Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.11.11 security update
🔗 CVE IDs covered (56)
📋 Description
CVE-2026-10090 — multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped ClusterRoleBinding and become cluster-admin via Application Subscription CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection CVE-2026-14362 — github.com/hashicorp/memberlist: HashiCorp memberlist: Denial of Service via push/pull state handling CVE-2026-18874 — volsync-addon-controller: volsync-addon-controller: annotation values rendered into YAML via text/template without escaping allows YAML injection into Subscription CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering CVE-2026-44740 — github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation CVE-2026-45623 — postcss: PostCSS: Information disclosure and denial of service via crafted CSS input CVE-2026-46600 — golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing CVE-2026-47219 — find-my-way: find-my-way: Denial of Service vulnerability in HTTP/2 server CVE-2026-53488 — github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin CVE-2026-54272 — ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-64927 — multicloud-operators-channel: multicloud-operators-channel: cross-namespace Secret and ConfigMap mutation via spec.secretRef.namespace confused deputy CVE-2026-66780 — submariner-operator: submariner-operator: flat broker trust model grants every spoke full CRUD on all endpoints, secrets, and endpointslices in broker namespace CVE-2026-66781 — submariner-operator: submariner-operator: IPsec PSK stored cleartext in Submariner CR spec CVE-2026-66792 — multicloud-operators-subscription: multicloud-operators-subscription: IsClusterAdmin() trusts user-settable annotations on managed clusters CVE-2026-66793 — governance-policy-addon-controller: governance-policy-addon-controller: arbitrary container image override via ManagedClusterAddOn annotation enables RCE on spoke CVE-2026-66797 — cluster-backup-operator: cluster-backup-operator: Velero Restore includes cluster-scoped RBAC resources with no exclusion — tampered backup yields hub cluster-admin CVE-2026-66798 — cluster-backup-operator: cluster-backup-operator: Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods CVE-2026-66800 — cluster-backup-operator: cluster-backup-operator: CleanupAll triggers unguarded cluster-wide mass-delete via operator ServiceAccount CVE-2026-66804 — console: console: authenticated SSRF via /ansibletower allows arbitrary host access with full response disclosure CVE-2026-66805 — console: console: stored DOM XSS via unescaped pod logs in document.write CVE-2026-66806 — console: console: TLS verification disabled when sending hub pull-secret to console.redhat.com CVE-2026-66878 — multicloud-operators-subscription: multicloud-operators-subscription: FetchChannelReferences honours Channel.spec.secretRef.namespace enabling cross-namespace Secret exfiltration CVE-2026-67213 — nanoid: nanoid: Denial of Service via infinite loop in random ID generation CVE-2026-67214 — nanoid: nanoid: Denial of Service via negative size input in non-secure module functions CVE-2026-67320 — axios: axios: Information disclosure via Prototype Pollution in Node HTTP adapter CVE-2026-67567 — multicloud-operators-subscription: multicloud-operators-subscription: HelmRelease chart applied with controller SA without GVK or namespace restriction CVE-2026-69153 — postcss: PostCSS: Information disclosure via crafted sourceMappingURL CVE-2026-69192 — ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass CVE-2026-70398 — multicloud-integrations: multicloud-integrations: GitOpsCluster.spec.argoServer.argoNamespace writes spoke bearer tokens to attacker-chosen namespace CVE-2026-70495 — search-v2-operator: search-v2-operator: cluster-wide impersonate on users/groups shared across 4 pods grants hub system:masters CVE-2026-70496 — search-v2-operator: search-v2-operator: operator ClusterRole is cluster-admin equivalent via impersonate, RBAC write, CSR approve, and ManifestWork CVE-2026-71468 — acm-search-v2-api-rhel9: search-v2-api: Cross-user bearer-token reuse via global federation-config cache CVE-2026-71469 — acm-search-v2-api-rhel9: search-v2-api: Unbounded tokenReviews cache allows unauthenticated memory-exhaustion DoS CVE-2026-71470 — acm-search-v2-rhel9: search-v2-operator: Search CR imageOverride/arguments/envVar flow unsanitized into pods running impersonating SA CVE-2026-71471 — acm-search-v2-rhel9: search-v2-operator: Hub Search CR Collector.ImageOverride propagated to every spoke as arbitrary container image CVE-2026-71472 — acm-search-v2-rhel9: search-v2-operator: Shell-command and SQL injection in postgresql-start.sh via CR-supplied WORK_MEM CVE-2026-71473 — acm-search-v2-rhel9: search-v2-operator: addonfactory.GetValuesFromAddonAnnotation enables arbitrary Helm-values override per spoke CVE-2026-71474 — insights-client-rhel9: insights-client: Pull-secret bearer token written to logs on non-200 CCX response CVE-2026-71845 — insights-client: insights-client: CCX_TOKEN bearer credential logged in clear text at startup via setDefault() CVE-2026-71846 — insights-client: insights-client: ClusterRole grants cluster-wide secrets get/list/watch beyond least privilege CVE-2026-72508 — multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke ServiceAccounts bound to wildcard RBAC (//*) CVE-2026-72526 — multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation CVE-2026-73086 — nanoid: nanoid: Predictable ID generation due to integer overflow CVE-2026-73122 — multicloud-operators-channel: multicloud-operators-channel: auto-generated Role grants every managed-cluster agent secrets:get,list,watch in Channel namespaces CVE-2026-73137 — multicloud-operators-subscription: multicloud-operators-subscription: cross-namespace Secret exfiltration via HelmRelease.repo.secretRef.namespace CVE-2026-73834 — must-gather: must-gather: embedded Secret data in ACM wrapper CRs collected without redaction CVE-2026-75485 — must-gather: must-gather: cluster Proxy object dumped raw, bypassing inspect redaction of proxy basic-auth credentials CVE-2026-76827 — search-indexer: search-indexer: UPDATE/DELETE operations not scoped to caller's cluster (cross-tenant data tampering)
🎯 Affected products165
- Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:3713326a7c0dde1bdd3e812ef366a409f8edcc773653b26ca81807db9f86b2ac_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:57e188661b9c6ce69926032b74420d4e8032d60654ce97bbdb2ed571ff0da4f9_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:a49a75ac5e34b5416b8f0e379d0234e2ae0fc99f7fee7a25167910c2496c852d_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:baf76f8820fc228c2d30198883e8b618ede44ac4196f9d4336cd5da39eabb448_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:753988c61167dea55ea388970f7cd0e104255428d77b044fe95982303088bc80_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:895b7f64d5973271d98b80e61cd0d5c47050ba2400730451130396860579ed7a_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:c74c6edae34bb6c8a99c70b83af3924bde6f79798099152480fd4c5026e2e41d_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:d60d5c8df956a23c5f1b9f2729f3ea1d04e18da199229e0c2da000a4650f93db_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:0ad6f34f25cc182173d13ffd8a305a0f50edda8172578ea78e9afb8f49b74652_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:4c3f2101a4c806cb07d185d9c83892706c760cc3348290a23888f175fc1ce8c3_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:7815e0d5779771b8d5d66a2d98dfe75c10749ad4962d87693b60264da6a211ff_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:d88ca221f89d14f56d38f9fa59c1a58ef48cea1e8ef521e9d4e51105574fb936_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:26017b2d228e7a8d266c30672cc013550c1de3fe249caf8b70e027c2ebbc2d51_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:2fbe95b077d8eb30ef4a9a4d57bd37ea68a70fd25dbcfa230770cf32a62852a9_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:3c027f88d854dc1bacad1713b131e64bd327f919d53543e3f702123656d25e12_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:7e66579d376886a1c7e6bb5f1e6fc3ad0517eec486963865777dd8b3e7b74f7d_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:24eff4577e1ed40847386c33368368e067f08d55b6d1765a63a995916ce898d5_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:53574712a69ee477fccc606b42079241023a529712900c0dd9e3bc2e32835c2f_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:6285b61d1f754c13ef58c771f8aab6066e68887cfc361931105e3d65de4a73b6_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:fca14ac81964e48c86a7a22ba44d0e9f4c87046fdcf9ed6de9ceaa15946dcb45_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:60279d6e733c61066b78cdb3f62361f02d01309eb0cfc74e8b5b96a37e475ed0_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:9cc6ba3d20ab78d91d4041323f882537fade6fad50407d0e75a96fb08af2d148_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:ca4f470edd12866523f94a253a9d0fc85cddef3b986eacf3592cb12d86efff98_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:f88646158428ef6aa6c70de25d644a514b12533b9eae2b3468fd5b2eb9685d4a_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-prometheus-rhel9@sha256:29e13f520c9169f6802a5f035dadc5b1d624d6fb77acd268370f19bbbcd5a671_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-prometheus-rhel9@sha256:4e554303a04307c68952f82b81699f06f8141de476972523d1995ac470d28713_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-prometheus-rhel9@sha256:dca7c0528524ff54bb28feb93239af0827d6a2f10b24f2598d5ee54f3db547fd_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-prometheus-rhel9@sha256:e2c01184b19f8e16482250f9583004b3f2e0173c6bc52087090da46ab0f69a5d_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-search-indexer-rhel9@sha256:409f6a65f728e6bbd716980f12308a95ee5a3e8948efb4fd1836e5622f8d09b6_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- +135 more not shown
