All 2 CVE vulnerabilities found in Red Hat Advanced Cluster Management for Kubernetes 2, with AI-generated Chinese analysis, references, and POCs.
This page catalogs known vulnerabilities within Red Hat Advanced Cluster Management for Kubernetes 2, focusing on common weakness classifications and associated security tags. It aggregates a comprehensive list of reported security flaws affecting this container management platform, covering historical data up to the most recent patch cycles. Users can utilize this resource to track specific vendor advisories related to Red Hat’s enterprise-grade Kubernetes orchestration tools, gain a deeper understanding of prevalent weakness classes such as configuration errors or permission issues, and examine the complete vulnerability history for this product to assess long-term security posture. By centralizing these data points, the page serves as a critical reference for security analysts and system administrators seeking to identify risks, prioritize remediation efforts, and ensure compliance with internal security policies. The information presented is derived from official vendor security bulletins, public vulnerability databases, and community-reported incidents, ensuring a reliable foundation for risk assessment and mitigation planning without relying on speculative or unverified sources.
Vendor: Red Hat
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-93685 | Multicluster-observability-addon: multicluster-observability-addon: possible unauthenticated debug/metrics endpoint via cmdfactory.newcontrollercommandconfig (confirmed exposed by engineering) CWE-200 | 5.4 | Medium | 2026-09-18 |
| CVE-2026-92615 | Flightctl: flightctl: package-global go-git https transport mutated per-repo -- cross-tenant tls-config bleed CWE-413 | 6.6 | Medium | 2026-09-16 |
All 2 known CVE vulnerabilities affecting Red Hat Advanced Cluster Management for Kubernetes 2 with full Chinese analysis, references, and POCs where available.