RHSA-2026:72880HighCVSS 7.5

Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.16.6 security update

Published
September 28, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2026-48586 — thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data CVE-2026-55969 — thrift: github.com/apache/thrift: Apache Thrift: Denial of Service via integer overflow or wraparound CVE-2026-66780 — submariner-operator: Broker ServiceAccount Secret (token + CA) logged in full at TRACE verbosity CVE-2026-75899 — fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding CVE-2026-75931 — fast-uri: fast-uri: Host confusion via skipped IDN canonicalization CVE-2026-75975 — fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization CVE-2026-76172 — fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects

🎯 Affected products189

  • Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:24e1e004a697d4039b2f96ac5a5b9f604a925ea6e279a65a2c0f385b6f6f9860_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:47a4f1bf0fe07c5ecb04f5a606b18b5a353198a2d7663d2d37b2541f79663143_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:a5eaa370b67b33d64e49060cd602d5bb023ea1b472cbc709d0d4f0673c52de8c_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:f71e61e04c557502db818b0d6b2bd9ba4fe48789e48780382b3eb5f512176e51_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:01d3396bef5391a4ca37ed1e35ea49c9856701b74ccff8c193709b2baa86c287_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:3328015f3d68b62ed80d86f8f8704752af0ba4c6dc66acd340c5b015d8cde67a_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:3470fe9afab5f431caeeccf2a4d9170a48d36d107f7c5eb03bae8e45b5efc559_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:576f4e16480d785c554ecd41085283b59e1dd5ec3faf6c60d5449235d7987a44_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:2dfed11a1beec3b8f165465899edd08985f75f5d29e3a2c1735b02f94fc8ec44_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:2f0d1cd9b8943ef0959b2252e74a032e6db63cc9c566de71adbe8f972fdffcae_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:75e3245d1bf70e64eb59105c6feb8df59fe016990f7934d64a8edbf3c65f0440_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:c4142c442aaf7d70bda203a2c613dc5024877322ad72ce812f2ff13be65ddd10_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:2d18da82d50b9562b109a71536b92db6ef6019853c126b0dadeb3059f58b88dc_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:6b286a7c5333592aef2e3d106be218b11830f4f079cdb5ab25848b25764fe05e_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:809a9ac4cee2e2191d715f3fcade779bef902ed81be448f0b030acca8023504b_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:d96afcac16fee749b02c1c796fb1611affee00d8a5fb685708d261b15be330fa_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:47779227c5822a9d5f081d1a04f086d4ea6599d271b147ead213e552ec11cabc_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:8da852d7ccdcf7a133d9fc2b24f88cf68b92efc8537b0261f74748748979888d_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:dc20a660f506c835c393756d69e8ca0896c59a363b7728222e78d93f008d4313_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:e7ce9123cfafde180faa177c04e631c83942882398f80c9bd820a80986905ba6_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:46549b2fd8c26aace313716bc21b9ad99c863f747c15867fbdd9030f5132b944_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:6a649091c21725f736d43871b1c1ad9042c029224a6bdb72911400e2e4a0d812_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:7c4db7ec0135203c260e31bfa6e0eaf6eda008f0dc8020fd22040ce795f85d76_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:f1ee9f8dd677970269781efa5b1305588f2cdd61098266c5de1aae3c67a92041_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:46eb950072c37c25093cc114c08563e851f2358f184638f57060db2e1b4bbc31_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:5e4914b26e35928ead59dbc026ab77cc685aa8ca23db4f0f2189beba0e1d2514_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:6c9d1cd1d9cff40ac9560393ab966e77fbde06c10e24dd18c8b41dc8d92633f0_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:c310819b9413afc0d4e0fa67845d214354130a85929d797e20779cf911c2c253_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:11cfe441966b2d63d1ddb57cddf8ab46dfb4ecaaf0010868f9a080e21e47a3e4_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • +159 more not shown

✅ Remediation

Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Until updates are available, restrict the processing of user-supplied URIs to trusted sources only, implement strict allowlists for destination hosts (preferably IP-based rather than hostname-based), and apply egress filtering to prevent server-initiated connections to internal networks or cloud metadata services. Workaround: There is no mitigation available for this issue. Apply updates as they become available from Red Hat product teams.

🔗 References (11)