Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.13.11 security update
🔗 CVE IDs covered (57)
📋 Description
CVE-2026-10090 — multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped ClusterRoleBinding and become cluster-admin via Application Subscription CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection CVE-2026-14362 — github.com/hashicorp/memberlist: HashiCorp memberlist: Denial of Service via push/pull state handling CVE-2026-18874 — volsync-addon-controller: volsync-addon-controller: annotation values rendered into YAML via text/template without escaping allows YAML injection into Subscription CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-33377 — grafana: Grafana: Privilege escalation via dashboard overwrite CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering CVE-2026-43870 — apache-thrift: Apache Thrift: Denial of Service via multiple vulnerabilities CVE-2026-45623 — postcss: PostCSS: Information disclosure and denial of service via crafted CSS input CVE-2026-46600 — golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing CVE-2026-47219 — find-my-way: find-my-way: Denial of Service vulnerability in HTTP/2 server CVE-2026-54272 — ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-64927 — multicloud-operators-channel: multicloud-operators-channel: cross-namespace Secret and ConfigMap mutation via spec.secretRef.namespace confused deputy CVE-2026-66780 — submariner-operator: submariner-operator: flat broker trust model grants every spoke full CRUD on all endpoints, secrets, and endpointslices in broker namespace CVE-2026-66781 — submariner-operator: submariner-operator: IPsec PSK stored cleartext in Submariner CR spec CVE-2026-66792 — multicloud-operators-subscription: multicloud-operators-subscription: IsClusterAdmin() trusts user-settable annotations on managed clusters CVE-2026-66793 — governance-policy-addon-controller: governance-policy-addon-controller: arbitrary container image override via ManagedClusterAddOn annotation enables RCE on spoke CVE-2026-66797 — cluster-backup-operator: cluster-backup-operator: Velero Restore includes cluster-scoped RBAC resources with no exclusion — tampered backup yields hub cluster-admin CVE-2026-66798 — cluster-backup-operator: cluster-backup-operator: Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods CVE-2026-66799 — cluster-backup-operator: cluster-backup-operator: Restore.spec.namespaceMapping pass-through enables cross-namespace Secret/ConfigMap placement CVE-2026-66800 — cluster-backup-operator: cluster-backup-operator: CleanupAll triggers unguarded cluster-wide mass-delete via operator ServiceAccount CVE-2026-66804 — console: console: authenticated SSRF via /ansibletower allows arbitrary host access with full response disclosure CVE-2026-66805 — console: console: stored DOM XSS via unescaped pod logs in document.write CVE-2026-66878 — multicloud-operators-subscription: multicloud-operators-subscription: FetchChannelReferences honours Channel.spec.secretRef.namespace enabling cross-namespace Secret exfiltration CVE-2026-67213 — nanoid: nanoid: Denial of Service via infinite loop in random ID generation CVE-2026-67214 — nanoid: nanoid: Denial of Service via negative size input in non-secure module functions CVE-2026-67313 — axios: axios: Denial of Service via uncontrolled recursion in formDataToJSON CVE-2026-67314 — axios: axios: Outbound Request Tampering via Prototype Pollution in Basic Auth CVE-2026-67320 — axios: axios: Information disclosure via Prototype Pollution in Node HTTP adapter CVE-2026-67321 — axios: axios: Denial of Service via object serialization bypass CVE-2026-67567 — multicloud-operators-subscription: multicloud-operators-subscription: HelmRelease chart applied with controller SA without GVK or namespace restriction CVE-2026-69153 — postcss: PostCSS: Information disclosure via crafted sourceMappingURL CVE-2026-69192 — ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass CVE-2026-70398 — multicloud-integrations: multicloud-integrations: GitOpsCluster.spec.argoServer.argoNamespace writes spoke bearer tokens to attacker-chosen namespace CVE-2026-70495 — search-v2-operator: search-v2-operator: cluster-wide impersonate on users/groups shared across 4 pods grants hub system:masters CVE-2026-70496 — search-v2-operator: search-v2-operator: operator ClusterRole is cluster-admin equivalent via impersonate, RBAC write, CSR approve, and ManifestWork CVE-2026-71468 — acm-search-v2-api-rhel9: search-v2-api: Cross-user bearer-token reuse via global federation-config cache CVE-2026-71469 — acm-search-v2-api-rhel9: search-v2-api: Unbounded tokenReviews cache allows unauthenticated memory-exhaustion DoS CVE-2026-71470 — acm-search-v2-rhel9: search-v2-operator: Search CR imageOverride/arguments/envVar flow unsanitized into pods running impersonating SA CVE-2026-71471 — acm-search-v2-rhel9: search-v2-operator: Hub Search CR Collector.ImageOverride propagated to every spoke as arbitrary container image CVE-2026-71472 — acm-search-v2-rhel9: search-v2-operator: Shell-command and SQL injection in postgresql-start.sh via CR-supplied WORK_MEM CVE-2026-71473 — acm-search-v2-rhel9: search-v2-operator: addonfactory.GetValuesFromAddonAnnotation enables arbitrary Helm-values override per spoke CVE-2026-71474 — insights-client-rhel9: insights-client: Pull-secret bearer token written to logs on non-200 CCX response CVE-2026-71475 — insights-client-rhel9: insights-client: Spoke-controlled ClusterID injected unencoded into Insights API URL path CVE-2026-71845 — insights-client: insights-client: CCX_TOKEN bearer credential logged in clear text at startup via setDefault() CVE-2026-71846 — insights-client: insights-client: ClusterRole grants cluster-wide secrets get/list/watch beyond least privilege CVE-2026-72508 — multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke ServiceAccounts bound to wildcard RBAC (//*) CVE-2026-72526 — multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation CVE-2026-73086 — nanoid: nanoid: Predictable ID generation due to integer overflow CVE-2026-73122 — multicloud-operators-channel: multicloud-operators-channel: auto-generated Role grants every managed-cluster agent secrets:get,list,watch in Channel namespaces CVE-2026-73137 — multicloud-operators-subscription: multicloud-operators-subscription: cross-namespace Secret exfiltration via HelmRelease.repo.secretRef.namespace CVE-2026-73834 — must-gather: must-gather: embedded Secret data in ACM wrapper CRs collected without redaction CVE-2026-75485 — must-gather: must-gather: cluster Proxy object dumped raw, bypassing inspect redaction of proxy basic-auth credentials CVE-2026-76827 — search-indexer: search-indexer: UPDATE/DELETE operations not scoped to caller's cluster (cross-tenant data tampering)
🎯 Affected products177
- Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:5f34ce2092fa356d49cb3f03e3715e0b2b427142c4769be5ccc63cd4061b06b2_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:ce195153ee57f493c1c5abf5d70288fff62c5558648faf67e037bc7d7fe6fe7b_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:e15276388527daf06f54d9ad830d966438e0a5299065a26b9af77cf30bcb45c9_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:ea006a1774913176d44c4dca73501468c1c77d9f039b2291ec62fa5fec9eb2ef_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:297cd74d2fe1e0e3fe120142b06ca68e7cb5fdb22233fedd0847d1c3b9839965_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:4b149e6b4a1df9d8fbdc424dc2dfd73a9f0baa52bbf69861dad024fdbaa7b6bc_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:69452ada0170d310cf8162f9b5e3e9fd2d9770b617b54daf95095e69b299f1e0_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:db4adfa2b7950a777c9bd0557ba641b8928faf3c26b7113d3edd19ea3655782c_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:2a1df1c70a6a3dd95eb2877eb35bbcce416b6044c3b71234fb1273d83799e1fe_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:31296820926e0f958215ae4c776ce8f826838aae4029e4af9ae704d1bf90886a_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:b1770871427e322b73ccf5eb2cc946cd5286560596dcdc1291aef4c658c4f732_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:ee89dcfa01bb0b18acc6760b1fe7671450d2571bedb0e46c6499a23b5e3d0fae_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:4e8f3e5b7287a11485f196dfef56b79bc766c152c60effbfc5813aa7a583a82c_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:6073a7df03da8d319a00dc6c636edd5d22e0fe25d118b570787ba8517d70d679_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:b32d9176c6d2698fbb4e969be155021e64585a08f0bc414184bdb8259612a9b2_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:d93d011adf0f8e146d297681d79339750c211dc6e7d1a8949518f2f6c874131b_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:0a98691162ead991bdb5c77411891626147fe911fd119042497e9945110818ee_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:246e521045036258a5283ac0b8281640280a1e84e38c2d0f762bdede92933480_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:8b85d4c1947c6c284d898cfbba4eff8bf927f20470883da4be7db2efe3a76fe4_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:97c5d43dd9d3310e88733f1e59f95c92eff612581387e5dcb20aed67d218da00_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:8155da260489df1bb0b534281cbd403dfc0b7e99998e3a8bd708eaeec978e6a5_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:856db5df0662b7009f3f9c72bc3d3385728d26ec00b3a6d73a0b71f1c12f2103_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:9d051d14ca98d77c86918fd0ab94c777c896b2310356b5b675ebd3cc4fba0f66_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:ae225bf7f4e4d8933c2b34dfc5afbb0aba635c209d76c95a38d77c202d8a788d_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:1748b946b4014bea8a0e81ef50d77e67c7ef6cd05f648e77b26ba66bdfbb2e8a_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:9aff94fe2abec282d7a670476a7507cf2bb0b74ce76093b45d2d50a8f2f93a65_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:9b3a592331ef86de0c65c2745b47399b165b94d6a40e9ea3b6f8497682d5d12a_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:fe12e6f4e6770ac8a64886247d689be8e6c840cc70455ef3d75bb4e4019fba1d_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:0fab6d831ec3694884fba9c9bb7e7a82fcdbc3560e15a5eed515897d4b8fe00a_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- +147 more not shown
