Continue reading the full briefing.
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Several security issues were discovered in the Linux kernel. An attacker could possibly use these…
Why it matters: Ubuntu Security Notices may be embedded across servers, containers, appliances, and administration hosts. Package installation alone does not prove that the corrected code is running.
What to verify: Compare distribution package versions, identify the loaded kernel or library, plan required service restarts or reboots, and validate workload health after the change.
Operational focus: Confirm whether the provider has remediated the platform or whether tenant configuration remains exposed.
Open the original Ubuntu Security Notices record
CVE-2026-70473: Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history
### Summary The **GET `/api/v1/upsert-history`** endpoint returns the **entire server-wide upsert history** (response size **>100MB**) instead of being scoped to the requesting user/tenant/workspace. The response includes **sensitive configuration data** (e.g., Vector Store settings such as **Qdrant Server URL** and **collection name**), resulting in a **High severity information disclosure** that may enable further targeted attacks. ### Details – **Affected…
Why it matters: GitHub Advisory Database flowise participates in the path from source code to production. A weakness can inherit runner permissions, build secrets, trusted artifacts, or deployment access.
What to verify: Trace untrusted input through pull requests and jobs, review token scope, isolate runners, pin trusted dependencies, and rebuild affected artifacts after remediation.
Operational focus: Review public endpoints, privileged identities, service accounts, and cross-account trust.
Flowise: Incomplete Credential Redaction Exposes Secrets via API
## Summary The `GET /api/v1/credentials/:id` endpoint decrypts stored credential data and returns it in the `plainDataObj` field of the API response. While a `redactCredentialWithPasswordType()` function masks fields defined with `type: 'password'` in their component schema, many credential types store highly sensitive data (database connection URLs with embedded passwords, Google service account JSON with RSA private keys, AWS access…
Why it matters: GitHub Advisory Database flowise participates in the path from source code to production. A weakness can inherit runner permissions, build secrets, trusted artifacts, or deployment access.
What to verify: Trace untrusted input through pull requests and jobs, review token scope, isolate runners, pin trusted dependencies, and rebuild affected artifacts after remediation.
Operational focus: Keep audit logs outside the workload account and verify they cover the affected control plane.
CVE-2026-10090: A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red…
A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub namespace can create a Channel resource pointing to a Helm repository they control and a Subscription resource referencing it. The app-subscription controller fetches and applies the Helm chart contents…
Why it matters: CVE-2026-10090 may be embedded across servers, containers, appliances, and administration hosts. Package installation alone does not prove that the corrected code is running.
What to verify: Compare distribution package versions, identify the loaded kernel or library, plan required service restarts or reboots, and validate workload health after the change.
Operational focus: Confirm whether the provider has remediated the platform or whether tenant configuration remains exposed.
Open the original NIST National Vulnerability Database record
CVE-2026-14529: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server…
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server – Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.
Why it matters: CVE-2026-14529 participates in the path from source code to production. A weakness can inherit runner permissions, build secrets, trusted artifacts, or deployment access.
What to verify: Trace untrusted input through pull requests and jobs, review token scope, isolate runners, pin trusted dependencies, and rebuild affected artifacts after remediation.
Operational focus: Review public endpoints, privileged identities, service accounts, and cross-account trust.
Open the original NIST National Vulnerability Database record
Cloud response plan
Separate provider-side remediation from tenant-owned configuration. Check identities, public endpoints, workload images, service accounts, regions, and audit coverage before closing the issue.
- Map provider and package advisories to accounts, projects, regions, clusters, and managed services in use.
- Review public storage, load balancers, admin ports, and broad network rules.
- Remove stale keys, broad roles, unused service accounts, and persistent administrative access.
- Patch worker nodes, container images, agents, and self-managed control-plane components.
- Confirm centralized audit logging and alerting after every remediation.
Tenant checks
Verify the affected account and region, the identity path, public reachability, provider responsibility, and audit evidence.
- Confirm whether the provider has remediated the platform or whether tenant configuration remains exposed.
- Review public endpoints, privileged identities, service accounts, and cross-account trust.
- Keep audit logs outside the workload account and verify they cover the affected control plane.
Cloud team takeaway
Close cloud findings only after both the provider status and tenant configuration are understood, with centralized logs showing the repaired control is working.
References used in this briefing
- NIST National Vulnerability Database: CVE-2026-10059: A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller.…
- NIST National Vulnerability Database: CVE-2026-57510: SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService…
- GitHub Advisory Database: CVE-2026-70476: Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation
- Ubuntu Security Notices: USN-8615-2: Linux kernel (Raspberry Pi) vulnerabilities
- GitHub Advisory Database: CVE-2026-70473: Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history
- GitHub Advisory Database: Flowise: Incomplete Credential Redaction Exposes Secrets via API
- NIST National Vulnerability Database: CVE-2026-10090: A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red…
- NIST National Vulnerability Database: CVE-2026-14529: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server…
Need to add context to this briefing?
Send corrections, security tips, source updates, or collaboration notes through the contact page so the editorial team can review them properly.

