:27c29c6abfe8612e0d55db0e8949b67574bf8d753e4a35f0fbdbb97832a7bc30_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- +155 more not shown
✅ Remediation
Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Remove the RBAC aggregation (immediate, targeted) Delete the ClusterRole that aggregates Application Subscription management permissions into the Kubernetes edit role: oc delete clusterrole open-cluster-management:multicloud-operators-subscription:rbac-aggregate-edit Verification: oc auth can-i create subscriptions.apps.open-cluster-management.io --as=<user> -n <namespace> Expected result after mitigation: no Important notes: This ClusterRole is recreated by the multiclusterhub-operator during reconciliation. Customers must re-apply this mitigation after any ACM operator upgrade, operator pod restart, or MultiClusterHub CR modification until a fixed release is installed. After deletion, users with only the edit or view roles will no longer be able to create or delete Application Subscription, Channel, or related resources. Users who are bound to open-cluster-management:subscription-admin or who have explicit RBAC grants are unaffected. Existing Application Subscriptions continue to function normally. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Upgrade github.com/hashicorp/memberlist to version 0.6.0 or later, which fixes the push/pull state handling issue. As a temporary mitigation, restrict network access to the gossip port (UDP/TCP, commonly 7946 or 9094) to trusted cluster members only, e.g. via network policy, firewall rules, or security groups, since the flaw requires network access to the gossip listener to trigger memory exhaustion. Workaround: To mitigate this vulnerability, ensure that the `volsync-addon-deploy-type` annotation is not explicitly set to `olm`. The default Helm deployment type for volsync-addon-controller in Red Hat Advanced Cluster Management for Kubernetes (since ACM 2.13) is not affected by this flaw. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: Audit dashboard-level permissions to ensure that write access is granted only to users who should be able to modify each specific dashboard. Revoke per-dashboard write permissions from Editor users who do not strictly require them. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect. Workaround: Applications utilizing `golang.org/x/net/html` should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input. Workaround: To mitigate the issue, we suggest upgrading to versions 5.9.0+ or 6.0.0-alpha.1+ Workaround: Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available. Workaround: There is no available mitigation for this flaw other than updating the bundled find-my-way library to a fixed version (9.7.0 or later). Where feasible, restricting the affected service to HTTP/1.1 (disabling HTTP/2) removes the attack vector, since the flaw is only reachable through the HTTP/2 request path. Workaround: Restrict container image pulls to trusted registries using admission policies or image signature verification. Where containerd is used as the container runtime, disable or restrict the binary:// logger URI scheme in the containerd configuration to prevent the label-to-logger attack path. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: Restrict the creation of `Channel` resources to trusted administrators within Red Hat Advanced Cluster Management. This limits the attack surface by preventing unauthorized tenants from exploiting the confused deputy vulnerability in the `multicloud-operators-channel` component. Workaround: To mitigate the risk of IPsec pre-shared key (PSK) disclosure, implement strict Kubernetes Role-Based Access Control (RBAC) policies to limit access to Submariner Custom Resources. Ensure that only authorized administrators and systems are granted permissions to view `submariner` Custom Resources within their namespaces. Additionally, exercise caution when collecting and storing diagnostic data, such as must-gather bundles, and when managing GitOps repositories, as these may inadvertently expose the cleartext PSK. Workaround: To mitigate this issue, restrict users' ability to annotate ManagedClusterAddOn resources within the hub cluster. Ensure that only trusted administrators have namespace-level annotate permissions on these resources. Regularly review and audit permissions related to ManagedClusterAddOn resources to prevent unauthorized modifications. If a service is restarted or reloaded, these permission changes will persist. Workaround: Restrict access to the backup storage location (e.g., S3 bucket) to authorized personnel only. Implement strict Role-Based Access Control (RBAC) to limit which users or service accounts can create Velero Backup objects within the open-cluster-management-backup namespace. This prevents an attacker from injecting malicious ClusterRoleBindings into backups or referencing untrusted backup objects. Ensure that only trusted and verified backups are used for restore operations. Workaround: To mitigate this issue, ensure that only highly trusted administrators are granted `namespace-admin` privileges within the `open-cluster-management-backup` namespace. This restricts the ability to create or modify `Restore` Custom Resources with malicious hooks, thereby preventing arbitrary command execution in restored pods. Workaround: To mitigate this issue, restrict administrative access to the `open-cluste…