✅ Remediation
Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Remove the RBAC aggregation (immediate, targeted) Delete the ClusterRole that aggregates Application Subscription management permissions into the Kubernetes edit role: oc delete clusterrole open-cluster-management:multicloud-operators-subscription:rbac-aggregate-edit Verification: oc auth can-i create subscriptions.apps.open-cluster-management.io --as=<user> -n <namespace> Expected result after mitigation: no Important notes: This ClusterRole is recreated by the multiclusterhub-operator during reconciliation. Customers must re-apply this mitigation after any ACM operator upgrade, operator pod restart, or MultiClusterHub CR modification until a fixed release is installed. After deletion, users with only the edit or view roles will no longer be able to create or delete Application Subscription, Channel, or related resources. Users who are bound to open-cluster-management:subscription-admin or who have explicit RBAC grants are unaffected. Existing Application Subscriptions continue to function normally. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: Upgrade github.com/hashicorp/memberlist to version 0.6.0 or later, which fixes the push/pull state handling issue. As a temporary mitigation, restrict network access to the gossip port (UDP/TCP, commonly 7946 or 9094) to trusted cluster members only, e.g. via network policy, firewall rules, or security groups, since the flaw requires network access to the gossip listener to trigger memory exhaustion. Workaround: To mitigate this vulnerability, ensure that the `volsync-addon-deploy-type` annotation is not explicitly set to `olm`. The default Helm deployment type for volsync-addon-controller in Red Hat Advanced Cluster Management for Kubernetes (since ACM 2.13) is not affected by this flaw. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: Audit dashboard-level permissions to ensure that write access is granted only to users who should be able to modify each specific dashboard. Revoke per-dashboard write permissions from Editor users who do not strictly require them. Workaround: Applications utilizing `golang.org/x/net/html` should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: There is no available mitigation for this flaw other than updating the bundled find-my-way library to a fixed version (9.7.0 or later). Where feasible, restricting the affected service to HTTP/1.1 (disabling HTTP/2) removes the attack vector, since the flaw is only reachable through the HTTP/2 request path. Workaround: Restrict the creation of `Channel` resources to trusted administrators within Red Hat Advanced Cluster Management. This limits the attack surface by preventing unauthorized tenants from exploiting the confused deputy vulnerability in the `multicloud-operators-channel` component. Workaround: To mitigate the risk of IPsec pre-shared key (PSK) disclosure, implement strict Kubernetes Role-Based Access Control (RBAC) policies to limit access to Submariner Custom Resources. Ensure that only authorized administrators and systems are granted permissions to view `submariner` Custom Resources within their namespaces. Additionally, exercise caution when collecting and storing diagnostic data, such as must-gather bundles, and when managing GitOps repositories, as these may inadvertently expose the cleartext PSK. Workaround: To mitigate this issue, restrict users' ability to annotate ManagedClusterAddOn resources within the hub cluster. Ensure that only trusted administrators have namespace-level annotate permissions on these resources. Regularly review and audit permissions related to ManagedClusterAddOn resources to prevent unauthorized modifications. If a service is restarted or reloaded, these permission changes will persist. Workaround: Restrict access to the backup storage location (e.g., S3 bucket) to authorized personnel only. Implement strict Role-Based Access Control (RBAC) to limit which users or service accounts can create Velero Backup objects within the open-cluster-management-backup namespace. This prevents an attacker from injecting malicious ClusterRoleBindings into backups or referencing untrusted backup objects. Ensure that only trusted and verified backups are used for restore operations. Workaround: To mitigate this issue, ensure that only highly trusted administrators are granted `namespace-admin` privileges within the `open-cluster-management-backup` namespace. This restricts the ability to create or modify `Restore` Custom Resources with malicious hooks, thereby preventing arbitrary command execution in restored pods. Workaround: To mitigate this issue, restrict administrative access to the `open-cluster-management-backup` namespace. Only trusted administrators