{"schema_version":1,"title":"Red Hat Advanced Cluster Security for Kubernetes vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 11 vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes: 0 in the last 7 days and 2 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-19278, was published on 10 August 2026.","url":"https://junglewise.ai/threats/technologies/advanced-cluster-security-for-kubernetes","json_url":"https://junglewise.ai/threats/technologies/advanced-cluster-security-for-kubernetes.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/advanced-cluster-security-for-kubernetes","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":7,"all_time":11,"critical":2,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":2,"last_365_days":11},"latest":[{"cve":"CVE-2026-19278","cvss":6.8,"epss":0.0035,"slug":"cve-2026-19278-red-hat-advanced-cluster-security-privilege-escalation-in-m2m","title":"Red Hat Advanced Cluster Security privilege escalation in M2M auth","severity":"medium","exploited":false,"published_at":"2026-08-10T13:17:58.797+00:00","url":"https://junglewise.ai/threats/cve-2026-19278-red-hat-advanced-cluster-security-privilege-escalation-in-m2m"},{"cve":"CVE-2026-10079","cvss":8.5,"slug":"cve-2026-10079-red-hat-advanced-cluster-security-policy-bypass-via-label","title":"Red Hat Advanced Cluster Security policy bypass via label injection","severity":"high","exploited":false,"published_at":"2026-07-31T10:16:43.19+00:00","url":"https://junglewise.ai/threats/cve-2026-10079-red-hat-advanced-cluster-security-policy-bypass-via-label"},{"cve":"CVE-2026-31938","cvss":9.6,"epss":0.004,"slug":"cve-2026-31938-parallax-jspdf-xss-in-output-function-options","title":"parallax jsPDF XSS in output function options","severity":"critical","exploited":false,"published_at":"2026-03-18T04:17:23.507+00:00","url":"https://junglewise.ai/threats/cve-2026-31938-parallax-jspdf-xss-in-output-function-options"},{"cve":"CVE-2026-31898","cvss":8.1,"epss":0.0062,"slug":"cve-2026-31898-parallax-jspdf-pdf-object-injection-in-createannotation","title":"parallax jsPDF PDF object injection in createAnnotation","severity":"high","exploited":false,"published_at":"2026-03-18T04:17:21.05+00:00","url":"https://junglewise.ai/threats/cve-2026-31898-parallax-jspdf-pdf-object-injection-in-createannotation"},{"cve":"CVE-2026-25896","cvss":9.3,"epss":0.005,"slug":"cve-2026-25896-naturalintelligence-fast-xml-parser-xss-via-regex-injection-in","title":"NaturalIntelligence fast-xml-parser XSS via regex injection in DOCTYPE","severity":"critical","exploited":false,"published_at":"2026-02-20T21:19:27.47+00:00","url":"https://junglewise.ai/threats/cve-2026-25896-naturalintelligence-fast-xml-parser-xss-via-regex-injection-in"},{"cve":"CVE-2026-26278","cvss":7.5,"epss":0.0097,"slug":"cve-2026-26278-naturalintelligence-fast-xml-parser-denial-of-service-via-entity","title":"NaturalIntelligence fast-xml-parser denial of service via entity expansion","severity":"high","exploited":false,"published_at":"2026-02-19T20:25:43.717+00:00","url":"https://junglewise.ai/threats/cve-2026-26278-naturalintelligence-fast-xml-parser-denial-of-service-via-entity"},{"cve":"CVE-2026-25940","cvss":8.1,"epss":0.0063,"slug":"cve-2026-25940-parallax-jspdf-pdf-injection-in-acroform-module","title":"parallax jsPDF PDF injection in Acroform module","severity":"high","exploited":false,"published_at":"2026-02-19T16:27:15.66+00:00","url":"https://junglewise.ai/threats/cve-2026-25940-parallax-jspdf-pdf-injection-in-acroform-module"},{"cve":"CVE-2026-25755","cvss":8.1,"epss":0.008,"slug":"cve-2026-25755-parallax-jspdf-pdf-object-injection-in-addjs-method","title":"parallax jsPDF PDF object injection in addJS method","severity":"high","exploited":false,"published_at":"2026-02-19T15:16:12.303+00:00","url":"https://junglewise.ai/threats/cve-2026-25755-parallax-jspdf-pdf-object-injection-in-addjs-method"},{"cve":"CVE-2026-25535","cvss":7.5,"epss":0.0092,"slug":"cve-2026-25535-parallax-jspdf-denial-of-service-in-addimage-method","title":"parallax jsPDF denial of service in addImage method","severity":"high","exploited":false,"published_at":"2026-02-19T15:16:12.13+00:00","url":"https://junglewise.ai/threats/cve-2026-25535-parallax-jspdf-denial-of-service-in-addimage-method"},{"cve":"CVE-2026-24737","cvss":8.1,"epss":0.0055,"slug":"cve-2026-24737-parallax-jspdf-pdf-injection-in-acroform-module","title":"parallax jsPDF PDF injection in Acroform module","severity":"high","exploited":false,"published_at":"2026-02-02T23:16:08.443+00:00","url":"https://junglewise.ai/threats/cve-2026-24737-parallax-jspdf-pdf-injection-in-acroform-module"},{"cve":"CVE-2025-11065","cvss":5.3,"epss":0.0041,"slug":"cve-2025-11065-go-viper-mapstructure-information-disclosure-in-weakdecode","title":"go-viper mapstructure information disclosure in WeakDecode","severity":"medium","exploited":false,"published_at":"2026-01-26T20:16:06.84+00:00","url":"https://junglewise.ai/threats/cve-2025-11065-go-viper-mapstructure-information-disclosure-in-weakdecode"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Red Hat Enterprise Linux 9","slug":"enterprise-linux-9","vulnerabilities":146,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-9"},{"name":"Red Hat Enterprise Linux 10","slug":"enterprise-linux-10","vulnerabilities":140,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-10"},{"name":"Red Hat Enterprise Linux 8","slug":"enterprise-linux-8","vulnerabilities":132,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-8"},{"name":"Red Hat Enterprise Linux 7","slug":"enterprise-linux-7","vulnerabilities":68,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-7"},{"name":"Red Hat Keycloak","slug":"build-of-keycloak","vulnerabilities":61,"url":"https://junglewise.ai/threats/technologies/build-of-keycloak"},{"name":"Red Hat Enterprise Linux 6","slug":"enterprise-linux-6","vulnerabilities":56,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-6"},{"name":"Red Hat Build of Keycloak","slug":"red-hat-build-of-keycloak","vulnerabilities":54,"url":"https://junglewise.ai/threats/technologies/red-hat-build-of-keycloak"},{"name":"Red Hat Enterprise Linux AppStream","slug":"enterprise-linux-appstream","vulnerabilities":46,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-appstream"},{"name":"Red Hat OpenShift Container Platform 4","slug":"openshift-container-platform-4","vulnerabilities":36,"url":"https://junglewise.ai/threats/technologies/openshift-container-platform-4"},{"name":"Red Hat Ansible Automation Platform","slug":"ansible-automation-platform-2","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/ansible-automation-platform-2"},{"name":"Red Hat Developer Hub","slug":"developer-hub","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/developer-hub"},{"name":"Red Hat Multicluster Global Hub","slug":"multicluster-global-hub","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/multicluster-global-hub"}],"technology":{"hub":true,"name":"Red Hat Advanced Cluster Security for Kubernetes","slug":"advanced-cluster-security-for-kubernetes","vendor":{"name":"Red Hat","slug":"red-hat","url":"https://junglewise.ai/threats/vendors/red-hat"},"aliases":[],"category":"software","homepage":"https://www.redhat.com/en/technologies/cloud-computing/openshift/advanced-cluster-security-kubernetes","repo_url":"https://github.com/stackrox/stackrox","description":"Red Hat Advanced Cluster Security for Kubernetes is a security platform for containerized environments based on StackRox.","url":"https://junglewise.ai/threats/technologies/advanced-cluster-security-for-kubernetes"},"most_severe":[{"cve":"CVE-2026-31938","cvss":9.6,"epss":0.004,"slug":"cve-2026-31938-parallax-jspdf-xss-in-output-function-options","title":"parallax