TL;DR
Red Hat disclosed three critical flaws across its cloud and identity products. The most severe, CVE-2026-66780, scores a CVSS of 9.9. This Red Hat vulnerability lets a compromised cluster stage a Man-in-the-Middle (MITM) attack across an entire Kubernetes mesh.
- Product: Red Hat (3 products)
- Vulnerabilities: 3 flaws (CVE-2026-66780, CVE-2026-18963, CVE-2026-12564)
- Highest severity: 9.9 (Critical · CVSSv3)
- Worst impact: Submariner-operator: submariner-operator: flat broker trust model grants every spoke full crud on all endpoints, secrets, and endpointslices in broker namespace
- Status: No confirmed exploitation yet; patches available
- Action: Update to 26.4.15-1, 26.4-23, 26.6.6-1, 26.6-12 now
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-66780 | 9.9 | CWE-284 | — | Not exploited |
| CVE-2026-12564 | 9.6 | CWE-918 | — | Not exploited |
| CVE-2026-18963 | 9.1 | CWE-640 | 26.4.15-1, 26.4-23, 26.6.6-1 (+1) | Not exploited |
Why it matters
Each flaw carries a critical rating of 9.1 or higher. They affect widely used enterprise platforms. Together, they threaten identity, automation, and multi-cluster networking. As a result, the risk to affected estates is high.
How the attacks work
The headline Red Hat vulnerability lives in the submariner-operator. A broker role grants joined clusters excessive permissions. A compromised cluster can then overwrite other clusters’ endpoint data. That change redirects tunnel traffic and enables the MITM attack. The Red Hat advisory for CVE-2026-66780 describes the broad role at fault.
Two more critical breaks
CVE-2026-18963 (CVSS 9.1) sits in the Red Hat build of Keycloak. It lets an unauthenticated attacker reset any user’s password. The flaw bypasses the email verification step, as the Keycloak advisory explains. CVE-2026-12564 (CVSS 9.6) affects the AAP Controller’s HashiCorp Vault plugin. An authenticated attacker can exfiltrate a Kubernetes token to an external URL, per the AAP advisory.
Affected versions
The MITM flaw affects Red Hat Advanced Cluster Management for Kubernetes. The Keycloak bug affects the Red Hat build of Keycloak. The Vault flaw affects all AAP versions that ship the hashivault plugin with kubernetes_role support.
Exploitation status and mitigation
Red Hat has confirmed no in-the-wild exploitation of these flaws. Even so, patch as updates arrive. Until then, restrict cluster permissions and limit pod network egress. Also limit credential-creation rights to trusted administrators.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.