🔗 References (67)
- selfhttps://access.redhat.com/errata/RHSA-2026:60386
- externalhttps://access.redhat.com/security/cve/CVE-2026-10090
- externalhttps://access.redhat.com/security/cve/CVE-2026-13676
- externalhttps://access.redhat.com/security/cve/CVE-2026-14362
- externalhttps://access.redhat.com/security/cve/CVE-2026-18874
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-27145
- externalhttps://access.redhat.com/security/cve/CVE-2026-33377
- externalhttps://access.redhat.com/security/cve/CVE-2026-42151
- externalhttps://access.redhat.com/security/cve/CVE-2026-42154
- externalhttps://access.redhat.com/security/cve/CVE-2026-42502
- externalhttps://access.redhat.com/security/cve/CVE-2026-44740
- externalhttps://access.redhat.com/security/cve/CVE-2026-44990
- externalhttps://access.redhat.com/security/cve/CVE-2026-45623
- externalhttps://access.redhat.com/security/cve/CVE-2026-46384
- externalhttps://access.redhat.com/security/cve/CVE-2026-46385
- externalhttps://access.redhat.com/security/cve/CVE-2026-46600
- externalhttps://access.redhat.com/security/cve/CVE-2026-47219
- externalhttps://access.redhat.com/security/cve/CVE-2026-48586
- externalhttps://access.redhat.com/security/cve/CVE-2026-53488
- externalhttps://access.redhat.com/security/cve/CVE-2026-54272
- externalhttps://access.redhat.com/security/cve/CVE-2026-55677
- externalhttps://access.redhat.com/security/cve/CVE-2026-55969
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/cve/CVE-2026-64927
- externalhttps://access.redhat.com/security/cve/CVE-2026-66780
- externalhttps://access.redhat.com/security/cve/CVE-2026-66781
- externalhttps://access.redhat.com/security/cve/CVE-2026-66792
- externalhttps://access.redhat.com/security/cve/CVE-2026-66793
- externalhttps://access.redhat.com/security/cve/CVE-2026-66797
- externalhttps://access.redhat.com/security/cve/CVE-2026-66798
- externalhttps://access.redhat.com/security/cve/CVE-2026-66799
- externalhttps://access.redhat.com/security/cve/CVE-2026-66800
- externalhttps://access.redhat.com/security/cve/CVE-2026-66804
- externalhttps://access.redhat.com/security/cve/CVE-2026-66805
- externalhttps://access.redhat.com/security/cve/CVE-2026-66878
- externalhttps://access.redhat.com/security/cve/CVE-2026-67213
- externalhttps://access.redhat.com/security/cve/CVE-2026-67214
- externalhttps://access.redhat.com/security/cve/CVE-2026-67567
- externalhttps://access.redhat.com/security/cve/CVE-2026-69153
- externalhttps://access.redhat.com/security/cve/CVE-2026-69192
- externalhttps://access.redhat.com/security/cve/CVE-2026-70398
- externalhttps://access.redhat.com/security/cve/CVE-2026-70495
- externalhttps://access.redhat.com/security/cve/CVE-2026-70496
- externalhttps://access.redhat.com/security/cve/CVE-2026-71467
- externalhttps://access.redhat.com/security/cve/CVE-2026-71468
- externalhttps://access.redhat.com/security/cve/CVE-2026-71469
- externalhttps://access.redhat.com/security/cve/CVE-2026-71470
- externalhttps://access.redhat.com/security/cve/CVE-2026-71471
- externalhttps://access.redhat.com/security/cve/CVE-2026-71472
- externalhttps://access.redhat.com/security/cve/CVE-2026-71473
- externalhttps://access.redhat.com/security/cve/CVE-2026-71474
- externalhttps://access.redhat.com/security/cve/CVE-2026-71475
- externalhttps://access.redhat.com/security/cve/CVE-2026-71845
- externalhttps://access.redhat.com/security/cve/CVE-2026-71846
- externalhttps://access.redhat.com/security/cve/CVE-2026-72508
- externalhttps://access.redhat.com/security/cve/CVE-2026-72526
- externalhttps://access.redhat.com/security/cve/CVE-2026-73086
- externalhttps://access.redhat.com/security/cve/CVE-2026-73122
- externalhttps://access.redhat.com/security/cve/CVE-2026-73137
- externalhttps://access.redhat.com/security/cve/CVE-2026-73834
- externalhttps://access.redhat.com/security/cve/CVE-2026-75485
- externalhttps://access.redhat.com/security/cve/CVE-2026-76827
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/updates/classification/#important
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_60386.json