Vulnfeed

Archives
Log in
Subscribe
June 18, 2026

vulnfeed infra digest: Kubernetes · OpenStack · Kernel · nginx — 2026-06-18

vulnfeed Infrastructure Digest — 2026-06-18

Vulnerabilities affecting Kubernetes, OpenStack, Linux Kernel, nginx & Traefik from the past 7 days.

Kubernetes — 1 CVE
CVESevDescriptionCVSSEPSS
CVE-2026-3865MEDIUMCSI Driver for SMB path traversal via subDir may delete unintended directories on the SMB server6.5—
OpenStack — 10 CVEs
CVESevDescriptionCVSSEPSS
OSS-20260616-5UNKNOWN[OSSA-2026-022] OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduli——
CVE-2026-50266UNKNOWNOSSA-2026-021: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared ——
CVE-2026-49299UNKNOWNOSSA-2026-016: Neutron tagging policy bypass allows project readers to mutate tags——
CVE-2026-42998UNKNOWNOSSA-2026-015: Multiple credential delegation and authorization bypass vulnerabilities in Keystone——
CVE-2026-40213UNKNOWNOSSA-2026-011: Multiple access control vulnerabilities in Cyborg accelerator management——
CVE-2026-42997UNKNOWNOSSA-2026-010: Credential Forwarding to Arbitrary Endpoints via Ironic’s idrac Configuration molds Feature——
OSSA-2026-007UNKNOWNOSSA-2026-007: LDAP identity backend does not convert enabled attribute to boolean——
CVE-2026-33551UNKNOWNOSSA-2026-005: Restricted application credentials can create EC2 credentials——
CVE-2026-34881UNKNOWNOSSA-2026-004: Server-Side Request Forgery (SSRF) vulnerabilities in OpenStack Glance image import functionali——
OSSN-0098UNKNOWNOSSN-0098: Mistral workflow execution context exposes Keystone auth token——
Linux Kernel — 8 CVEs
CVESevDescriptionCVSSEPSS
USN-8390-2UNKNOWNUSN-8390-2: Linux kernel vulnerability——
USN-8441-1UNKNOWNUSN-8441-1: Linux kernel vulnerabilities——
USN-8361-3UNKNOWNUSN-8361-3: Linux kernel vulnerability——
USN-8440-1UNKNOWNUSN-8440-1: Linux kernel (Azure) vulnerabilities——
USN-8426-2UNKNOWNUSN-8426-2: Linux kernel (Azure) vulnerabilities——
USN-8439-1UNKNOWNUSN-8439-1: Linux kernel (Oracle) vulnerabilities——
USN-8426-1UNKNOWNUSN-8426-1: Linux kernel (Azure) vulnerabilities——
USN-8421-1UNKNOWNUSN-8421-1: Ironic vulnerabilities——
nginx / Traefik — 10 CVEs
CVESevDescriptionCVSSEPSS
CVE-2026-45552CRITICALRoxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and9.9—
CVE-2026-45556CRITICALRoxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and9.9—
CVE-2026-45558CRITICALRoxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and9.9—
CVE-2026-42055CRITICALNGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module9.2—
CVE-2026-42530CRITICALNGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured t9.2—
CVE-2026-45550CRITICALRoxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and9.1—
CVE-2026-45564HIGHRoxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and8.8—
CVE-2026-11311HIGHWhen NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in8.6—
CVE-2026-50107HIGHWhen NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vu8.6—
CVE-2026-45549HIGHRoxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and8.5—

Full digest →  ·  Live feed

vulnfeed infrastructure digest. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer vulnfeed weekly: 10645 CVEs · 675 critical — 2026-06-21 Older → vulnfeed weekly: 9582 CVEs · 617 critical — 2026-06-18
Powered by Buttondown, the easiest way to start and grow your newsletter.