{"schema_version":1,"title":"Apache CloudStack vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 25 vulnerabilities in Apache CloudStack: 0 in the last 7 days and 20 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-59654, was published on 21 August 2026.","url":"https://junglewise.ai/threats/technologies/cloudstack","json_url":"https://junglewise.ai/threats/technologies/cloudstack.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/cloudstack","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":15,"all_time":25,"critical":3,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":20,"last_365_days":25},"latest":[{"cve":"CVE-2026-59654","cvss":7.5,"epss":0.0059,"slug":"cve-2026-59654-apache-cloudstack-resource-leak-in-scoped-global-configuration","title":"Apache CloudStack resource leak in scoped global configuration","severity":"high","exploited":false,"published_at":"2026-08-21T13:18:17.767+00:00","url":"https://junglewise.ai/threats/cve-2026-59654-apache-cloudstack-resource-leak-in-scoped-global-configuration"},{"cve":"CVE-2026-68745","cvss":8.1,"epss":0.002,"slug":"cve-2026-68745-apache-cloudstack-certificate-validation-bypass-in-saml","title":"Apache CloudStack certificate validation bypass in SAML authentication","severity":"high","exploited":false,"published_at":"2026-08-21T09:16:40.697+00:00","url":"https://junglewise.ai/threats/cve-2026-68745-apache-cloudstack-certificate-validation-bypass-in-saml"},{"cve":"CVE-2026-66797","cvss":5.4,"epss":0.0046,"slug":"cve-2026-66797-apache-cloudstack-improper-access-control-in-annotation-apis","title":"Apache CloudStack improper access control in annotation APIs","severity":"medium","exploited":false,"published_at":"2026-08-21T09:16:40.577+00:00","url":"https://junglewise.ai/threats/cve-2026-66797-apache-cloudstack-improper-access-control-in-annotation-apis"},{"cve":"CVE-2026-66722","cvss":7.2,"epss":0.0062,"slug":"cve-2026-66722-apache-cloudstack-improper-authorization-in-project-role","title":"Apache CloudStack improper authorization in project role management","severity":"high","exploited":false,"published_at":"2026-08-21T09:16:40.46+00:00","url":"https://junglewise.ai/threats/cve-2026-66722-apache-cloudstack-improper-authorization-in-project-role"},{"cve":"CVE-2026-66721","cvss":2.7,"epss":0.0048,"slug":"cve-2026-66721-apache-cloudstack-authorization-bypass-in-host-tags-listing","title":"Apache CloudStack authorization bypass in host tags listing","severity":"low","exploited":false,"published_at":"2026-08-21T09:16:40.327+00:00","url":"https://junglewise.ai/threats/cve-2026-66721-apache-cloudstack-authorization-bypass-in-host-tags-listing"},{"cve":"CVE-2026-65613","cvss":4.3,"epss":0.0045,"slug":"cve-2026-65613-apache-cloudstack-information-disclosure-in-webhook-module","title":"Apache CloudStack information disclosure in Webhook module","severity":"medium","exploited":false,"published_at":"2026-08-21T09:16:40.207+00:00","url":"https://junglewise.ai/threats/cve-2026-65613-apache-cloudstack-information-disclosure-in-webhook-module"},{"cve":"CVE-2026-62440","cvss":9.1,"epss":0.0054,"slug":"cve-2026-62440-apache-cloudstack-improper-access-control-in-kubernetes-service","title":"Apache CloudStack improper access control in Kubernetes Service plugin","severity":"critical","exploited":false,"published_at":"2026-08-21T09:16:39.963+00:00","url":"https://junglewise.ai/threats/cve-2026-62440-apache-cloudstack-improper-access-control-in-kubernetes-service"},{"cve":"CVE-2026-61422","cvss":4.3,"epss":0.0042,"slug":"cve-2026-61422-apache-cloudstack-ssrf-in-template-and-iso-registration","title":"Apache CloudStack SSRF in template and ISO registration","severity":"medium","exploited":false,"published_at":"2026-08-21T09:16:39.84+00:00","url":"https://junglewise.ai/threats/cve-2026-61422-apache-cloudstack-ssrf-in-template-and-iso-registration"},{"cve":"CVE-2026-61400","cvss":8.8,"epss":0.0291,"slug":"cve-2026-61400-apache-cloudstack-command-injection-in-diagnostics-api","title":"Apache CloudStack command injection in diagnostics