RED Hat has patched five critical vulnerabilities in Advanced Cluster Management (RHACM), including two remote code execution (RCE) flaws (CVE-2026-72526, CVE-2026-73269) both rated 9.9 on the CVSS scale. The vulnerabilities could allow attackers to hijack deployments or escalate privileges in a multi-tenant environment. A detailed breakdown of notable CVEs highlights their types and CVSS scores.
Patching is recommended as the vulnerabilities affect cluster management in Kubernetes, posing significant risks if exploited. Mitigation steps are suggested for organizations unable to patch immediately.