
Red Hat Kubernetes SSRF Vulnerability Exposes Internal Managed Cluster Services
Red Hat has disclosed CVE-2026-66794, an important-severity server-side request forgery vulnerability affecting the cluster-proxy-addon component in Multicluster Engine for Kubernetes. The flaw, published on August 19, 2026, carries a CVSS v3.1 score of 9.3 and could allow unauthenticated remote attackers to access services that would otherwise remain isolated inside connected managed clusters. Tracked under CWE-918, […]
The post Red Hat Kubernetes SSRF Vulnerability Exposes Internal Managed Cluster Services appeared first on Cyber Security News.