Skip to main content

Security Alerts

Find security alerts related to our cloud services here. This page is updated daily to reflect newly identified vulnerabilities.

Vulnerabilities

DateReference(s)CVSSTitleDescriptionService(s)SeverityRemediation
29/07/2026VMSA-2026-00069.8VMSA-2026-0006: Critical Vulnerabilities in VMware vCenter (CVE-2026-59309, CVE-2026-59310)Authentication bypass in the VMware directory service (CVE-2026-59309) and directory traversal in the vCenter Syslog server allowing unauthenticated remote code execution (CVE-2026-59310). An attacker with network access to vCenter can compromise the management plane.IaaS By VMware🔴 Critical✅ Updating your vCenter instances is scheduled as soon as patches are validated by Cloud Temple. No action is required on your part. The update will be indicated in Console notifications.
29/07/2026VMSA-2026-00062.7 - 9.3VMSA-2026-0006: VM Escape in VMware ESX (CVE-2026-47876)Out-of-bounds write in the VMXNET3 virtual network adapter (CVE-2026-47876): an attacker with administrative privileges inside a VM can execute code on the ESX host (VM escape). The advisory also fixes a less severe out-of-bounds read (CVE-2026-41703).IaaS By VMware🟠 Important⚠️ We recommend updating your hypervisors. Patched ESXi versions will be available as soon as they are validated by Cloud Temple. Console will indicate which ESXi hosts require an update.
13/07/2026CVE-2026-155847.5Vulnerability in Red Hat OpenShift (CVE-2026-15584)Privilege escalation via the incluster-checks tool: privileged debug pods created in the default namespace allow a user to escalate privileges.PaaS OpenShift🟠 Important✅ Updating your OpenShift instances is scheduled as soon as patches are validated by Cloud Temple. No action is required on your part.
29/06/2026CVE-2026-540998.8Vulnerability in Red Hat OpenShift (CVE-2026-54099)Incorrect validation of Certificate Signing Request (CSR) queries in the Windows operator: a compromised Windows node can escalate its privileges within the cluster.PaaS OpenShift🟠 Important✅ Updating your OpenShift instances is scheduled as soon as patches are validated by Cloud Temple. No action is required on your part.
29/06/2026CVE-2026-541008.3Vulnerability in Red Hat OpenShift (CVE-2026-54100)SSH key verification flaw in the Windows operator: a network-based attacker can intercept credentials during Windows node configuration.PaaS OpenShift🟠 Important✅ Updating your OpenShift instances is scheduled as soon as patches are validated by Cloud Temple. No action is required on your part.
29/06/2026CVE-2026-106096.8Vulnerability in Red Hat OpenShift (CVE-2026-10609)Access control flaw in the Cluster Logging Operator allowing a delegated writer to exfiltrate ServiceAccount tokens and escalate privileges.PaaS OpenShift🟡 Moderate✅ Updating your OpenShift instances is scheduled as soon as patches are validated by Cloud Temple. No action is required on your part.
23/06/2026CVE-2026-42487N/DXCP-NG Vulnerability (CVE-2026-42487)A vulnerability related to x86 HVM I/O port list traversal allows an HVM guest to crash the hypervisor (DoS), potentially escalate privileges, or leak information. The actual impact is considered highly unlikely on XCP-ng.IaaS OpenSource🔵 Low✅ Updating your XCP-ng instances is scheduled as soon as patches are validated by Cloud Temple. No action is required on your part.
09/06/2026XSA-492 / VSA-2026-0185.3XCP-NG Vulnerability (CVE-2026-42489)Unfair domctl system lock: a low-privilege entity can block operations from an entity of equal or higher priority, causing a denial of service for the entire host.IaaS OpenSource🟡 Moderate✅ Updating your XCP-ng instances is scheduled as soon as patches are validated by Cloud Temple. No action is required on your part.
02/06/2026CVE-2026-17848.8Vulnerability in Red Hat OpenShift (CVE-2026-1784)A vulnerability in the ose-cluster-ingress-operator component allows remote code execution (RCE) via HAProxy configuration injection. Exploitation requires permissions to create or modify an OpenShift Route resource (specifically the spec.path field).PaaS OpenShift🟠 Important✅ Updating your OpenShift instances is scheduled as soon as patches are validated by Cloud Temple. No action is required on your part.
02/06/2026VSA-2026-0165.5 - 7.8XCP-NG Vulnerabilities (CVE-2026-46333 / CVE-2026-43494)Vulnerabilities in the ptrace and RDS subsystems of the XCP-ng dom0 Linux kernel (exploits ptrace_may_dream, Pintheft) allow a local unprivileged user to escalate privileges to root, with cross-reboot persistence possible for CVE-2026-46333.IaaS OpenSource🟠 Important✅ Updating your XCP-ng instances is scheduled as soon as patches are validated by Cloud Temple. No action is required on your part.
02/06/2026CVE-2026-105335.0Vulnerability in Red Hat OpenShift (CVE-2026-10533)Denial of service in OpenShift Container Platform: terminated pods that are not properly cleaned up can exhaust resources.PaaS OpenShift🟡 Moderate✅ Updating your OpenShift instances is scheduled as soon as patches are validated by Cloud Temple. No action is required on your part.
01/06/2026CVE-2026-73749.9Vulnerability in Red Hat OpenShift (CVE-2026-7374)Critical access control flaw in the KubeVirt virt-handler component (VM virtualization on OpenShift), which could lead to compromise.PaaS OpenShift🟠 Important✅ Updating your OpenShift instances is scheduled as soon as patches are validated by Cloud Temple. No action is required on your part.
01/06/2026CVE-2026-429657.7Vulnerability in Red Hat OpenShift (CVE-2026-42965)Information disclosure in OpenShift Router: incorrect FQDN validation in EndpointSlices exposes information.PaaS OpenShift🟠 Important✅ Updating your OpenShift instances is scheduled as soon as patches are validated by Cloud Temple. No action is required on your part.
29/05/2026CVE-2026-465797.4Vulnerability in Red Hat OpenShift (CVE-2026-46579)Authentication bypass in OpenShift Router related to improper handling of the insecureEdgeTerminationPolicy policy.PaaS OpenShift🟠 Important✅ Updating your OpenShift instances is scheduled as soon as patches are validated by Cloud Temple. No action is required on your part.
21/05/2026VSA-2026-0147.8XCP-NG Vulnerability (CVE-2026-43284 / CVE-2026-46300)Vulnerabilities in the XFRM-ESP modules of the XCP-ng dom0 Linux kernel (exploits DirtyFrag, CopyFail2, Fragnesia) allow a local unprivileged user to escalate privileges to root.IaaS OpenSource🟠 Important✅ Updating your XCP-ng instances is scheduled as soon as patches are validated by Cloud Temple. No action is required on your part.
21/05/2026XSA-4907.3XCP-NG Vulnerability (XSA-490 / CVE-2025-54518)A vulnerability in AMD Zen2 processors (CPU opcode cache corruption) allows code running in a guest VM to escalate privileges to the host level (dom0).IaaS OpenSource🟠 Important✅ Updating your XCP-ng instances is scheduled as soon as patches are validated by Cloud Temple. No action is required on your part.
20/05/2026XSA-486 / VSA-2026-0087.8XCP-NG Vulnerability (CVE-2026-23558)Race condition in the mapping of Xen grant table v2 status pages: a privileged user in an HVM/PVH VM can escalate privileges to the hypervisor level.IaaS OpenSource🟠 Important✅ Updating your XCP-ng instances is scheduled as soon as patches are validated by Cloud Temple. No action is required on your part.
20/05/2026XSA-4846.5XCP-NG Vulnerability (CVE-2026-23557)Denial of service via the XS_RESET_WATCHES command in xenstored: an unprivileged guest VM can crash the service and block host domain administration.IaaS OpenSource🟡 Moderate✅ Updating your XCP-ng instances is scheduled as soon as patches are validated by Cloud Temple. No action is required on your part.
