vulnfeed
Infrastructure Digest — 2026-06-18
Vulnerabilities affecting Kubernetes, OpenStack, Linux Kernel, nginx & Traefik
from the past 7 days.
| CVE | Sev | Description | CVSS | EPSS |
|---|
| CVE-2026-3865 | MEDIUM | CSI Driver for SMB path traversal via subDir may delete unintended directories on the SMB server | 6.5 | — |
| CVE | Sev | Description | CVSS | EPSS |
|---|
| OSS-20260616-5 | UNKNOWN | [OSSA-2026-022] OpenStack Nova: Nova scheduler hint injection
bypasses Placement resource claims and scheduli | — | — |
| CVE-2026-50266 | UNKNOWN | OSSA-2026-021: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared | — | — |
| CVE-2026-49299 | UNKNOWN | OSSA-2026-016: Neutron tagging policy bypass allows project readers to mutate tags | — | — |
| CVE-2026-42998 | UNKNOWN | OSSA-2026-015: Multiple credential delegation and authorization bypass vulnerabilities in Keystone | — | — |
| CVE-2026-40213 | UNKNOWN | OSSA-2026-011: Multiple access control vulnerabilities in Cyborg accelerator management | — | — |
| CVE-2026-42997 | UNKNOWN | OSSA-2026-010: Credential Forwarding to Arbitrary Endpoints via Ironic’s idrac Configuration molds Feature | — | — |
| OSSA-2026-007 | UNKNOWN | OSSA-2026-007: LDAP identity backend does not convert enabled attribute to boolean | — | — |
| CVE-2026-33551 | UNKNOWN | OSSA-2026-005: Restricted application credentials can create EC2 credentials | — | — |
| CVE-2026-34881 | UNKNOWN | OSSA-2026-004: Server-Side Request Forgery (SSRF) vulnerabilities in OpenStack Glance image import functionali | — | — |
| OSSN-0098 | UNKNOWN | OSSN-0098: Mistral workflow execution context exposes Keystone auth token | — | — |
| CVE | Sev | Description | CVSS | EPSS |
|---|
| USN-8390-2 | UNKNOWN | USN-8390-2: Linux kernel vulnerability | — | — |
| USN-8441-1 | UNKNOWN | USN-8441-1: Linux kernel vulnerabilities | — | — |
| USN-8361-3 | UNKNOWN | USN-8361-3: Linux kernel vulnerability | — | — |
| USN-8440-1 | UNKNOWN | USN-8440-1: Linux kernel (Azure) vulnerabilities | — | — |
| USN-8426-2 | UNKNOWN | USN-8426-2: Linux kernel (Azure) vulnerabilities | — | — |
| USN-8439-1 | UNKNOWN | USN-8439-1: Linux kernel (Oracle) vulnerabilities | — | — |
| USN-8426-1 | UNKNOWN | USN-8426-1: Linux kernel (Azure) vulnerabilities | — | — |
| USN-8421-1 | UNKNOWN | USN-8421-1: Ironic vulnerabilities | — | — |
| CVE | Sev | Description | CVSS | EPSS |
|---|
| CVE-2026-45552 | CRITICAL | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and | 9.9 | — |
| CVE-2026-45556 | CRITICAL | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and | 9.9 | — |
| CVE-2026-45558 | CRITICAL | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and | 9.9 | — |
| CVE-2026-42055 | CRITICAL | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module | 9.2 | — |
| CVE-2026-42530 | CRITICAL | NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured t | 9.2 | — |
| CVE-2026-45550 | CRITICAL | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and | 9.1 | — |
| CVE-2026-45564 | HIGH | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and | 8.8 | — |
| CVE-2026-11311 | HIGH | When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in | 8.6 | — |
| CVE-2026-50107 | HIGH | When NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vu | 8.6 | — |
| CVE-2026-45549 | HIGH | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and | 8.5 | — |
Full digest →
·
Live feed