{"schema_version":1,"title":"Kubernetes vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 8 vulnerabilities in Kubernetes: 0 in the last 7 days and 1 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-15687, was published on 23 July 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/kubernetes","json_url":"https://junglewise.ai/threats/vendors/kubernetes.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/kubernetes","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":1,"all_time":8,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":1,"last_365_days":3},"latest":[{"cve":"CVE-2026-15687","cvss":2.4,"slug":"cve-2026-15687-kubernetes-java-client-path-traversal-in-copydirectoryfrompod","title":"Kubernetes Java client path traversal in copyDirectoryFromPod","severity":"low","exploited":false,"published_at":"2026-07-23T19:16:53.39+00:00","url":"https://junglewise.ai/threats/cve-2026-15687-kubernetes-java-client-path-traversal-in-copydirectoryfrompod"},{"cve":"CVE-2026-4342","cvss":8.8,"epss":0.006,"slug":"cve-2026-4342-kubernetes-ingress-nginx-configuration-injection-via-annotations","title":"Kubernetes ingress-nginx configuration injection via annotations","severity":"high","exploited":false,"published_at":"2026-03-19T22:16:43.143+00:00","url":"https://junglewise.ai/threats/cve-2026-4342-kubernetes-ingress-nginx-configuration-injection-via-annotations"},{"cve":"CVE-2025-57870","cvss":10,"epss":0.0054,"slug":"cve-2025-57870-a-sql-injection-vulnerability-exists-in-esri-arcgis-server","title":"A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability","severity":"critical","exploited":false,"published_at":"2025-10-22T15:15:51.83+00:00","url":"https://junglewise.ai/threats/cve-2025-57870-a-sql-injection-vulnerability-exists-in-esri-arcgis-server"},{"cve":"CVE-2021-25736","cvss":5.8,"epss":0.0092,"slug":"cve-2021-25736-kubernetes-kube-proxy-traffic-forwarding-error-on-windows","title":"Kubernetes kube-proxy traffic forwarding error on Windows","severity":"medium","exploited":false,"published_at":"2023-10-30T03:30:15+00:00","url":"https://junglewise.ai/threats/cve-2021-25736-kubernetes-kube-proxy-traffic-forwarding-error-on-windows"},{"cve":"CVE-2020-8554","cvss":5,"epss":0.0927,"slug":"cve-2020-8554-kubernetes-traffic-interception-via-unverified-externalips","title":"Kubernetes traffic interception via unverified ExternalIPs ownership","severity":"medium","exploited":false,"published_at":"2022-02-08T21:50:34+00:00","url":"https://junglewise.ai/threats/cve-2020-8554-kubernetes-traffic-interception-via-unverified-externalips"},{"cve":"CVE-2020-8562","cvss":3.1,"epss":0.0108,"slug":"cve-2020-8562-kubernetes-proxy-ip-restriction-bypass-via-dns-toctou","title":"Kubernetes proxy IP restriction bypass via DNS TOCTOU","severity":"low","exploited":false,"published_at":"2022-02-02T00:01:58+00:00","url":"https://junglewise.ai/threats/cve-2020-8562-kubernetes-proxy-ip-restriction-bypass-via-dns-toctou"},{"cve":"CVE-2021-25740","cvss":3.1,"epss":0.0195,"slug":"cve-2021-25740-kubernetes-confused-deputy-in-endpoints-and-endpointslices","title":"Kubernetes confused deputy in Endpoints and EndpointSlices","severity":"low","exploited":false,"published_at":"2021-09-21T18:28:30+00:00","url":"https://junglewise.ai/threats/cve-2021-25740-kubernetes-confused-deputy-in-endpoints-and-endpointslices"},{"cve":"CVE-2020-8561","cvss":4.1,"epss":0.021,"slug":"cve-2020-8561-kubernetes-kube-apiserver-confused-deputy-in-webhook","title":"Kubernetes kube-apiserver confused deputy in webhook