windows_machine_config_operator vulnerabilities
CVEs whose affected-version data names the windows_machine_config_operator package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-54100High· 8.3A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-network attacker …
▾ Twilightredhat · openshift_container_platformEPSS 0.30%via NVD
CVE-2026-54099High· 8.8A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not rej…
▾ Twilightredhat · openshift_container_platformEPSS 0.11%via NVD