Critical Intel Stream

Vulnerability
Intelligence.

Proactive technical analysis of zero-day threats and critical CVEs affecting Linux kernel, Kubernetes, and cloud infrastructure.

System Health: Operational
1
2
3
4
+12
Active Threats
482
Analyzed Logs
1.2M
Verified Fixes
100%

Intelligence Records

Sort:
Severity Filter
MCP Kubernetes Server - Read-Only Access Control Bypass
High Severity
SCORE: 8.8
CVE-2026-46519
Jun 29, 2026

MCP Kubernetes Server - Read-Only Access Control Bypass

"A high-severity security vulnerability in the mcp-server-kubernetes project allows AI agents or clients to bypass configured read-only restrictions and execute mutating cluster commands because restriction checks are missing in the tool execution layer."

KubernetesMCPAI
Docker Engine AuthZ Plugin Bypass via Oversized Request Body
High Severity
SCORE: 8.8
CVE-2026-34040
Jun 25, 2026

Docker Engine AuthZ Plugin Bypass via Oversized Request Body

"An incomplete fix for CVE-2024-41110 in Moby (Docker Engine) allows attackers to bypass authorization (AuthZ) plugins by sending API requests exceeding 1MB, leading to potential unauthorized privilege escalation."

DockerContainersBypass
Heap Buffer Overflow in Nginx Rewrite Module
Critical Severity
SCORE: 9.2
CVE-2026-42945
Jun 11, 2026

Heap Buffer Overflow in Nginx Rewrite Module

"A heap buffer overflow vulnerability in NGINX's rewrite module, allowing unauthenticated remote attackers to trigger denial-of-service or potentially execute arbitrary code via malformed URI requests."

NginxRCEOverflow
Linux Kernel Plan 9 Filesystem Client Privilege Escalation
High Severity
SCORE: 7.8
CVE-2026-52906
Jun 9, 2026

Linux Kernel Plan 9 Filesystem Client Privilege Escalation

"A privilege escalation vulnerability in the Linux kernel's Plan 9 (9p) client mount subsystem allowing unprivileged users to bypass access control restrictions."

LinuxKernelFilesystem
HTTP/2 Bomb - Denial of Service Memory Exhaustion in Web Gateways
High Severity
SCORE: 7.5
CVE-2026-49975
Jun 3, 2026

HTTP/2 Bomb - Denial of Service Memory Exhaustion in Web Gateways

"A denial-of-service vulnerability affecting HTTP/2 web servers (including NGINX) where unauthenticated attackers send malicious header compression frames to exhaust system memory."

NginxHTTP/2DoS
Unauthenticated Remote Code Execution in n8n Workflow Automation
Critical Severity
SCORE: 9.8
CVE-2026-27495
May 28, 2026

Unauthenticated Remote Code Execution in n8n Workflow Automation

"A critical Remote Code Execution vulnerability in n8n nodes enabling unauthenticated remote attackers to execute arbitrary commands, facilitating lateral movement within Kubernetes clusters."

n8nWorkflowAutomation
Remote Code Execution in vLLM Multimodal Inference Server
Critical Severity
SCORE: 9.8
CVE-2026-22778
May 24, 2026

Remote Code Execution in vLLM Multimodal Inference Server

"A critical Remote Code Execution vulnerability in vLLM's video processing path allowing unauthenticated remote attackers to execute arbitrary system commands via malformed video inputs, leading to host container escape."

vLLMAIInference
DirtyClone - Linux Kernel Page Cache Manipulation via SKB Cloning
High Severity
SCORE: 8.8
CVE-2026-43503
May 21, 2026

DirtyClone - Linux Kernel Page Cache Manipulation via SKB Cloning

"A high-severity local privilege escalation vulnerability in the Linux kernel where unprivileged users can modify read-only file pages in memory (Page Cache) due to incorrect SKBFL_SHARED_FRAG flag propagation."

LinuxKernelLPE
Fragnesia - Linux Kernel IPv6 ESP-in-TCP Page Cache Corruption
High Severity
SCORE: 8.8
CVE-2026-46300
May 19, 2026

Fragnesia - Linux Kernel IPv6 ESP-in-TCP Page Cache Corruption

"A logic flaw in the Linux kernel's socket buffer coalescing mechanism within the XFRM ESP-in-TCP subsystem, allowing local attackers to corrupt the page cache and escalate privileges."

LinuxKernelNetworking
Microsoft SSO Plugin Authentication Bypass in Jira & Confluence
Critical Severity
SCORE: 9.1
CVE-2026-41103
May 12, 2026

Microsoft SSO Plugin Authentication Bypass in Jira & Confluence

"An administrative privilege escalation and authentication bypass vulnerability in the Microsoft SSO plugin for Atlassian Jira and Confluence, allowing remote unauthenticated attackers to hijack enterprise user sessions."

AtlassianSSOPrivilege Escalation
DirtyFrag - Successor to CopyFail via Networking Subsystems
High Severity
SCORE: 8.8
CVE-2026-43284
May 5, 2026

DirtyFrag - Successor to CopyFail via Networking Subsystems

"A successor to CopyFail that utilizes vulnerabilities in the IPsec and RxRPC subsystems to achieve local privilege escalation via page cache manipulation."

LinuxKernelNetworking
CopyFail - Deterministic Logic Flaw in Linux Crypto Subsystem
Critical Severity
SCORE: 9.8
CVE-2026-31431
Apr 20, 2026

CopyFail - Deterministic Logic Flaw in Linux Crypto Subsystem

"A high-impact deterministic logic flaw in the Linux kernel cryptographic subsystem allowing unprivileged local users to gain root privileges by manipulating the page cache."

LinuxKernelLPE
Authentication Bypass & Remote Code Execution in Nginx UI
Critical Severity
SCORE: 9.8
CVE-2026-33032
Mar 18, 2026

Authentication Bypass & Remote Code Execution in Nginx UI

"A critical missing authentication flaw in Nginx UI that allows unauthenticated remote attackers to execute arbitrary system commands via the web terminal integration, leading to container takeover."

NginxRCEAuthentication Bypass