10/05/2026DSA-2026-0195.6 - 9.8DSA-2026-019: Multiple Vulnerabilities in Dell ECS and ObjectScaleHardcoded credentials granting file system access (CVE-2026-40636, 9.8), local privilege escalation (CVE-2026-26946), CSV formula injection in the interface (CVE-2026-35157), and geographic replication authentication bypass (CVE-2025-43992).Object Storage🟠 Important✅ Remediation of your ObjectScale environments is handled by Cloud Temple. No action is required on your part.
29/04/2026CVE-2026-73094.3Vulnerability in Red Hat OpenShift (CVE-2026-7309)Information disclosure in OpenShift Container Platform via arbitrary environment variable injection.PaaS OpenShift🟡 Moderate✅ Updating your OpenShift instances is scheduled as soon as patches are validated by Cloud Temple. No action is required on your part.
13/04/2026CVE-2025-578546.4Vulnerability in Red Hat OpenShift (CVE-2025-57854)Privilege escalation in OpenShift Update Service images.PaaS OpenShift🟡 Moderate✅ Updating your OpenShift instances is scheduled as soon as patches are validated by Cloud Temple. No action is required on your part.
13/04/2026CVE-2025-142435.3Vulnerability in Red Hat OpenShift (CVE-2025-14243)Information disclosure in OpenShift Mirror Registry via divergent error messages during writes.PaaS OpenShift🟡 Moderate✅ Updating your OpenShift instances is scheduled as soon as patches are validated by Cloud Temple. No action is required on your part.
06/04/2026DSA-2026-1437.8DSA-2026-143: Vulnerability in Dell ObjectScale (CVE-2026-28261)A vulnerability (CVE-2026-28261) in Dell ObjectScale related to the insertion of sensitive information into log files allows a local attacker to expose secrets and escalate privileges to compromise the system.Object Storage🟡 Moderate✅ Remediation of your ObjectScale environments is handled by Cloud Temple. No action is required on your part.
23/03/2026XSA-4807.8XCP-NG Vulnerability (CVE-2026-23554)A vulnerability (CVE-2026-23554) has been identified in XCP-ng 8.3, specifically affecting systems based on Intel x86 processors, allowing a VM to compromise the host (privilege escalation or DoS).IaaS OpenSource🟠 Important✅ Updating your XCP-ng instances is scheduled as soon as patches are validated by Cloud Temple. No action is required on your part.
29/01/2026Bulletin éditeur2.9 - 8.5XCP-NG VulnerabilitiesSeveral vulnerabilities have been discovered in XCP-ng. The most significant allows privilege escalation from a VM to dom0. Other flaws allow arbitrary code execution via NVMe emulation or confidential data leaks between virtual machines.IaaS OpenSource🟠 Important✅ Updating your XCP-ng instances is scheduled as soon as patches are validated by Cloud Temple. No action is required on your part.
23/01/2026DSA-2026-0474.4 - 8.8DSA-2026-047: Vulnerabilities in Dell ObjectScaleMultiple vulnerabilities in Dell ObjectScale related to default credentials and plaintext transmission/storage allow local or remote compromise.Object Storage🟠 Important✅ Remediation of your ObjectScale environments is handled by Cloud Temple. No action is required on your part.
23/12/2025CVE-2025-144438.5Vulnerability in Red Hat OpenShift (CVE-2025-14443)A vulnerability in the openshift-apiserver component allows privilege escalation. Exploitation requires prior authentication.PaaS OpenShift🟠 Important✅ Updating your OpenShift instances is scheduled as soon as patches are validated by Cloud Temple. No action is required on your part.
30/09/2025VMSA-2025-00168.5VMSA-2025-0016: Vulnerability in VMware vCenter (CVE-2025-41250)A vulnerability (CVE-2025-41250) allows an authenticated attacker to modify notification emails for scheduled tasks.IaaS By VMware🟠 Important✅ Updating your vCenter instances is scheduled as soon as patches are validated by Cloud Temple. No action is required on your part. The update will be indicated in Console notifications..