✅ Remediation
Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Remove the RBAC aggregation (immediate, targeted) Delete the ClusterRole that aggregates Application Subscription management permissions into the Kubernetes edit role: oc delete clusterrole open-cluster-management:multicloud-operators-subscription:rbac-aggregate-edit Verification: oc auth can-i create subscriptions.apps.open-cluster-management.io --as=<user> -n <namespace> Expected result after mitigation: no Important notes: This ClusterRole is recreated by the multiclusterhub-operator during reconciliation. Customers must re-apply this mitigation after any ACM operator upgrade, operator pod restart, or MultiClusterHub CR modification until a fixed release is installed. After deletion, users with only the edit or view roles will no longer be able to create or delete Application Subscription, Channel, or related resources. Users who are bound to open-cluster-management:subscription-admin or who have explicit RBAC grants are unaffected. Existing Application Subscriptions continue to function normally. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: Upgrade github.com/hashicorp/memberlist to version 0.6.0 or later, which fixes the push/pull state handling issue. As a temporary mitigation, restrict network access to the gossip port (UDP/TCP, commonly 7946 or 9094) to trusted cluster members only, e.g. via network policy, firewall rules, or security groups, since the flaw requires network access to the gossip listener to trigger memory exhaustion. Workaround: To mitigate this vulnerability, ensure that the `volsync-addon-deploy-type` annotation is not explicitly set to `olm`. The default Helm deployment type for volsync-addon-controller in Red Hat Advanced Cluster Management for Kubernetes (since ACM 2.13) is not affected by this flaw. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: Applications utilizing `golang.org/x/net/html` should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input. Workaround: To mitigate the issue, we suggest upgrading to versions 5.9.0+ or 6.0.0-alpha.1+ Workaround: There is no available mitigation for this flaw other than updating the bundled find-my-way library to a fixed version (9.7.0 or later). Where feasible, restricting the affected service to HTTP/1.1 (disabling HTTP/2) removes the attack vector, since the flaw is only reachable through the HTTP/2 request path. Workaround: Restrict container image pulls to trusted registries using admission policies or image signature verification. Where containerd is used as the container runtime, disable or restrict the binary:// logger URI scheme in the containerd configuration to prevent the label-to-logger attack path. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: Restrict the creation of `Channel` resources to trusted administrators within Red Hat Advanced Cluster Management. This limits the attack surface by preventing unauthorized tenants from exploiting the confused deputy vulnerability in the `multicloud-operators-channel` component. Workaround: To mitigate the risk of IPsec pre-shared key (PSK) disclosure, implement strict Kubernetes Role-Based Access Control (RBAC) policies to limit access to Submariner Custom Resources. Ensure that only authorized administrators and systems are granted permissions to view `submariner` Custom Resources within their namespaces. Additionally, exercise caution when collecting and storing diagnostic data, such as must-gather bundles, and when managing GitOps repositories, as these may inadvertently expose the cleartext PSK. Workaround: To mitigate this issue, restrict users' ability to annotate ManagedClusterAddOn resources within the hub cluster. Ensure that only trusted administrators have namespace-level annotate permissions on these resources. Regularly review and audit permissions related to ManagedClusterAddOn resources to prevent unauthorized modifications. If a service is restarted or reloaded, these permission changes will persist. Workaround: Restrict access to the backup storage location (e.g., S3 bucket) to authorized personnel only. Implement strict Role-Based Access Control (RBAC) to limit which users or service accounts can create Velero Backup objects within the open-cluster-management-backup namespace. This prevents an attacker from injecting malicious ClusterRoleBindings into backups or referencing untrusted backup objects. Ensure that only trusted and verified backups are used for restore operations. Workaround: To mitigate this issue, ensure that only highly trusted administrators are granted `namespace-admin` privileges within the `open-cluster-management-backup` namespace. This restricts the ability to create or modify `Restore` Custom Resources with malicious hooks, thereby preventing arbitrary command execution in restored pods. Workaround: To reduce the risk of exploitation, ensure strict access controls are enforced on managed clusters, limiting the ability of untrusted users to deploy or modify pods and thus inject malicious content into container logs. Additionally, users should exercise caution when viewing "Raw" logs from potentially untrusted sources within the hub console. Workaround: To mitigate this issue, ensure that the HTTPS_PROXY environment variable is configured for the affected console component. This will enable proper TLS verification for outbound connections to console.redhat.com. Consult product documentation for specific instructions on configuring proxy settings for Multicluster Engine for Kubernetes and Red Hat Advanced Cluster Management for Kubernet…
🔗 References (60)
- selfhttps://access.redhat.com/errata/RHSA-2026:60387
- externalhttps://access.redhat.com/security/cve/CVE-2026-10090
- externalhttps://access.redhat.com/security/cve/CVE-2026-12143
- externalhttps://access.redhat.com/security/cve/CVE-2026-14362
- externalhttps://access.redhat.com/security/cve/CVE-2026-18874
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-27145
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-42151
- externalhttps://access.redhat.com/security/cve/CVE-2026-42502
- externalhttps://access.redhat.com/security/cve/CVE-2026-44740
- externalhttps://access.redhat.com/security/cve/CVE-2026-45623
- externalhttps://access.redhat.com/security/cve/CVE-2026-46600
- externalhttps://access.redhat.com/security/cve/CVE-2026-47219
- externalhttps://access.redhat.com/security/cve/CVE-2026-53488
- externalhttps://access.redhat.com/security/cve/CVE-2026-54272
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/cve/CVE-2026-64927
- externalhttps://access.redhat.com/security/cve/CVE-2026-66780
- externalhttps://access.redhat.com/security/cve/CVE-2026-66781
- externalhttps://access.redhat.com/security/cve/CVE-2026-66792
- externalhttps://access.redhat.com/security/cve/CVE-2026-66793
- externalhttps://access.redhat.com/security/cve/CVE-2026-66797
- externalhttps://access.redhat.com/security/cve/CVE-2026-66798
- externalhttps://access.redhat.com/security/cve/CVE-2026-66800
- externalhttps://access.redhat.com/security/cve/CVE-2026-66804
- externalhttps://access.redhat.com/security/cve/CVE-2026-66805
- externalhttps://access.redhat.com/security/cve/CVE-2026-66806
- externalhttps://access.redhat.com/security/cve/CVE-2026-66878
- externalhttps://access.redhat.com/security/cve/CVE-2026-67213
- externalhttps://access.redhat.com/security/cve/CVE-2026-67214
- externalhttps://access.redhat.com/security/cve/CVE-2026-67320
- externalhttps://access.redhat.com/security/cve/CVE-2026-67567
- externalhttps://access.redhat.com/security/cve/CVE-2026-69153
- externalhttps://access.redhat.com/security/cve/CVE-2026-69192
- externalhttps://access.redhat.com/security/cve/CVE-2026-70398
- externalhttps://access.redhat.com/security/cve/CVE-2026-70495
- externalhttps://access.redhat.com/security/cve/CVE-2026-70496
- externalhttps://access.redhat.com/security/cve/CVE-2026-71468
- externalhttps://access.redhat.com/security/cve/CVE-2026-71469
- externalhttps://access.redhat.com/security/cve/CVE-2026-71470
- externalhttps://access.redhat.com/security/cve/CVE-2026-71471
- externalhttps://access.redhat.com/security/cve/CVE-2026-71472
- externalhttps://access.redhat.com/security/cve/CVE-2026-71473
- externalhttps://access.redhat.com/security/cve/CVE-2026-71474
- externalhttps://access.redhat.com/security/cve/CVE-2026-71845
- externalhttps://access.redhat.com/security/cve/CVE-2026-71846
- externalhttps://access.redhat.com/security/cve/CVE-2026-72508
- externalhttps://access.redhat.com/security/cve/CVE-2026-72526
- externalhttps://access.redhat.com/security/cve/CVE-2026-73086
- externalhttps://access.redhat.com/security/cve/CVE-2026-73122
- externalhttps://access.redhat.com/security/cve/CVE-2026-73137
- externalhttps://access.redhat.com/security/cve/CVE-2026-73834
- externalhttps://access.redhat.com/security/cve/CVE-2026-75485
- externalhttps://access.redhat.com/security/cve/CVE-2026-76827
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/updates/classification/#important
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_60387.json