CVE Tools

Kubevirt

19 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Kubevirt, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.

Kubevirt CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Kubevirt CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-117
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-066
2026-070
2026-080
2026-090

Severity

How the 19 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical15%
  • High526%
  • Medium1263%
  • Low15%

Latest CVEs

The 15 most recently published vulnerabilities affecting Kubevirt.

  1. CVE-2026-13434Virt-controller-rhel9: kubevirt: kubevirt: multus default-network annotation injection via unvalidated tenant networkname when externalnetresourceinjection is enabled4.9
  2. CVE-2026-13322Kubevirt: virt-handler-rhel9: kubevirt: unbounded virtio-serial readline in virt-handler causes oom denial of service3.8
  3. CVE-2026-13318Virt-api-rhel9: kubevirt: kubevirt: ssrf in virt-api port-forward via unvalidated guest-agent-reported ip6.4
  4. CVE-2026-13218Kubevirt: kubevirt: symlink following in writetocachedfile allows host file overwrite from virt-launcher4.2
  5. CVE-2026-13208Kubevirt: virt-handler-rhel9: kubevirt: virt-handler notify server trusts vmi identity from unauthenticated grpc request body6.5
  6. CVE-2026-13201Kubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enables notify socket hijacking and node-level vm disruption7.3
  7. CVE-2025-64324KubeVirt Vulnerable to Arbitrary Host File Read and Write7.7
  8. CVE-2025-64433KubeVirt Arbitrary Container File Read6.5
  9. CVE-2025-64437KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes5.0
  10. CVE-2025-64436KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes5.3
  11. CVE-2025-64435KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation5.3
  12. CVE-2025-64434KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing4.7
  13. CVE-2025-64432KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer4.7
  14. CVE-2024-33394An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.5.9
  15. CVE-2023-26484On a compromised KubeVirt node, the virt-handler service account can be used to modify all node specs8.2

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store