CVE-2026-84200
Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two PolicyE
CVSS
9.0
Crítico
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 1 sept 2026 · Última mod.: 1 sept 2026 · CWE-284
Sin historial EPSS suficiente todavía.
Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive exception takes precedence, allowing an attacker to bypass the policy by crafting a resource name that matches the second exception's name pattern (e.g., '*ingress*'). This can be used to circumvent policies such as one blocking hostPath volumes. Fixed in v1.13.0.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-737414.3 MED—
———A vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to view some system files. Successful exploitation could allow an attacker to access limited data beyond what is authorized by the user's existing privilege level.5hCVE-2024-7953——
———A vulnerability exists in the affected products that allows a threat actor to create a project and become the administrator for it. If exploited, a threat actor could create, modify, and delete their own project.6hCVE-2026-517667.5 ALT—
———Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local device and, on a master, fan out reboot commands to mesh slaves via sending a crafted MQTT message to the cs_broker component.5hCVE-2026-517615.3 MED—
———Incorrect access control in the updateLanIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the LAN address state via sending a crafted MQTT message to the cs_broker component.5hCVE-2026-517565.9 MED—
———Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start firmware flashing using existing upgrade files via sending a crafted MQTT message to the cs_broker component.5hCVE-2026-517525.3 MED—
———Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger static information reporting to the configured master via sending a crafted MQTT message to the cs_broker component.5h