Multicluster Engine For Kubernetes 2.9
14 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Multicluster Engine For Kubernetes 2.9, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
Multicluster Engine For Kubernetes 2.9 CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 1 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 2 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 2 |
| 2026-08 | 9 |
| 2026-09 | 0 |
Severity
How the 14 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical6
- High5
- Medium3
Latest CVEs
The 14 most recently published vulnerabilities affecting Multicluster Engine For Kubernetes 2.9.
- CVE-2026-73267Clusterclaims-controller: managedcluster deletion keyed solely on clusterclaim.spec.namespace with no local ownership check7.7
- CVE-2026-75569Mce-operator-bundle: all github actions pinned by mutable tag, not commit sha7.7
- CVE-2026-66794Cluster-proxy-addon: cluster-proxy-addon: unauthenticated ssrf to arbitrary managed-cluster services via public route9.3
- CVE-2026-66795Managedcluster-import-controller: csr auto-approver does not validate certificate subject or signername (spoke→hub cluster-admin)9.9
- CVE-2026-73266Clusterclaims-controller: confused deputy: tenant-controlled clusterclaim labels propagated to managedcluster, enabling cross-tenant managedclusterset join7.1
- CVE-2026-19130Provider-credential-controller: provider-credential-controller: cross-namespace credential propagation via attacker-controlled copiedfrom labels bypasses authorization5.8
- CVE-2026-73268Cluster-curator-controller: cluster-curator-controller: spec.install.overridejob allows arbitrary job spec injection9.9
- CVE-2026-73269Cluster-curator-controller: cluster-curator-controller: tenant-controllable trigger creates clusterrolebinding granting cluster-wide secrets access to namespace-local sa9.9
- CVE-2026-10059Cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cluster-wide curator authority via clustercurator serviceaccount token9.1
- CVE-2026-17107Cluster-proxy: impersonation-header injection grants cluster-admin on every managed cluster8.5
- CVE-2026-16242Hypershift: konnectivity proxy-server accepts agent connections without validating client certificates9.4
- CVE-2026-7163Assisted-service: assisted-service: authenticated users can gain administrative access to openshift clusters via credential disclosure6.1
- CVE-2026-4740Rhacm: open cluster management (ocm): cross-cluster privilege escalation via improper kubernetes client certificate renewal validation8.2
- CVE-2025-7195Operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd6.4
Product grouping is registry-driven, with AI assist and human review. How it works