Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.7) | 0.63% | — | Redhat Multicluster EngineAIRedhat Clusterclaims ControllerAI | 21/8/2026 | 29/9/2026 | A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete ClusterClaim resources can exploit this by manipulating the `spec.namespace` field. This allows the tenant to specify and delete any ManagedCluster, including the hub's… | |
| Pendiente de análisis | Crítica (9.3) | 0.62% | — | Redhat Multicluster Engine FOR KubernetesAI | 19/8/2026 | 29/9/2026 | A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manipulating URL path segments, the attacker can proxy requests to arbitrary… | |
| Pendiente de análisis | Alta (7.1) | 0.35% | — | Redhat Multicluster EngineAIRedhat Clusterclaims ControllerAI | 13/8/2026 | 29/9/2026 | A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable… | |
| Pendiente de análisis | Media (5.8) | 0.40% | — | Redhat Multicluster EngineAI | 12/8/2026 | 29/9/2026 | A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a prior credential value, could exploit an authorization bypass vulnerability. By manipulating `copiedFrom` labels, the attacker could intercept… | |
| Pendiente de análisis | Crítica (9.9) | 0.88% | — | Redhat Multicluster EngineAIRedhat Cluster Curator ControllerAI | 12/8/2026 | 29/9/2026 | A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate user-controlled input when unmarshaling the… | |
| Pendiente de análisis | Crítica (9.1) | 0.64% | — | Multicluster Engine FOR Kubernetes ClustercuratorAI | 5/8/2026 | 8/9/2026 | A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a… | |
| Pendiente de análisis | Alta (8.5) | 0.57% | — | Redhat Advanced Cluster Management FOR KubernetesAIRedhat Multicluster-engineAI | 24/7/2026 | 29/9/2026 | A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds… | |
| Modificada | Media (5.5) | 0.20% | — | Redhat Multicluster Engine FOR Kubernetes | 30/4/2026 | 5/9/2026 | A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrative credentials for arbitrary clusters provisioned through the hub. The credentials… | |
| Aplazada | Alta (8.2) | 0.49% | — | Redhat Multicluster EngineAIRedhat Advanced Cluster ManagementAIRedhat HiveAI | 17/3/2025 | 21/8/2026 | A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials… |