API","severity":"high","exploited":false,"published_at":"2026-08-21T09:16:39.717+00:00","url":"https://junglewise.ai/threats/cve-2026-61400-apache-cloudstack-command-injection-in-diagnostics-api"},{"cve":"CVE-2026-61399","cvss":4.8,"epss":0.005,"slug":"cve-2026-61399-apache-cloudstack-improper-output-encoding-in-lock-user-ui","title":"Apache CloudStack improper output encoding in Lock User UI","severity":"medium","exploited":false,"published_at":"2026-08-21T09:16:39.603+00:00","url":"https://junglewise.ai/threats/cve-2026-61399-apache-cloudstack-improper-output-encoding-in-lock-user-ui"},{"cve":"CVE-2026-61398","cvss":9.1,"epss":0.0057,"slug":"cve-2026-61398-apache-cloudstack-improper-output-encoding-in-password-reset-ui","title":"Apache CloudStack improper output encoding in password reset UI","severity":"critical","exploited":false,"published_at":"2026-08-21T09:16:39.48+00:00","url":"https://junglewise.ai/threats/cve-2026-61398-apache-cloudstack-improper-output-encoding-in-password-reset-ui"},{"cve":"CVE-2026-61397","cvss":7.5,"epss":0.006,"slug":"cve-2026-61397-apache-cloudstack-sensitive-information-exposure-in-oauth2","title":"Apache CloudStack sensitive information exposure in OAuth2 authentication","severity":"high","exploited":false,"published_at":"2026-08-21T09:16:39.363+00:00","url":"https://junglewise.ai/threats/cve-2026-61397-apache-cloudstack-sensitive-information-exposure-in-oauth2"},{"cve":"CVE-2026-59799","cvss":8.8,"epss":0.006,"slug":"cve-2026-59799-apache-cloudstack-privilege-management-bypass-in-two-factor","title":"Apache CloudStack privilege management bypass in two-factor authentication","severity":"high","exploited":false,"published_at":"2026-08-21T09:16:38.89+00:00","url":"https://junglewise.ai/threats/cve-2026-59799-apache-cloudstack-privilege-management-bypass-in-two-factor"},{"cve":"CVE-2026-59780","cvss":7.5,"epss":0.006,"slug":"cve-2026-59780-apache-cloudstack-information-disclosure-in-ldap-authentication","title":"Apache CloudStack information disclosure in LDAP authentication plugin","severity":"high","exploited":false,"published_at":"2026-08-21T09:16:38.77+00:00","url":"https://junglewise.ai/threats/cve-2026-59780-apache-cloudstack-information-disclosure-in-ldap-authentication"},{"cve":"CVE-2026-59657","cvss":7.5,"epss":0.0034,"slug":"cve-2026-59657-apache-cloudstack-cleartext-storage-of-sensitive-information-in","title":"Apache CloudStack cleartext storage of sensitive information in AsyncJob","severity":"high","exploited":false,"published_at":"2026-08-21T09:16:38.657+00:00","url":"https://junglewise.ai/threats/cve-2026-59657-apache-cloudstack-cleartext-storage-of-sensitive-information-in"},{"cve":"CVE-2026-59655","cvss":7.5,"epss":0.006,"slug":"cve-2026-59655-apache-cloudstack-oauth-authentication-information-disclosure","title":"Apache CloudStack OAuth authentication information disclosure","severity":"high","exploited":false,"published_at":"2026-08-21T09:16:38.533+00:00","url":"https://junglewise.ai/threats/cve-2026-59655-apache-cloudstack-oauth-authentication-information-disclosure"},{"cve":"CVE-2026-59085","cvss":9.1,"epss":0.0059,"slug":"cve-2026-59085-apache-cloudstack-ssrf-in-webhook-module","title":"Apache CloudStack SSRF in webhook module","severity":"critical","exploited":false,"published_at":"2026-08-21T09:16:38.41+00:00","url":"https://junglewise.ai/threats/cve-2026-59085-apache-cloudstack-ssrf-in-webhook-module"},{"cve":"CVE-2026-50222","cvss":7.5,"epss":0.0054,"slug":"cve-2026-50222-apache-cloudstack-missing-authorization-in-userdata-apis","title":"Apache CloudStack missing authorization in userdata APIs","severity":"high","exploited":false,"published_at":"2026-08-21T09:16:38.28+00:00","url":"https://junglewise.ai/threats/cve-2026-50222-apache-cloudstack-missing-authorization-in-userdata-apis"},{"cve":"CVE-2026-50112","cvss":8.8,"epss":0.0072,"slug":"cve-2026-50112-apache-cloudstack-rce-via-metalink-url-validation-bypass","title":"Apache CloudStack RCE via metalink URL validation bypass","severity":"high","exploited":false,"published_at":"2026-08-21T09:16:38.15+00:00","url":"https://junglewise.ai/threats/cve-2026-50112-apache-cloudstack-rce-via-metalink-url-validation-bypass"},{"cve":"CVE-2026-47359","cvss":8.8,"epss":0.0203,"slug":"cve-2026-47359-apache-cloudstack-os-command-injection-in-nas-backup-plugin","title":"Apache