Critical Red Hat Kubernetes SSRF Flaw Exposes Internal Services Across Managed Clusters
20/08/2026-14:50 20/08/2026-14:55 מחשבים וטכנולוגיה Cyber Security News דיווח
Red Hat has disclosed CVE-2026-66794, a high-severity cybersecuritynews.com
affecting the cluster-proxy-addon component in Multicluster Engine for Kubernetes. The issue carries a CVSS v3.1 score of 9.3. It could all
affecting the cluster-proxy-addon component in Multicluster Engine for Kubernetes. The issue carries a CVSS v3.1 score of 9.3. It could all
סיכום מאמרתקציר: איום בבטיחות: חולשה ב-Red Hat Kubernetes חשופה לפגיעה בשירותים פנימיים Red Hat הכריזה על CVE-2026-66794, חולשה חמורה הפוגעת במרכיב cluster-proxy-addon של Multicluster Engine for Kubernetes. הבעיה נותנת ציון CVSS v3.1 של 9.3 ועלולה לגלות שירותים פנימיים בקלות. החולשה נגרמת עקב SSRF (Server-Side Request Forgery) שאפשר לתוקף לשלוח בקשות HTTP לשירותים פנימיים של הקלסטר, כולל שירותי API ו-HTTP. Red Hat ממליץ לבצע עדכון בקלסטרים כדי לתקן את הבעיה.תוכן זה נוצר על ידי בינה מלאכותית.