| 30/09/2025 | VMSA-2025-0015 | 7.6 | VMSA-2025-0015 : Vulnerability in VMware Tools (Windows) | A vulnerability (CVE-2025-41246) affecting VMware Tools for Windows allows privilege escalation (nécessite un accès local authentifié). | IaaS By VMware | 🟡 Moderate | ⚠️ We recommend updating VMware Tools on your virtual machines. The patched VM Tools versions are included in the ESXi packages provided by Cloud Temple. | | 07/08/2025 | DSA-2025-154 | 8.4 | DSA-2025-154 : Vulnerability in Dell ObjectScale (CVE-2025-26476) | A vulnerability (CVE-2025-26476) in Dell ObjectScale (< 4.0.0.0) related to the use of hard-coded SSH keys allows unauthenticated local access. | Object Storage | 🟠 Important | ✅ Remediation for your ObjectScale environments is handled by Cloud Temple. No action is required on your part. | | 15/07/2025 | VMSA-2025-0013 | 9.3 | VMSA-2025-0013 : Important Vulnerabilities in VMware ESXi | Several important vulnerabilities affect VMware ESXi. Patches are provided by the vendor. | IaaS By VMware | 🟠 Important | ⚠️ We recommend updating your hypervisors. Patched ESXi versions are available upon validation by Cloud Temple. The Console will indicate which ESXi hosts require an update. | | 15/07/2025 | VMSA-2025-0013 | 7.1 | VMSA-2025-0013 : Vulnerability in VMware Tools (CVE-2025-41239) | A vulnerability (CVE-2025-41239) in VMware Tools allows sensitive information disclosure via uninitialized vSockets. Patches are provided by the vendor. | IaaS By VMware | 🟡 Moderate | ⚠️ We recommend updating VMware Tools on your virtual machines. The patched VM Tools versions are included in the ESXi packages provided by Cloud Temple. | | 01/07/2025 | XSA-470 | N/A | XCP-NG Vulnerability via Improper Exception Handling Bulletin éditeur | A vulnerability has been discovered in XCP-NG, allowing privileged code executed from a virtual machine to crash the hypervisor, resulting in a denial of service (DoS) for the entire host. | IaaS OpenSource | 🟡 Moderate | ✅ Updating your XCP-ng instances is scheduled upon validation of the patches by Cloud Temple. No action is required on your part.| | 23/05/2025 | XSA-468 | 8.8-9.0 | XCP-NG Vulnerabilities in Windows PV Drivers (XSA-468) Bulletin éditeur | Several vulnerabilities (CVE-2025-27462, CVE-2025-27463, CVE-2025-27464) in Windows PV drivers allow unprivileged users to obtain system privileges inside Windows VMs. | IaaS OpenSource | 🟠 Important | ⚠️ We recommend updating the Windows PV drivers on your virtual machines to the patched versions indicated in the security bulletin. ✅ Updating your XCP-ng instances is scheduled upon validation of the patches by Cloud Temple. | | 22/05/2025 | XSA-469, INTEL-SA | 4.9-6.5 | XCP-NG Vulnerabilities in Intel Microcode and Xen (XSA-469, INTEL-SA) Bulletin éditeur | Security patches for XCP-ng have been released, fixing several vulnerabilities in Intel microcode and Xen. | IaaS OpenSource | 🟡 Moderate | ✅ Updating your XCP-ng instances is scheduled upon validation of the patches by Cloud Temple. No action is required on your part.| | 21/05/2025 | VMSA-2025-0010 | 4.3-6.8 | VMSA-2025-0010 : Multiple Vulnerabilities in VMware ESXi (CVE-2025-41226, CVE-2025-41227, CVE-2025-41228) | Several vulnerabilities in VMware ESXi have been reported: Guest operations denial of service vulnerability (CVE-2025-41226), Denial of service vulnerability (CVE-2025-41227), Cross-Site Scripting (XSS) vulnerability (CVE-2025-41228). Patches are provided by the vendor. | IaaS By VMware | 🟡 Moderate | ⚠️ We recommend updating your hypervisors. Patched ESXi versions are available upon validation by Cloud Temple. The Console