CloudStack OS command injection in NAS backup plugin","severity":"high","exploited":false,"published_at":"2026-08-21T09:16:38+00:00","url":"https://junglewise.ai/threats/cve-2026-47359-apache-cloudstack-os-command-injection-in-nas-backup-plugin"},{"cve":"CVE-2026-25077","cvss":8.8,"slug":"cve-2026-25077-account-users-are-allowed-by-default-to-register-templates-to-be","title":"Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using th","severity":"high","exploited":false,"published_at":"2026-05-08T13:16:36.133+00:00","url":"https://junglewise.ai/threats/cve-2026-25077-account-users-are-allowed-by-default-to-register-templates-to-be"},{"cve":"CVE-2025-66467","cvss":8,"slug":"cve-2025-66467-apache-cloudstack-incomplete-cleanup-in-minio-bucket-deletion","title":"Apache CloudStack incomplete cleanup in MinIO bucket deletion","severity":"high","exploited":false,"published_at":"2026-05-08T13:16:35.72+00:00","url":"https://junglewise.ai/threats/cve-2025-66467-apache-cloudstack-incomplete-cleanup-in-minio-bucket-deletion"},{"cve":"CVE-2025-66172","cvss":8.1,"slug":"cve-2025-66172-the-cloudstack-backup-plugin-has-an-improper-access-logic-in","title":"The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access i","severity":"high","exploited":false,"published_at":"2026-05-08T13:16:35.607+00:00","url":"https://junglewise.ai/threats/cve-2025-66172-the-cloudstack-backup-plugin-has-an-improper-access-logic-in"},{"cve":"CVE-2025-66171","cvss":6.5,"slug":"cve-2025-66171-apache-cloudstack-improper-access-control-in-backup-plugin","title":"Apache CloudStack improper access control in Backup plugin","severity":"medium","exploited":false,"published_at":"2026-05-08T13:16:35.483+00:00","url":"https://junglewise.ai/threats/cve-2025-66171-apache-cloudstack-improper-access-control-in-backup-plugin"},{"cve":"CVE-2025-66170","cvss":6.5,"slug":"cve-2025-66170-apache-cloudstack-improper-authorization-in-backup-plugin","title":"Apache CloudStack improper authorization in Backup plugin","severity":"medium","exploited":false,"published_at":"2026-05-08T13:16:35.36+00:00","url":"https://junglewise.ai/threats/cve-2025-66170-apache-cloudstack-improper-authorization-in-backup-plugin"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":3,"exploited":0,"vulnerabilities":20},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Apache Tomcat","slug":"tomcat","vulnerabilities":67,"url":"https://junglewise.ai/threats/technologies/tomcat"},{"name":"Apache Airflow","slug":"airflow","vulnerabilities":61,"url":"https://junglewise.ai/threats/technologies/airflow"},{"name":"Apache Camel","slug":"camel","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/camel"},{"name":"Apache Traffic Server","slug":"traffic-server","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/traffic-server"},{"name":"Apache HTTP Server","slug":"http-server","vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/http-server"},{"name":"Apache Ofbiz","slug":"ofbiz","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/ofbiz"},{"name":"Apache ActiveMQ","slug":"activemq","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/activemq"},{"name":"Apache Storm","slug":"storm","vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/storm"},{"name":"Apache Apisix","slug":"apisix","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/apisix"},{"name":"Apache Thrift","slug":"thrift","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/thrift"},{"name":"Apache ActiveMQ Artemis","slug":"activemq-artemis","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/activemq-artemis"},{"name":"Apache Ranger","slug":"ranger","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/ranger"}],"technology":{"hub":true,"name":"Apache CloudStack","slug":"cloudstack","vendor":{"name":"Apache","slug":"apache","url":"https://junglewise.ai/threats/vendors/apache"},"aliases":[],"category":"cloud-computing-platform","homepage":"https://cloudstack.apache.org/","repo_url":"https://github.com/apache/cloudstack","description":"An open-source cloud computing software for