LIVE · cybersecurity feed
Live wire
vendor

Cloudfoundry

4 CVEs published in the last four months. Exploited flaws first.

Critical1
High3
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-478269.1criticalbosh cliThe blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files an59d ago
CVE-2026-478288.8highbosh cliDuring bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to th59d ago
CVE-2026-418577.8highbosh cliA compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when t59d ago
CVE-2026-478297.8highbosh cliArgument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the loc59d ago

Filter the full tracker by Cloudfoundry