THREE critical security vulnerabilities affecting Red Hat products have been identified, enabling privilege escalation. The most severe, CVE-2026-67567 (CVSS 9.9), affects Advanced Cluster Management for Kubernetes, while two others (CVE-2026-13097 and CVE-2026-11861) target the FreeIPA identity system. While there are no confirmed exploits in the wild, these flaws allow low-trust users to gain excessive privileges, threatening both identity and cluster boundaries. Recommendations include applying updates and implementing strict access control measures.
CVE-2026-67567 (CVSS 9.9): Red Hat Flaws Enable Privilege Escalation in ACM and FreeIPA
CyberSIXT Evidence Panel
Article by CyberSIXT