Executive brief
A series of vulnerabilities were discovered in Envoy Proxy, a widely-used service mesh and proxy component in cloud environments. These vulnerabilities could allow attackers to compromise service mesh configurations, intercept traffic, or gain unauthorized access to network services running on affected infrastructure.
Technical details
Multiple security vulnerabilities were identified in Envoy Proxy as tracked under 13 distinct CVE identifiers (CVE-2026-73513, CVE-2026-73552, CVE-2026-73512, CVE-2026-73547, CVE-2026-73549, CVE-2026-50572, CVE-2026-73546, CVE-2026-48521, CVE-2026-73551, CVE-2026-73511, CVE-2026-73548, CVE-2026-73550, CVE-2026-73553). The vulnerabilities span moderate to high severity ratings. Specific technical details regarding vulnerability class, attack vectors, and preconditions are not disclosed in the available advisory excerpt. Details and remediation guidance are available in the Cloud Service Mesh security bulletin. The advisory does not indicate active exploitation in the wild at the time of publication.
Affected products
- Envoy Envoy Proxy
CVE identifiers
- CVE-2026-73552
- CVE-2026-73511
- CVE-2026-73546
- CVE-2026-73548
- CVE-2026-73551
- CVE-2026-73547
- CVE-2026-73549
- CVE-2026-48521
- CVE-2026-50572
- CVE-2026-73513
- CVE-2026-73550
- CVE-2026-73553
- CVE-2026-73512
Timeline
- 2026-08-26: disclosed