Technology · Apache
Apache CloudStack vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 25 vulnerabilities in Apache CloudStack: 0 in the last 7 days and 20 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-59654, was published on 21 August 2026.
- Last 7 days
- 0
- Last 90 days
- 20
- Critical, all time
- 3
- Exploited in the wild
- 0
About Apache CloudStack
An open-source cloud computing software for creating, managing, and deploying infrastructure cloud services.
Latest Apache CloudStack vulnerabilities
- CVE-2026-59654: Apache CloudStack resource leak in scoped global configurationhighCVSS 7.5EPSS 0.6%
- CVE-2026-68745: Apache CloudStack certificate validation bypass in SAML authenticationhighCVSS 8.1EPSS 0.2%
- CVE-2026-66797: Apache CloudStack improper access control in annotation APIsmediumCVSS 5.4EPSS 0.5%
- CVE-2026-66722: Apache CloudStack improper authorization in project role managementhighCVSS 7.2EPSS 0.6%
- CVE-2026-66721: Apache CloudStack authorization bypass in host tags listinglowCVSS 2.7EPSS 0.5%
- CVE-2026-65613: Apache CloudStack information disclosure in Webhook modulemediumCVSS 4.3EPSS 0.4%
- CVE-2026-62440: Apache CloudStack improper access control in Kubernetes Service plugincriticalCVSS 9.1EPSS 0.5%
- CVE-2026-61422: Apache CloudStack SSRF in template and ISO registrationmediumCVSS 4.3EPSS 0.4%
- CVE-2026-61400: Apache CloudStack command injection in diagnostics APIhighCVSS 8.8EPSS 2.9%
- CVE-2026-61399: Apache CloudStack improper output encoding in Lock User UImediumCVSS 4.8EPSS 0.5%
- CVE-2026-61398: Apache CloudStack improper output encoding in password reset UIcriticalCVSS 9.1EPSS 0.6%
- CVE-2026-61397: Apache CloudStack sensitive information exposure in OAuth2 authenticationhighCVSS 7.5EPSS 0.6%
- CVE-2026-59799: Apache CloudStack privilege management bypass in two-factor authenticationhighCVSS 8.8EPSS 0.6%
- CVE-2026-59780: Apache CloudStack information disclosure in LDAP authentication pluginhighCVSS 7.5EPSS 0.6%
- CVE-2026-59657: Apache CloudStack cleartext storage of sensitive information in AsyncJobhighCVSS 7.5EPSS 0.3%
- CVE-2026-59655: Apache CloudStack OAuth authentication information disclosurehighCVSS 7.5EPSS 0.6%
- CVE-2026-59085: Apache CloudStack SSRF in webhook modulecriticalCVSS 9.1EPSS 0.6%
- CVE-2026-50222: Apache CloudStack missing authorization in userdata APIshighCVSS 7.5EPSS 0.5%
- CVE-2026-50112: Apache CloudStack RCE via metalink URL validation bypasshighCVSS 8.8EPSS 0.7%
- CVE-2026-47359: Apache CloudStack OS command injection in NAS backup pluginhighCVSS 8.8EPSS 2.0%
- CVE-2026-25077: Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying…highCVSS 8.8
- CVE-2025-66467: Apache CloudStack incomplete cleanup in MinIO bucket deletionhighCVSS 8
- CVE-2025-66172: The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated…highCVSS 8.1
- CVE-2025-66171: Apache CloudStack improper access control in Backup pluginmediumCVSS 6.5
- CVE-2025-66170: Apache CloudStack improper authorization in Backup pluginmediumCVSS 6.5
Most severe Apache CloudStack vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-59085: Apache CloudStack SSRF in webhook modulecriticalCVSS 9.1EPSS 0.6%
- CVE-2026-61398: Apache CloudStack improper output encoding in password reset UIcriticalCVSS 9.1EPSS 0.6%
- CVE-2026-62440: Apache CloudStack improper access control in Kubernetes Service plugincriticalCVSS 9.1EPSS 0.5%
- CVE-2026-61400: Apache CloudStack command injection in diagnostics APIhighCVSS 8.8EPSS 2.9%
- CVE-2026-47359: Apache CloudStack OS command injection in NAS backup pluginhighCVSS 8.8EPSS 2.0%
- CVE-2026-50112: Apache CloudStack RCE via metalink URL validation bypasshighCVSS 8.8EPSS 0.7%
- CVE-2026-59799: Apache CloudStack privilege management bypass in two-factor authenticationhighCVSS 8.8EPSS 0.6%
- CVE-2026-25077: Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying…highCVSS 8.8
- CVE-2026-68745: Apache CloudStack certificate validation bypass in SAML authenticationhighCVSS 8.1EPSS 0.2%
- CVE-2025-66172: The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated…highCVSS 8.1
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 20 | 3 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/cloudstack.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Apache CloudStack vulnerabilities", https://junglewise.ai/threats/technologies/cloudstack, 26 September 2026.