Red Hat Security Advisory: Multicluster Global Hub 1.3.4 security update
Red Hat multicluster global hub is a set of components that enable you to import one or more hub clusters and manage them from a single hub cluster.
AI Analysis
Technical Summary
Red Hat Multicluster Global Hub 1.3.4 is a set of components for managing multiple hub clusters centrally. A security advisory (RHSA-2026:22423) addresses multiple vulnerabilities including CVE-2026-21728 and 19 others. The CVSS vector for CVE-2026-21728 indicates network attack vector, low attack complexity, no privileges or user interaction required, unchanged scope, no confidentiality or integrity impact, but high impact on availability. The advisory provides updated container images and security fixes in the v1.3.4 release. No known exploits are reported. The update is rated as important by Red Hat Product Security. The vendor advisory directs users to upgrade to the fixed version 1.3.4 for remediation.
Potential Impact
The vulnerabilities addressed primarily impact availability of the Red Hat Multicluster Global Hub component, potentially causing denial of service or disruption of cluster management functions. There is no reported impact on confidentiality or integrity. The high severity rating is based on the potential to disrupt availability without requiring privileges or user interaction. No known active exploitation has been reported.
Mitigation Recommendations
Red Hat has released version 1.3.4 of Multicluster Global Hub which includes security fixes for these vulnerabilities. Users should upgrade to Multicluster Global Hub 1.3.4 to remediate the issues. The vendor advisory (RHSA-2026:22423) is the authoritative source for patch availability and upgrade instructions. No additional mitigation steps are indicated beyond applying the update.
Red Hat Security Advisory: Multicluster Global Hub 1.3.4 security update
Description
Red Hat multicluster global hub is a set of components that enable you to import one or more hub clusters and manage them from a single hub cluster.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Red Hat Multicluster Global Hub 1.3.4 is a set of components for managing multiple hub clusters centrally. A security advisory (RHSA-2026:22423) addresses multiple vulnerabilities including CVE-2026-21728 and 19 others. The CVSS vector for CVE-2026-21728 indicates network attack vector, low attack complexity, no privileges or user interaction required, unchanged scope, no confidentiality or integrity impact, but high impact on availability. The advisory provides updated container images and security fixes in the v1.3.4 release. No known exploits are reported. The update is rated as important by Red Hat Product Security. The vendor advisory directs users to upgrade to the fixed version 1.3.4 for remediation.
Potential Impact
The vulnerabilities addressed primarily impact availability of the Red Hat Multicluster Global Hub component, potentially causing denial of service or disruption of cluster management functions. There is no reported impact on confidentiality or integrity. The high severity rating is based on the potential to disrupt availability without requiring privileges or user interaction. No known active exploitation has been reported.
Mitigation Recommendations
Red Hat has released version 1.3.4 of Multicluster Global Hub which includes security fixes for these vulnerabilities. Users should upgrade to Multicluster Global Hub 1.3.4 to remediate the issues. The vendor advisory (RHSA-2026:22423) is the authoritative source for patch availability and upgrade instructions. No additional mitigation steps are indicated beyond applying the update.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:22423
- Cve Count
- 20
- Additional Cves
- ["CVE-2026-25679","CVE-2026-27137","CVE-2026-32282","CVE-2026-32283","CVE-2026-32285","CVE-2026-32286","CVE-2026-33186","CVE-2026-33487","CVE-2026-33815","CVE-2026-33816","CVE-2026-34986","CVE-2026-41602","CVE-2026-41603","CVE-2026-41604","CVE-2026-41605","CVE-2026-41606","CVE-2026-41607","CVE-2026-41636","CVE-2026-43869"]
- Cvss Version
- null
Threat ID: 6a1f4e80e29bf47b5007c118
Added to database: 06/02/2026, 21:43:28 UTC
Last enriched: 07/26/2026, 01:48:37 UTC
Last updated: 07/31/2026, 21:28:43 UTC
Views: 76
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.