LIVE · cybersecurity feed
Live wire
vendor

Kubernetes

1 CVEs published in the last four months and 3 stories. Exploited flaws first.

Critical0
High1
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-43428.8highnginx ingress controllerA security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject c205d ago

Filter the full tracker by Kubernetes →

Our coverage of Kubernetes

CVE-2026-63688critical

Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

Dell has issued security updates to address several critical vulnerabilities within its Container Storage Modules (CSM) that could be leveraged by malicious actors to compromise affected systems. Among the disclosed flaws is CVE-2026-63688, which has been assigned a CVSS score of 10.0. This particular vulnerability is described as a missing authentication for critical function flaw residing in…

cloud

EU Cyber Resilience Act requirements for containers and Kubernetes

The European Union's Cyber Resilience Act (CRA), Regulation (EU 2024/2847), will impose mandatory cybersecurity requirements on all digital products sold within EU markets, significantly impacting organizations that develop and distribute containerized applications and Kubernetes deployments. The regulation, which entered into full force on December 10, 2024, will begin its reporting…

threat actorhigh

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

Reports indicate that the threat actor group identified as TeamPCP has been active since at least 2020, engaging in cybercriminal operations that predate their more widely recognized supply chain campaigns. Early activities attributed to the group reportedly involved exploiting vulnerabilities in internet-facing infrastructure, specifically mentioning Redis servers and AI platforms. These…