VulncastBriefing archive

Daily Brief - 2026-08-19

· 5 vulnerabilities · 6 min listen

▶ Listen to this briefing

CVE-2026-66780

critical · CVSS 9.9 · Red Hat Advanced Cluster Management for Kubernetes

A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, specifically by overwriting other clusters' endpoint information. Consequently, an attacker can redirect inter-cluster tunnel traffic, enabling a Man-in-the-Middle (MITM) attack across the entire cluster mesh.

  • Man-in-the-Middle
  • kubernetes
  • container orchestration

CVE-2026-71102

critical · CVSS 9.1 · Oracle Database Server

Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Portable Clusterware. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Portable Clusterware accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Portable Clusterware. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).

  • Unauthorized Data Access
  • Denial Of Service
  • database server
  • clusterware

CVE-2026-75627

critical · CVSS 9.8 · Bastillion

Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administrative controllers to read user listings, create manager accounts, and register managed systems, gaining control over SSH access to the managed fleet.

  • Authentication Bypass
  • java
  • web application

CVE-2026-75874

critical · CVSS 10 · Mozilla Firefox

Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.

  • Sandbox Escape
  • web browser

CVE-2026-76047

Google Chrome

Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • Type Confusion
  • Remote Code Execution
  • web browser
  • javascript engine