CVE-2026-66783
A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a c
CVSS
4.4
Medio
EPSS
0.1%
p3
KEV
—
Exploit Today
1
0-100
Publicado: 18 ago 2026 · Última mod.: 1 sept 2026 · CWE-1357
0.1%EPSS · 30 días0.1%
2026-08-192026-08-31
A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation enables an attacker to execute arbitrary code with elevated privileges across the entire cluster, including control-plane nodes, by deploying a malicious image.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-672755.3 MED6.8%
——2Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Cache poisoning.4dCVE-2026-476196.6 MED37.2%
——11NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.25d