configurations","severity":"medium","exploited":false,"published_at":"2021-09-21T18:28:21+00:00","url":"https://junglewise.ai/threats/cve-2020-8561-kubernetes-kube-apiserver-confused-deputy-in-webhook"}],"vendor":{"hub":true,"name":"Kubernetes","slug":"kubernetes","homepage":"https://kubernetes.io/","description":"Kubernetes is an open-source system for automating deployment, scaling, and management of containerized applications.","url":"https://junglewise.ai/threats/vendors/kubernetes"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2025-57870","cvss":10,"epss":0.0054,"slug":"cve-2025-57870-a-sql-injection-vulnerability-exists-in-esri-arcgis-server","title":"A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability","severity":"critical","exploited":false,"published_at":"2025-10-22T15:15:51.83+00:00","url":"https://junglewise.ai/threats/cve-2025-57870-a-sql-injection-vulnerability-exists-in-esri-arcgis-server"},{"cve":"CVE-2026-4342","cvss":8.8,"epss":0.006,"slug":"cve-2026-4342-kubernetes-ingress-nginx-configuration-injection-via-annotations","title":"Kubernetes ingress-nginx configuration injection via annotations","severity":"high","exploited":false,"published_at":"2026-03-19T22:16:43.143+00:00","url":"https://junglewise.ai/threats/cve-2026-4342-kubernetes-ingress-nginx-configuration-injection-via-annotations"},{"cve":"CVE-2021-25736","cvss":5.8,"epss":0.0092,"slug":"cve-2021-25736-kubernetes-kube-proxy-traffic-forwarding-error-on-windows","title":"Kubernetes kube-proxy traffic forwarding error on Windows","severity":"medium","exploited":false,"published_at":"2023-10-30T03:30:15+00:00","url":"https://junglewise.ai/threats/cve-2021-25736-kubernetes-kube-proxy-traffic-forwarding-error-on-windows"},{"cve":"CVE-2020-8554","cvss":5,"epss":0.0927,"slug":"cve-2020-8554-kubernetes-traffic-interception-via-unverified-externalips","title":"Kubernetes traffic interception via unverified ExternalIPs ownership","severity":"medium","exploited":false,"published_at":"2022-02-08T21:50:34+00:00","url":"https://junglewise.ai/threats/cve-2020-8554-kubernetes-traffic-interception-via-unverified-externalips"},{"cve":"CVE-2020-8561","cvss":4.1,"epss":0.021,"slug":"cve-2020-8561-kubernetes-kube-apiserver-confused-deputy-in-webhook","title":"Kubernetes kube-apiserver confused deputy in webhook configurations","severity":"medium","exploited":false,"published_at":"2021-09-21T18:28:21+00:00","url":"https://junglewise.ai/threats/cve-2020-8561-kubernetes-kube-apiserver-confused-deputy-in-webhook"},{"cve":"CVE-2021-25740","cvss":3.1,"epss":0.0195,"slug":"cve-2021-25740-kubernetes-confused-deputy-in-endpoints-and-endpointslices","title":"Kubernetes confused deputy in Endpoints and EndpointSlices","severity":"low","exploited":false,"published_at":"2021-09-21T18:28:30+00:00","url":"https://junglewise.ai/threats/cve-2021-25740-kubernetes-confused-deputy-in-endpoints-and-endpointslices"},{"cve":"CVE-2020-8562","cvss":3.1,"epss":0.0108,"slug":"cve-2020-8562-kubernetes-proxy-ip-restriction-bypass-via-dns-toctou","title":"Kubernetes proxy IP restriction bypass via DNS TOCTOU","severity":"low","exploited":false,"published_at":"2022-02-02T00:01:58+00:00","url":"https://junglewise.ai/threats/cve-2020-8562-kubernetes-proxy-ip-restriction-bypass-via-dns-toctou"},{"cve":"CVE-2026-15687","cvss":2.4,"slug":"cve-2026-15687-kubernetes-java-client-path-traversal-in-copydirectoryfrompod","title":"Kubernetes Java client path traversal in copyDirectoryFromPod","severity":"low","exploited":false,"published_at":"2026-07-23T19:16:53.39+00:00","url":"https://junglewise.ai/threats/cve-2026-15687-kubernetes-java-client-path-traversal-in-copydirectoryfrompod"}],"generated_at":"2026-09-26T16:07:00.132667+00:00","technologies":[{"name":"Kubernetes","slug":"kubernetes","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/kubernetes"}]}