Skip to main content
EPSS 0.7%top 47%

Red Hat Security Advisory: RHACS 4.9.3 security and bug fix update

0
High
Published: 02/11/2026 (02/11/2026, 15:09:41 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

See the release notes (link in the references section) for a description of the fixes and enhancements in this particular release.

Affected software

Affected versions
>=4.9.0 <4.9.3Red HatRed Hat Advanced Cluster Security for KubernetesRed Hat Advanced Cluster Security for Kubernetes 4.9amd64registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:fdc9b12b9ee45dd85e277f21f5219c8900b7c0a684090937a9a4cf69a3d22061_amd64Red Hat Advanced Cluster SecurityRed Hat Advanced Cluster Security 4.9

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 21:38:25 UTC

Technical Analysis

The vulnerability CVE-2025-12816 exists in the node-forge library, which is used for cryptographic operations in Red Hat Advanced Cluster Security for Kubernetes. The flaw involves an interpretation conflict in ASN.1 structure parsing, allowing attackers to craft malicious ASN.1 data that desynchronizes schema validations. This results in bypassing downstream cryptographic verifications and security decisions, potentially compromising the integrity and confidentiality of affected systems. Red Hat has released RHACS version 4.9.3 containing fixes and security patches to address this vulnerability.

Potential Impact

An unauthenticated attacker can exploit this vulnerability to bypass cryptographic verification mechanisms, leading to potential compromise of data integrity and confidentiality in affected Red Hat Advanced Cluster Security deployments. The vulnerability does not impact availability. There are no known exploits in the wild at this time.

Mitigation Recommendations

A fix is available in Red Hat Advanced Cluster Security version 4.9.3. Users of earlier versions (>=4.9.0 <4.9.3) are advised to upgrade to version 4.9.3 to benefit from the security patches and bug fixes. No alternative mitigations meeting Red Hat's criteria are currently available.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:2568
Cve Count
9
Additional Cves
["CVE-2025-15284","CVE-2025-58183","CVE-2025-66031","CVE-2025-66506","CVE-2025-66564","CVE-2025-68428","CVE-2025-68973","CVE-2026-22029"]
State
PUBLISHED

Threat ID: 6a16096fe29bf47b50636fd8

Added to database: 05/26/2026, 20:58:23 UTC

Last enriched: 08/14/2026, 21:38:25 UTC

Last updated: 09/10/2026, 22:05:24 UTC

Views: 118

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses