Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.14.4 security update
🔗 CVE IDs covered (61)
📋 Description
CVE-2026-10090 — multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped ClusterRoleBinding and become cluster-admin via Application Subscription CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection CVE-2026-14362 — github.com/hashicorp/memberlist: HashiCorp memberlist: Denial of Service via push/pull state handling CVE-2026-18874 — volsync-addon-controller: volsync-addon-controller: annotation values rendered into YAML via text/template without escaping allows YAML injection into Subscription CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-33815 — github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering CVE-2026-44740 — github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation CVE-2026-45623 — postcss: PostCSS: Information disclosure and denial of service via crafted CSS input CVE-2026-46600 — golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing CVE-2026-47219 — find-my-way: find-my-way: Denial of Service vulnerability in HTTP/2 server CVE-2026-53488 — github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin CVE-2026-54272 — ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-64927 — multicloud-operators-channel: multicloud-operators-channel: cross-namespace Secret and ConfigMap mutation via spec.secretRef.namespace confused deputy CVE-2026-66780 — submariner-operator: submariner-operator: flat broker trust model grants every spoke full CRUD on all endpoints, secrets, and endpointslices in broker namespace CVE-2026-66781 — submariner-operator: submariner-operator: IPsec PSK stored cleartext in Submariner CR spec CVE-2026-66792 — multicloud-operators-subscription: multicloud-operators-subscription: IsClusterAdmin() trusts user-settable annotations on managed clusters CVE-2026-66793 — governance-policy-addon-controller: governance-policy-addon-controller: arbitrary container image override via ManagedClusterAddOn annotation enables RCE on spoke CVE-2026-66797 — cluster-backup-operator: cluster-backup-operator: Velero Restore includes cluster-scoped RBAC resources with no exclusion — tampered backup yields hub cluster-admin CVE-2026-66798 — cluster-backup-operator: cluster-backup-operator: Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods CVE-2026-66799 — cluster-backup-operator: cluster-backup-operator: Restore.spec.namespaceMapping pass-through enables cross-namespace Secret/ConfigMap placement CVE-2026-66800 — cluster-backup-operator: cluster-backup-operator: CleanupAll triggers unguarded cluster-wide mass-delete via operator ServiceAccount CVE-2026-66804 — console: console: authenticated SSRF via /ansibletower allows arbitrary host access with full response disclosure CVE-2026-66805 — console: console: stored DOM XSS via unescaped pod logs in document.write CVE-2026-66878 — multicloud-operators-subscription: multicloud-operators-subscription: FetchChannelReferences honours Channel.spec.secretRef.namespace enabling cross-namespace Secret exfiltration CVE-2026-67213 — nanoid: nanoid: Denial of Service via infinite loop in random ID generation CVE-2026-67214 — nanoid: nanoid: Denial of Service via negative size input in non-secure module functions CVE-2026-67313 — axios: axios: Denial of Service via uncontrolled recursion in formDataToJSON CVE-2026-67314 — axios: axios: Outbound Request Tampering via Prototype Pollution in Basic Auth CVE-2026-67320 — axios: axios: Information disclosure via Prototype Pollution in Node HTTP adapter CVE-2026-67321 — axios: axios: Denial of Service via object serialization bypass CVE-2026-67567 — multicloud-operators-subscription: multicloud-operators-subscription: HelmRelease chart applied with controller SA without GVK or namespace restriction CVE-2026-69153 — postcss: PostCSS: Information disclosure via crafted sourceMappingURL CVE-2026-69192 — ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass CVE-2026-70398 — multicloud-integrations: multicloud-integrations: GitOpsCluster.spec.argoServer.argoNamespace writes spoke bearer tokens to attacker-chosen namespace CVE-2026-70495 — search-v2-operator: search-v2-operator: cluster-wide impersonate on users/groups shared across 4 pods grants hub system:masters CVE-2026-70496 — search-v2-operator: search-v2-operator: operator ClusterRole is cluster-admin equivalent via impersonate, RBAC write, CSR approve, and ManifestWork CVE-2026-71468 — acm-search-v2-api-rhel9: search-v2-api: Cross-user bearer-token reuse via global federation-config cache CVE-2026-71469 — acm-search-v2-api-rhel9: search-v2-api: Unbounded tokenReviews cache allows unauthenticated memory-exhaustion DoS CVE-2026-71470 — acm-search-v2-rhel9: search-v2-operator: Search CR imageOverride/arguments/envVar flow unsanitized into pods running impersonating SA CVE-2026-71471 — acm-search-v2-rhel9: search-v2-operator: Hub Search CR Collector.ImageOverride propagated to every spoke as arbitrary container image CVE-2026-71472 — acm-search-v2-rhel9: search-v2-operator: Shell-command and SQL injection in postgresql-start.sh via CR-supplied WORK_MEM CVE-2026-71473 — acm-search-v2-rhel9: search-v2-operator: addonfactory.GetValuesFromAddonAnnotation enables arbitrary Helm-values override per spoke CVE-2026-71474 — insights-client-rhel9: insights-client: Pull-secret bearer token written to logs on non-200 CCX response CVE-2026-71475 — insights-client-rhel9: insights-client: Spoke-controlled ClusterID injected unencoded into Insights API URL path CVE-2026-71845 — insights-client: insights-client: CCX_TOKEN bearer credential logged in clear text at startup via setDefault() CVE-2026-71846 — insights-client: insights-client: ClusterRole grants cluster-wide secrets get/list/watch beyond least privilege CVE-2026-72508 — multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke ServiceAccounts bound to wildcard RBAC (//*) CVE-2026-72526 — multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation CVE-2026-73086 — nanoid: nanoid: Predictable ID generation due to integer overflow CVE-2026-73122 — multicloud-operators-channel: multicloud-operators-channel: auto-generated Role grants every managed-cluster agent secrets:get,list,watch in Channel namespaces CVE-2026-73137 — multicloud-operators-subscription: multicloud-operators-subscription: cross-namespace Secret exfiltration via HelmRelease.repo.secretRef.namespace CVE-2026-73834 — must-gather: must-gather: embedded Secret data in ACM wrapper CRs collected without redaction CVE-2026-75485 — must-gather: must-gather: cluster Proxy object dumped raw, bypassing inspect redaction of proxy basic-auth credentials CVE-2026-76827 — search-indexer: search-indexer: UPDATE/DELETE operations not scoped to caller's cluster (cross-tenant data tampering)
🎯 Affected products177
- Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:085afbeeff7dbe8d8d49b13b7e9043720b2730ae4ee02de60537c66b61769c16_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:4523db7932c0c31908e9be33376109cad8a0fc8d1fefab23b46c430584bf724b_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:b3533535756acf900d372323494f50011431c5a1eae4a0be9344c51eb4dbb7b3_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:eb8462c09c98cfb694d30eb74ed216fde8b920db9bc6d85b6e5831207c21f633_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:6c0de902b5b97037f622e988a4cc365301439678151dced3308c42b6d3ba5e83_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:79c9681f174c1f0d1a44651c9736d787b313a05570132588cdd5d586a05c040e_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:84bdddb6d31445def4d4bcb0fe699174c943039fda3ce28620c0e1e964b9efec_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:bc178bb90976219d192223d4a36ca3cafb1d8bf681981311b463ec0ca8b483e5_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:06301d071487eb482f722f9c57d0ae97e443805e2dead80cd749356a740ce4d6_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:2f042287a3cd6e75689dabd88df49d8902b099d3985d4a179d029d6b6ce48f99_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:8641fb7eee40486034b35b73bd5b89e98abee759c944d518cd48db194f22d7d6_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:e243d68950ebaf06ebeb03959470c8ad31240baae385d8b40448b4a995988e44_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:32588574de1738acb629990f5be28c559e139075070ff2ef4806ddb94caeb65d_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:b7436feb7cc6cb16f2100d0270a5c3485eb800b01bc61b3de86558abb9ff1c32_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:ba392c41cc87caf71fa0004581a259065cc39c98fed4b3118d1e55110d11aacc_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:d57a10da0075ce7c66ea5a65ba6b7debaa6de28f79e4553be33a137577b41b13_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:03797a01bb4d80b4946fbc59ad6302083f84ae163c716cffebd917a68547b185_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:28633b05ecb007b858abd180fb09ca03d24b7a9c502d88f6f7b3edf6dac9fd30_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:2f097900e95f40192ccc10a495f16234d5d07bfb8702244d0471f00f35eb8e4f_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:59ad7293030cee59cd9ff8e6c008c1376803da19931abbc0c9cfbf9affad8687_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:652cca7194074f7773ac88d06e0552194c71346b480e05f60de8961f5df45f97_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:6d0e3c9c261e33cd943389cfcc7d3de9309c6e5b0c2ac352b651b76bdd17e2a3_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:75c34fcb0e5ca1e094616fcc1101f06b64e6971fc815d1eacd98251f4d117149_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:9fa6020c6888a5ddb24a81f8c1dfca6135d3998f9a288c66d1123da678553a6e_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:0c1dac37ae3d1f2131593f8bdea8d42b89f835afa3bb557674440ca7592db79b_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:529c6d3484373799cc6301e23dca0164e3fb729efd3f0923b343d115613a332e_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:6cdc2a5c0686aef3f2584311881b1dc116a62fb48793aef6d1de82f43ac29401_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:cf01f83df37d3f292a9e3fb9fd3d44e49173f6423b58704aa8d96d0eeed9c871_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:304a9da968650b6d0bfe4bf92f3dc13d13b75e22152818349cc1797e3879e392_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- +147 more not shown
✅ Remediation
Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Remove the RBAC aggregation (immediate, targeted) Delete the ClusterRole that aggregates Application Subscription management permissions into the Kubernetes edit role: oc delete clusterrole open-cluster-management:multicloud-operators-subscription:rbac-aggregate-edit Verification: oc auth can-i create subscriptions.apps.open-cluster-management.io --as=<user> -n <namespace> Expected result after mitigation: no Important notes: This ClusterRole is recreated by the multiclusterhub-operator during reconciliation. Customers must re-apply this mitigation after any ACM operator upgrade, operator pod restart, or MultiClusterHub CR modification until a fixed release is installed. After deletion, users with only the edit or view roles will no longer be able to create or delete Application Subscription, Channel, or related resources. Users who are bound to open-cluster-management:subscription-admin or who have explicit RBAC grants are unaffected. Existing Application Subscriptions continue to function normally. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: Upgrade github.com/hashicorp/memberlist to version 0.6.0 or later, which fixes the push/pull state handling issue. As a temporary mitigation, restrict network access to the gossip port (UDP/TCP, commonly 7946 or 9094) to trusted cluster members only, e.g. via network policy, firewall rules, or security groups, since the flaw requires network access to the gossip listener to trigger memory exhaustion. Workaround: To mitigate this vulnerability, ensure that the `volsync-addon-deploy-type` annotation is not explicitly set to `olm`. The default Helm deployment type for volsync-addon-controller in Red Hat Advanced Cluster Management for Kubernetes (since ACM 2.13) is not affected by this flaw. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Applications utilizing `golang.org/x/net/html` should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input. Workaround: To mitigate the issue, we suggest upgrading to versions 5.9.0+ or 6.0.0-alpha.1+ Workaround: There is no available mitigation for this flaw other than updating the bundled find-my-way library to a fixed version (9.7.0 or later). Where feasible, restricting the affected service to HTTP/1.1 (disabling HTTP/2) removes the attack vector, since the flaw is only reachable through the HTTP/2 request path. Workaround: Restrict container image pulls to trusted registries using admission policies or image signature verification. Where containerd is used as the container runtime, disable or restrict the binary:// logger URI scheme in the containerd configuration to prevent the label-to-logger attack path. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: Restrict the creation of `Channel` resources to trusted administrators within Red Hat Advanced Cluster Management. This limits the attack surface by preventing unauthorized tenants from exploiting the confused deputy vulnerability in the `multicloud-operators-channel` component. Workaround: To mitigate the risk of IPsec pre-shared key (PSK) disclosure, implement strict Kubernetes Role-Based Access Control (RBAC) policies to limit access to Submariner Custom Resources. Ensure that only authorized administrators and systems are granted permissions to view `submariner` Custom Resources within their namespaces. Additionally, exercise caution when collecting and storing diagnostic data, such as must-gather bundles, and when managing GitOps repositories, as these may inadvertently expose the cleartext PSK. Workaround: To mitigate this issue, restrict users' ability to annotate ManagedClusterAddOn resources within the hub cluster. Ensure that only trusted administrators have namespace-level annotate permissions on these resources. Regularly review and audit permissions related to ManagedClusterAddOn resources to prevent unauthorized modifications. If a service is restarted or reloaded, these permission changes will persist. Workaround: Restrict access to the backup storage location (e.g., S3 bucket) to authorized personnel only. Implement strict Role-Based Access Control (RBAC) to limit which users or service accounts can create Velero Backup objects within the open-cluster-management-backup namespace. This prevents an attacker from injecting malicious ClusterRoleBindings into backups or referencing untrusted backup objects. Ensure that only trusted and verified backups are used for restore operations. Workaround: To mitigate this issue, ensure that only highly trusted administrators are granted `namespace-admin` privileges within the `open-cluster-management-backup` namespace. This restricts the ability to create or modify `Restore` Custom Resources with malicious hooks, thereby preventing arbitrary command execution in restored pods. Workaround: To mitigate this issue, restrict administrative access to the `open-cluster-management-backup` namespace. Only trusted administrators should have permissions to create or modify `Restore` Custom Resources within this namespace, as this act…
🔗 References (65)
- selfhttps://access.redhat.com/errata/RHSA-2026:60388
- externalhttps://access.redhat.com/security/cve/CVE-2026-10090
- externalhttps://access.redhat.com/security/cve/CVE-2026-12143
- externalhttps://access.redhat.com/security/cve/CVE-2026-14362
- externalhttps://access.redhat.com/security/cve/CVE-2026-18874
- externalhttps://access.redhat.com/security/cve/CVE-2026-25681
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-27145
- externalhttps://access.redhat.com/security/cve/CVE-2026-33815
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-42151
- externalhttps://access.redhat.com/security/cve/CVE-2026-42502
- externalhttps://access.redhat.com/security/cve/CVE-2026-44740
- externalhttps://access.redhat.com/security/cve/CVE-2026-45623
- externalhttps://access.redhat.com/security/cve/CVE-2026-46600
- externalhttps://access.redhat.com/security/cve/CVE-2026-47219
- externalhttps://access.redhat.com/security/cve/CVE-2026-53488
- externalhttps://access.redhat.com/security/cve/CVE-2026-54272
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/cve/CVE-2026-64927
- externalhttps://access.redhat.com/security/cve/CVE-2026-66780
- externalhttps://access.redhat.com/security/cve/CVE-2026-66781
- externalhttps://access.redhat.com/security/cve/CVE-2026-66792
- externalhttps://access.redhat.com/security/cve/CVE-2026-66793
- externalhttps://access.redhat.com/security/cve/CVE-2026-66797
- externalhttps://access.redhat.com/security/cve/CVE-2026-66798
- externalhttps://access.redhat.com/security/cve/CVE-2026-66799
- externalhttps://access.redhat.com/security/cve/CVE-2026-66800
- externalhttps://access.redhat.com/security/cve/CVE-2026-66804
- externalhttps://access.redhat.com/security/cve/CVE-2026-66805
- externalhttps://access.redhat.com/security/cve/CVE-2026-66878
- externalhttps://access.redhat.com/security/cve/CVE-2026-67213
- externalhttps://access.redhat.com/security/cve/CVE-2026-67214
- externalhttps://access.redhat.com/security/cve/CVE-2026-67313
- externalhttps://access.redhat.com/security/cve/CVE-2026-67314
- externalhttps://access.redhat.com/security/cve/CVE-2026-67320
- externalhttps://access.redhat.com/security/cve/CVE-2026-67321
- externalhttps://access.redhat.com/security/cve/CVE-2026-67567
- externalhttps://access.redhat.com/security/cve/CVE-2026-69153
- externalhttps://access.redhat.com/security/cve/CVE-2026-69192
- externalhttps://access.redhat.com/security/cve/CVE-2026-70398
- externalhttps://access.redhat.com/security/cve/CVE-2026-70495
- externalhttps://access.redhat.com/security/cve/CVE-2026-70496
- externalhttps://access.redhat.com/security/cve/CVE-2026-71468
- externalhttps://access.redhat.com/security/cve/CVE-2026-71469
- externalhttps://access.redhat.com/security/cve/CVE-2026-71470
- externalhttps://access.redhat.com/security/cve/CVE-2026-71471
- externalhttps://access.redhat.com/security/cve/CVE-2026-71472
- externalhttps://access.redhat.com/security/cve/CVE-2026-71473
- externalhttps://access.redhat.com/security/cve/CVE-2026-71474
- externalhttps://access.redhat.com/security/cve/CVE-2026-71475
- externalhttps://access.redhat.com/security/cve/CVE-2026-71845
- externalhttps://access.redhat.com/security/cve/CVE-2026-71846
- externalhttps://access.redhat.com/security/cve/CVE-2026-72508
- externalhttps://access.redhat.com/security/cve/CVE-2026-72526
- externalhttps://access.redhat.com/security/cve/CVE-2026-73086
- externalhttps://access.redhat.com/security/cve/CVE-2026-73122
- externalhttps://access.redhat.com/security/cve/CVE-2026-73137
- externalhttps://access.redhat.com/security/cve/CVE-2026-73834
- externalhttps://access.redhat.com/security/cve/CVE-2026-75485
- externalhttps://access.redhat.com/security/cve/CVE-2026-76827
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/updates/classification/#important
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_60388.json