jsPDF XSS in output function options","severity":"critical","exploited":false,"published_at":"2026-03-18T04:17:23.507+00:00","url":"https://junglewise.ai/threats/cve-2026-31938-parallax-jspdf-xss-in-output-function-options"},{"cve":"CVE-2026-25896","cvss":9.3,"epss":0.005,"slug":"cve-2026-25896-naturalintelligence-fast-xml-parser-xss-via-regex-injection-in","title":"NaturalIntelligence fast-xml-parser XSS via regex injection in DOCTYPE","severity":"critical","exploited":false,"published_at":"2026-02-20T21:19:27.47+00:00","url":"https://junglewise.ai/threats/cve-2026-25896-naturalintelligence-fast-xml-parser-xss-via-regex-injection-in"},{"cve":"CVE-2026-10079","cvss":8.5,"slug":"cve-2026-10079-red-hat-advanced-cluster-security-policy-bypass-via-label","title":"Red Hat Advanced Cluster Security policy bypass via label injection","severity":"high","exploited":false,"published_at":"2026-07-31T10:16:43.19+00:00","url":"https://junglewise.ai/threats/cve-2026-10079-red-hat-advanced-cluster-security-policy-bypass-via-label"},{"cve":"CVE-2026-25755","cvss":8.1,"epss":0.008,"slug":"cve-2026-25755-parallax-jspdf-pdf-object-injection-in-addjs-method","title":"parallax jsPDF PDF object injection in addJS method","severity":"high","exploited":false,"published_at":"2026-02-19T15:16:12.303+00:00","url":"https://junglewise.ai/threats/cve-2026-25755-parallax-jspdf-pdf-object-injection-in-addjs-method"},{"cve":"CVE-2026-25940","cvss":8.1,"epss":0.0063,"slug":"cve-2026-25940-parallax-jspdf-pdf-injection-in-acroform-module","title":"parallax jsPDF PDF injection in Acroform module","severity":"high","exploited":false,"published_at":"2026-02-19T16:27:15.66+00:00","url":"https://junglewise.ai/threats/cve-2026-25940-parallax-jspdf-pdf-injection-in-acroform-module"},{"cve":"CVE-2026-31898","cvss":8.1,"epss":0.0062,"slug":"cve-2026-31898-parallax-jspdf-pdf-object-injection-in-createannotation","title":"parallax jsPDF PDF object injection in createAnnotation","severity":"high","exploited":false,"published_at":"2026-03-18T04:17:21.05+00:00","url":"https://junglewise.ai/threats/cve-2026-31898-parallax-jspdf-pdf-object-injection-in-createannotation"},{"cve":"CVE-2026-24737","cvss":8.1,"epss":0.0055,"slug":"cve-2026-24737-parallax-jspdf-pdf-injection-in-acroform-module","title":"parallax jsPDF PDF injection in Acroform module","severity":"high","exploited":false,"published_at":"2026-02-02T23:16:08.443+00:00","url":"https://junglewise.ai/threats/cve-2026-24737-parallax-jspdf-pdf-injection-in-acroform-module"},{"cve":"CVE-2026-26278","cvss":7.5,"epss":0.0097,"slug":"cve-2026-26278-naturalintelligence-fast-xml-parser-denial-of-service-via-entity","title":"NaturalIntelligence fast-xml-parser denial of service via entity expansion","severity":"high","exploited":false,"published_at":"2026-02-19T20:25:43.717+00:00","url":"https://junglewise.ai/threats/cve-2026-26278-naturalintelligence-fast-xml-parser-denial-of-service-via-entity"},{"cve":"CVE-2026-25535","cvss":7.5,"epss":0.0092,"slug":"cve-2026-25535-parallax-jspdf-denial-of-service-in-addimage-method","title":"parallax jsPDF denial of service in addImage method","severity":"high","exploited":false,"published_at":"2026-02-19T15:16:12.13+00:00","url":"https://junglewise.ai/threats/cve-2026-25535-parallax-jspdf-denial-of-service-in-addimage-method"},{"cve":"CVE-2026-19278","cvss":6.8,"epss":0.0035,"slug":"cve-2026-19278-red-hat-advanced-cluster-security-privilege-escalation-in-m2m","title":"Red Hat Advanced Cluster Security privilege escalation in M2M auth","severity":"medium","exploited":false,"published_at":"2026-08-10T13:17:58.797+00:00","url":"https://junglewise.ai/threats/cve-2026-19278-red-hat-advanced-cluster-security-privilege-escalation-in-m2m"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}