Technology · KubeVirt
KubeVirt vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 10 vulnerabilities in KubeVirt: 0 in the last 7 days and 0 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-13434, was published on 26 June 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 1
- Exploited in the wild
- 0
About KubeVirt
KubeVirt is an open-source virtualization add-on for Kubernetes that allows running virtual machines alongside containers.
Latest KubeVirt vulnerabilities
- CVE-2026-13434: KubeVirt improper input validation in network annotation generatormediumCVSS 4.9
- CVE-2026-13325: KubeVirt authentication bypass in migration proxy when TLS is disabledhighCVSS 8.5
- CVE-2026-13322: KubeVirt unbounded memory allocation in virt-handler virtio-serial serverlowCVSS 3.8
- CVE-2026-13318: KubeVirt SSRF in virt-api port-forward handlermediumCVSS 6.4
- CVE-2026-13218: KubeVirt virt-handler symlink following in WriteToCachedFilemediumCVSS 4.2
- CVE-2026-13208: KubeVirt virt-handler improper authentication in domain notify servermediumCVSS 6.5
- CVE-2026-13201: KubeVirt safepath symlink following in OpenAtNoFollowmediumCVSS 5.2
- CVE-2026-9804: KubeVirt path traversal in virt-exportserver via symlink escapehighCVSS 7.7EPSS 0.7%
- CVE-2026-7374: KubeVirt virt-handler privilege escalation via symlink followingcriticalCVSS 9.9EPSS 0.8%
- CVE-2026-6383: KubeVirt incorrect RBAC evaluation via subresource name truncationmediumCVSS 5.4EPSS 0.3%
Most severe KubeVirt vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-7374: KubeVirt virt-handler privilege escalation via symlink followingcriticalCVSS 9.9EPSS 0.8%
- CVE-2026-13325: KubeVirt authentication bypass in migration proxy when TLS is disabledhighCVSS 8.5
- CVE-2026-9804: KubeVirt path traversal in virt-exportserver via symlink escapehighCVSS 7.7EPSS 0.7%
- CVE-2026-13208: KubeVirt virt-handler improper authentication in domain notify servermediumCVSS 6.5
- CVE-2026-13318: KubeVirt SSRF in virt-api port-forward handlermediumCVSS 6.4
- CVE-2026-6383: KubeVirt incorrect RBAC evaluation via subresource name truncationmediumCVSS 5.4EPSS 0.3%
- CVE-2026-13201: KubeVirt safepath symlink following in OpenAtNoFollowmediumCVSS 5.2
- CVE-2026-13434: KubeVirt improper input validation in network annotation generatormediumCVSS 4.9
- CVE-2026-13218: KubeVirt virt-handler symlink following in WriteToCachedFilemediumCVSS 4.2
- CVE-2026-13322: KubeVirt unbounded memory allocation in virt-handler virtio-serial serverlowCVSS 3.8
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/kubevirt.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "KubeVirt vulnerabilities", https://junglewise.ai/threats/technologies/kubevirt, 26 September 2026.