should have permissions to create or modify `Restore` Custom Resources within this namespace, as this action is required to exploit the vulnerability. Workaround: To reduce the risk of exploitation, ensure strict access controls are enforced on managed clusters, limiting the ability of untrusted users to deploy or modify pods and thus inject malicious content into container logs. Additionally, users should exercise caution when viewing "Raw" logs from potentially untrusted sources within the hub console. Workaround: To mitigate this issue, ensure application code validates the size parameter passed to customAlphabet or customRandom, rejecting or sanitizing zero-value inputs before passing them to nanoid. Workaround: Sanitize all user-supplied integer inputs before passing them to `nanoid` or `customAlphabet` functions in the `nanoid/non-secure` module, ensuring the size parameter is strictly a non-negative integer. Workaround: To mitigate this issue, restrict the ability of untrusted tenants to create `HelmRelease` custom resources within the cluster. Implement strict Role-Based Access Control (RBAC) policies to limit which users or service accounts can create or modify `HelmRelease` objects. This will prevent unauthorized users from leveraging the controller's elevated p…
🔗 References (61)
- selfhttps://access.redhat.com/errata/RHSA-2026:60390
- externalhttps://access.redhat.com/security/cve/CVE-2026-10090
- externalhttps://access.redhat.com/security/cve/CVE-2026-12143
- externalhttps://access.redhat.com/security/cve/CVE-2026-14362
- externalhttps://access.redhat.com/security/cve/CVE-2026-18874
- externalhttps://access.redhat.com/security/cve/CVE-2026-27145
- externalhttps://access.redhat.com/security/cve/CVE-2026-33377
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-42151
- externalhttps://access.redhat.com/security/cve/CVE-2026-42502
- externalhttps://access.redhat.com/security/cve/CVE-2026-43870
- externalhttps://access.redhat.com/security/cve/CVE-2026-45623
- externalhttps://access.redhat.com/security/cve/CVE-2026-46600
- externalhttps://access.redhat.com/security/cve/CVE-2026-47219
- externalhttps://access.redhat.com/security/cve/CVE-2026-54272
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-64927
- externalhttps://access.redhat.com/security/cve/CVE-2026-66780
- externalhttps://access.redhat.com/security/cve/CVE-2026-66781
- externalhttps://access.redhat.com/security/cve/CVE-2026-66792
- externalhttps://access.redhat.com/security/cve/CVE-2026-66793
- externalhttps://access.redhat.com/security/cve/CVE-2026-66797
- externalhttps://access.redhat.com/security/cve/CVE-2026-66798
- externalhttps://access.redhat.com/security/cve/CVE-2026-66799
- externalhttps://access.redhat.com/security/cve/CVE-2026-66800
- externalhttps://access.redhat.com/security/cve/CVE-2026-66804
- externalhttps://access.redhat.com/security/cve/CVE-2026-66805
- externalhttps://access.redhat.com/security/cve/CVE-2026-66878
- externalhttps://access.redhat.com/security/cve/CVE-2026-67213
- externalhttps://access.redhat.com/security/cve/CVE-2026-67214
- externalhttps://access.redhat.com/security/cve/CVE-2026-67313
- externalhttps://access.redhat.com/security/cve/CVE-2026-67314
- externalhttps://access.redhat.com/security/cve/CVE-2026-67320
- externalhttps://access.redhat.com/security/cve/CVE-2026-67321
- externalhttps://access.redhat.com/security/cve/CVE-2026-67567
- externalhttps://access.redhat.com/security/cve/CVE-2026-69153
- externalhttps://access.redhat.com/security/cve/CVE-2026-69192
- externalhttps://access.redhat.com/security/cve/CVE-2026-70398
- externalhttps://access.redhat.com/security/cve/CVE-2026-70495
- externalhttps://access.redhat.com/security/cve/CVE-2026-70496
- externalhttps://access.redhat.com/security/cve/CVE-2026-71468
- externalhttps://access.redhat.com/security/cve/CVE-2026-71469
- externalhttps://access.redhat.com/security/cve/CVE-2026-71470
- externalhttps://access.redhat.com/security/cve/CVE-2026-71471
- externalhttps://access.redhat.com/security/cve/CVE-2026-71472
- externalhttps://access.redhat.com/security/cve/CVE-2026-71473
- externalhttps://access.redhat.com/security/cve/CVE-2026-71474
- externalhttps://access.redhat.com/security/cve/CVE-2026-71475
- externalhttps://access.redhat.com/security/cve/CVE-2026-71845
- externalhttps://access.redhat.com/security/cve/CVE-2026-71846
- externalhttps://access.redhat.com/security/cve/CVE-2026-72508
- externalhttps://access.redhat.com/security/cve/CVE-2026-72526
- externalhttps://access.redhat.com/security/cve/CVE-2026-73086
- externalhttps://access.redhat.com/security/cve/CVE-2026-73122
- externalhttps://access.redhat.com/security/cve/CVE-2026-73137
- externalhttps://access.redhat.com/security/cve/CVE-2026-73834
- externalhttps://access.redhat.com/security/cve/CVE-2026-75485
- externalhttps://access.redhat.com/security/cve/CVE-2026-76827
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/updates/classification/#important
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_60390.json