RED Hat has disclosed three high-severity vulnerabilities in its Advanced Cluster Management and Multicluster Engine for Kubernetes. The most critical, CVE-2026-70496, has a CVSS score of 9.9 and allows for Kubernetes privilege escalation to cluster-admin level. Currently, there are no known instances of exploitation. Here are the key points:
- **Products Affected:** Red Hat Advanced Cluster Management and Multicluster Engine for Kubernetes.
- **Total Vulnerabilities:** 3 (CVE-2026-70496, CVE-2026-66794, CVE-2026-71470)
- **Highest Severity Score:** 9.9 (Critical)
- **No Confirmed Exploitation** reported to date.
- **Flaws Impact:** They can enable privilege escalation and take control of Kubernetes clusters. One vulnerability requires no authentication, which increases the risk.
- **Mitigation Steps:** Apply Red Hat updates and enforce strict RBAC permissions to mitigate the vulnerabilities.