Technology · Red Hat
Red Hat Multicluster Global Hub vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 19 vulnerabilities in Red Hat Multicluster Global Hub: 0 in the last 7 days and 2 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-71577, was published on 10 August 2026.
- Last 7 days
- 0
- Last 90 days
- 2
- Critical, all time
- 1
- Exploited in the wild
- 0
About Red Hat Multicluster Global Hub
Multicluster Global Hub is a management suite for aggregating and visualizing data across multiple Red Hat Advanced Cluster Management for Kubernetes clusters.
Latest Red Hat Multicluster Global Hub vulnerabilities
- CVE-2026-71577: Red Hat Multicluster Global Hub privilege escalation during ManagedClusterMigrationmediumCVSS 6.3EPSS 0.4%
- CVE-2026-71576: Red Hat Multicluster Global Hub authentication bypass in Kafka CloudEventshighCVSS 8.5EPSS 0.2%
- CVE-2026-43869: Apache Thrift improper certificate validation in TSSLTransportFactoryhighCVSS 7.3EPSS 0.8%
- CVE-2026-41607: Apache Thrift out-of-bounds read in C++ JSON implementationmediumCVSS 6.5EPSS 0.5%
- CVE-2026-41606: Apache Thrift uncontrolled recursion in c_glib dispatchmediumCVSS 5.3EPSS 0.6%
- CVE-2026-41605: Apache Thrift integer overflow in Swift Compact ProtocolhighCVSS 7.3EPSS 0.5%
- CVE-2026-41604: Apache Thrift out-of-bounds read in Swift Range skip functionhighCVSS 8.2EPSS 0.6%
- CVE-2026-41603: Apache Thrift improper certificate validation in Java TSSLTransportFactoryhighCVSS 7.4EPSS 0.3%
- CVE-2026-41602: Apache Thrift integer overflow in Go TFramedTransporthighCVSS 7.5EPSS 0.7%
- CVE-2026-40293: OpenFGA API key exposure in playground endpointmediumCVSS 6.5EPSS 0.5%
- CVE-2025-41118: Grafana Pyroscope information disclosure in Tencent COS configuration APIcriticalCVSS 9.1EPSS 0.4%
- CVE-2026-32285: buger jsonparser denial of service via negative slice index panichighCVSS 7.5EPSS 1.0%
- CVE-2026-33487: russellhaering goxmldsig signature bypass in validateSignaturehighCVSS 7.5EPSS 0.4%
- CVE-2026-33247: NATS-Server sensitive information disclosure in monitoring endpointhighCVSS 7.4EPSS 0.3%
- CVE-2026-33218: NATS-Server denial of service in leafnode handlinghighCVSS 7.5EPSS 0.4%
- CVE-2026-33217: NATS-Server ACL bypass in MQTT namespacehighCVSS 7.1EPSS 0.4%
- CVE-2026-33216: NATS-Server plaintext password disclosure in monitoring endpointshighCVSS 8.6EPSS 0.3%
- CVE-2026-29785: nats-io nats-server NULL pointer dereference in leafnode protocolhighCVSS 7.5EPSS 1.0%
- CVE-2026-27889: NATS Server denial of service via WebSocket frame length overflowhighCVSS 7.5EPSS 0.8%
Most severe Red Hat Multicluster Global Hub vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-41118: Grafana Pyroscope information disclosure in Tencent COS configuration APIcriticalCVSS 9.1EPSS 0.4%
- CVE-2026-33216: NATS-Server plaintext password disclosure in monitoring endpointshighCVSS 8.6EPSS 0.3%
- CVE-2026-71576: Red Hat Multicluster Global Hub authentication bypass in Kafka CloudEventshighCVSS 8.5EPSS 0.2%
- CVE-2026-41604: Apache Thrift out-of-bounds read in Swift Range skip functionhighCVSS 8.2EPSS 0.6%
- CVE-2026-32285: buger jsonparser denial of service via negative slice index panichighCVSS 7.5EPSS 1.0%
- CVE-2026-29785: nats-io nats-server NULL pointer dereference in leafnode protocolhighCVSS 7.5EPSS 1.0%
- CVE-2026-27889: NATS Server denial of service via WebSocket frame length overflowhighCVSS 7.5EPSS 0.8%
- CVE-2026-41602: Apache Thrift integer overflow in Go TFramedTransporthighCVSS 7.5EPSS 0.7%
- CVE-2026-33218: NATS-Server denial of service in leafnode handlinghighCVSS 7.5EPSS 0.4%
- CVE-2026-33487: russellhaering goxmldsig signature bypass in validateSignaturehighCVSS 7.5EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 2 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/multicluster-global-hub.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Red Hat Multicluster Global Hub vulnerabilities", https://junglewise.ai/threats/technologies/multicluster-global-hub, 26 September 2026.