will indicate which ESXi hosts require an update. | | 21/05/2025 | VMSA-2025-0010 | 4.3-8.8 | VMSA-2025-0010 : Multiple Vulnerabilities in vCenter (CVE-2025-41225, CVE-2025-41228) | Several vulnerabilities in VMware vCenter have been reported: Authenticated command execution vulnerability in VMware vCenter Server (CVE-2025-41225), Cross-Site Scripting (XSS) vulnerability (CVE-2025-41228). Patches are provided by the vendor. | IaaS By VMware | 🟠 Important | ✅ Updating your vCenter instances is scheduled upon validation of the patches by Cloud Temple. No action is required on your part. The update is indicated in the Console notifications.. | | 14/05/2025 | VMSA-2025-0007 | 6.1 | VMSA-2025-0007 : Insecure File Handling Vulnerability in VMware Tools (CVE-2025-22247) | An insecure file handling vulnerability in VMware Tools has been reported. Patches are provided by the vendor. | IaaS By VMware | 🟡 Moderate | ⚠️ We recommend updating VMware Tools on your virtual machines. The patched VM Tools versions are included in the ESXi packages provided by Cloud Temple. | | 25/03/2025 | VMSA-2025-0005 | 7.8 | VMSA-2025-0005 : Authentication Bypass Vulnerability in VMware Tools for Windows (CVE-2025-22230) | An authentication bypass vulnerability in VMware Tools for Windows has been reported. Patches are provided by the vendor. | IaaS By VMware | 🟠 Important | ⚠️ We recommend updating VMware Tools on your virtual machines. The patched VM Tools versions are included in the ESXi packages provided by Cloud Temple | | 04/03/2025 | VMSA-2025-0004 | 7.1-9.3 | VMSA-2025-0004 : Multiple Vulnerabilities in VMware ESXi (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226) | Several vulnerabilities in VMware ESXi have been reported: VMCI heap overflow vulnerability (CVE-2025-22224) rated Critical by VMware, Arbitrary write vulnerability in VMware ESXi (CVE-2025-22225), HGFS information disclosure vulnerability (CVE-2025-22226). Patches are provided by the vendor. | IaaS By VMware | 🟠 Important | ⚠️ We recommend updating your hypervisors. Patched ESXi versions are available upon validation by Cloud Temple. The Console will indicate which ESXi hosts require an update. |

Information

  • Date : Initial publication date of the Cloud Temple security alert.
  • Reference(s) : CVE ID, if available.
  • CVSS : Base CVSS v3 score as reported by the vendor or CVE, non-contextualized. Contextualization is expressed by the CT severity. If the alert covers multiple vulnerabilities, the minimum and maximum CVSS scores are indicated.
  • Title : Alert title, with vendor reference if available.
  • Description : Concise description, with link(s) to detailed information.
  • Service(s) : Cloud Temple service(s) that may be affected.
  • Severity : Severity level within the context of Cloud Temple services (for the most critical vulnerability in case of multiple vulnerabilities). Exploitation criteria are considered within the technical context of our cloud infrastructure and services.
LevelDescription
🔴 CriticalCVSS 7+ vulnerability presenting a significant exploitation risk (high exposure, ease of exploitation). A patch or mitigation as soon as possible is strongly recommended.
🟠 ImportantCVSS 7+ vulnerability not presenting a significant exploitation risk (limited exposure or exploitation constraints)
🟡 ModerateCVSS 4+ vulnerability
🔵 LowCVSS vulnerability below 4, or unexploitable.
  • Handling : Information and recommendations within the context of Cloud Temple services. ⚠️ indicates that user action is required to address the vulnerability. ✅ indicates that vulnerability handling is managed by Cloud Temple.