< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

Red Hat and SUSE disclose critical security vulnerabilities and patches

Red Hat has disclosed a critical privilege escalation vulnerability, tracked as CVE-2026-10090, affecting the Application Subscription controller in Red Hat Advanced Cluster Management (ACM) for Kubernetes. Rated with a CVSS score of 9.9, the flaw allows users with limited namespace-scoped edit permissions to escalate their privileges to full cluster-admin status. This occurs because the controller fails to verify if a user holds the required subscription-admin role and does not restrict deployed resources to the requester's namespace, potentially allowing an attacker to gain control over an entire managed cluster fleet.

Separately, SUSE has released a series of security patches to address various vulnerabilities across its enterprise and open-source distributions. These updates cover critical components including the Linux kernel, Python 3.11, FFmpeg, Podman, and OpenSSH libraries. The patches are intended to resolve issues such as remote code execution, memory corruption, and denial of service attacks across multiple SUSE Linux Enterprise versions and openSUSE distributions.

Entities

Kubernetes · OpenShift · Red Hat · SUSE