THE Apache CloudStack has released version 4.20.3.1 and 4.22.1.1 to address 20 vulnerabilities (CVEs), including a critical flaw (CVE-2026-50112) that could enable cross-tenant remote code execution on KVM hypervisors. Currently, there are no confirmed exploits in the wild. Key points include: the vulnerabilities' severity ranges from high to unrated, a need for immediate updates, command execution risks linked to specific CVEs, and potential impacts on shared infrastructure. Recommendations include upgrading to the latest versions and limiting high-risk API access to mitigate future risks.
Apache CloudStack patches critical KVM RCE flaw CVE-2026-50112
CyberSIXT Evidence Panel
Article by CyberSIXT