CVE-2026-16242Critical· 9.4▾ MidnightA flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not va…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 51.7 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Aug 2.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.6%
0.6% → 0.8%
Last analysed / modified upstream
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-12548Critical· 9.0A flaw was found in Eclipse Che che-machine-exec
CVE-2026-15563High· 7.4A flaw was found in EAP's IIOP
CVE-2026-15581High· 8.0A flaw was found in the TrustyAI Service (TAS) deployment
CVE-2025-5187Medium· 6.7kubernetes: kube-apiserver: Nodes can delete themselves by adding an OwnerReference (CVE-2025-5187)
CVE-2026-90959High· 8.1A path traversal vulnerability was found in pulpcore
CVE-2026-95521High· 7.8A command injection flaw was found in rpm