creating, managing, and deploying infrastructure cloud services.","url":"https://junglewise.ai/threats/technologies/cloudstack"},"most_severe":[{"cve":"CVE-2026-59085","cvss":9.1,"epss":0.0059,"slug":"cve-2026-59085-apache-cloudstack-ssrf-in-webhook-module","title":"Apache CloudStack SSRF in webhook module","severity":"critical","exploited":false,"published_at":"2026-08-21T09:16:38.41+00:00","url":"https://junglewise.ai/threats/cve-2026-59085-apache-cloudstack-ssrf-in-webhook-module"},{"cve":"CVE-2026-61398","cvss":9.1,"epss":0.0057,"slug":"cve-2026-61398-apache-cloudstack-improper-output-encoding-in-password-reset-ui","title":"Apache CloudStack improper output encoding in password reset UI","severity":"critical","exploited":false,"published_at":"2026-08-21T09:16:39.48+00:00","url":"https://junglewise.ai/threats/cve-2026-61398-apache-cloudstack-improper-output-encoding-in-password-reset-ui"},{"cve":"CVE-2026-62440","cvss":9.1,"epss":0.0054,"slug":"cve-2026-62440-apache-cloudstack-improper-access-control-in-kubernetes-service","title":"Apache CloudStack improper access control in Kubernetes Service plugin","severity":"critical","exploited":false,"published_at":"2026-08-21T09:16:39.963+00:00","url":"https://junglewise.ai/threats/cve-2026-62440-apache-cloudstack-improper-access-control-in-kubernetes-service"},{"cve":"CVE-2026-61400","cvss":8.8,"epss":0.0291,"slug":"cve-2026-61400-apache-cloudstack-command-injection-in-diagnostics-api","title":"Apache CloudStack command injection in diagnostics API","severity":"high","exploited":false,"published_at":"2026-08-21T09:16:39.717+00:00","url":"https://junglewise.ai/threats/cve-2026-61400-apache-cloudstack-command-injection-in-diagnostics-api"},{"cve":"CVE-2026-47359","cvss":8.8,"epss":0.0203,"slug":"cve-2026-47359-apache-cloudstack-os-command-injection-in-nas-backup-plugin","title":"Apache CloudStack OS command injection in NAS backup plugin","severity":"high","exploited":false,"published_at":"2026-08-21T09:16:38+00:00","url":"https://junglewise.ai/threats/cve-2026-47359-apache-cloudstack-os-command-injection-in-nas-backup-plugin"},{"cve":"CVE-2026-50112","cvss":8.8,"epss":0.0072,"slug":"cve-2026-50112-apache-cloudstack-rce-via-metalink-url-validation-bypass","title":"Apache CloudStack RCE via metalink URL validation bypass","severity":"high","exploited":false,"published_at":"2026-08-21T09:16:38.15+00:00","url":"https://junglewise.ai/threats/cve-2026-50112-apache-cloudstack-rce-via-metalink-url-validation-bypass"},{"cve":"CVE-2026-59799","cvss":8.8,"epss":0.006,"slug":"cve-2026-59799-apache-cloudstack-privilege-management-bypass-in-two-factor","title":"Apache CloudStack privilege management bypass in two-factor authentication","severity":"high","exploited":false,"published_at":"2026-08-21T09:16:38.89+00:00","url":"https://junglewise.ai/threats/cve-2026-59799-apache-cloudstack-privilege-management-bypass-in-two-factor"},{"cve":"CVE-2026-25077","cvss":8.8,"slug":"cve-2026-25077-account-users-are-allowed-by-default-to-register-templates-to-be","title":"Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using th","severity":"high","exploited":false,"published_at":"2026-05-08T13:16:36.133+00:00","url":"https://junglewise.ai/threats/cve-2026-25077-account-users-are-allowed-by-default-to-register-templates-to-be"},{"cve":"CVE-2026-68745","cvss":8.1,"epss":0.002,"slug":"cve-2026-68745-apache-cloudstack-certificate-validation-bypass-in-saml","title":"Apache CloudStack certificate validation bypass in SAML authentication","severity":"high","exploited":false,"published_at":"2026-08-21T09:16:40.697+00:00","url":"https://junglewise.ai/threats/cve-2026-68745-apache-cloudstack-certificate-validation-bypass-in-saml"},{"cve":"CVE-2025-66172","cvss":8.1,"slug":"cve-2025-66172-the-cloudstack-backup-plugin-has-an-improper-access-logic-in","title":"The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access i","severity":"high","exploited":false,"published_at":"2026-05-08T13:16:35.607+00:00","url":"https://junglewise.ai/threats/cve-2025-66172-the-cloudstack-backup-plugin-has-an-improper-access-logic-in"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}