RED Hat has disclosed three critical vulnerabilities across its cloud and identity products, with the most severe being CVE-2026-66780, which scores a CVSS of 9.9. This vulnerability allows a compromised cluster to stage a Man-in-the-Middle (MITM) attack within a Kubernetes mesh. All flaws have critical ratings of 9.1 or higher, posing a significant risk to enterprise platforms. The other vulnerabilities, CVE-2026-18963 and CVE-2026-12564, allow unauthorized password resets and token exfiltration respectively.
Patches are available, and users are advised to update their systems promptly. No confirmed exploitation has been reported yet.