CVE-2026-53475Critical· 9.3▾ MidnightAssisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 51.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connections when communicating with vCenter. This vulnerability allows a Man-in-the-Middle (MITM) attacker to intercept and harvest vCenter administrator credentials. This can lead to unauthorized access to vCenter.
github.com/kubev2v/assisted-migration-agent < 0.16.0Upgrade to a patched release:
github.com/kubev2v/assisted-migration-agent 0.16.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53476Critical· 9.6Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution
CVE-2026-53474Critical· 9.6Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands
CVE-2026-53470Critical· 9.6Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs
CVE-2026-53469Critical· 9.1Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API
CVE-2026-53471Critical· 9.6Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation