Skip to main content
EPSS 0.7%top 47%

Red Hat Security Advisory: RHACS 4.9.3 security and bug fix update

0
High
Published: 02/09/2026 (02/09/2026, 15:50:42 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

See the release notes (link in the references section) for a description of the fixes and enhancements in this particular release.

Affected software

Affected versions
>=4.9.0 <4.9.3Red HatRed Hat Advanced Cluster Security for KubernetesRed Hat Advanced Cluster Security for Kubernetes 4.9amd64registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:4efd0780d62b6dddbd5eef4ae8c1620b8e72dfa1551d89e8c9b281ed50afc2f9_amd64Red Hat Advanced Cluster SecurityRed Hat Advanced Cluster Security 4.9

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 21:40:16 UTC

Technical Analysis

This vulnerability (CVE-2025-12816) affects the node-forge cryptographic library used in Red Hat Advanced Cluster Security for Kubernetes. It arises from an interpretation conflict in ASN.1 structure validation, allowing attackers to craft malicious ASN.1 data that bypasses downstream cryptographic verification and security decisions. The flaw results in semantic divergence due to desynchronized schema validations. Red Hat has addressed this issue in RHACS version 4.9.3, which includes security patches and bug fixes. The vulnerability is rated with a CVSS v3 base score of 8.7 by Red Hat, indicating high severity. No known exploits in the wild have been reported. Mitigation involves upgrading to the fixed version.

Potential Impact

An unauthenticated attacker can exploit this vulnerability to bypass cryptographic verification mechanisms in affected Red Hat products that use node-forge, potentially compromising integrity and confidentiality of security decisions. This could lead to unauthorized actions or acceptance of malicious data. The vulnerability does not impact availability. Red Hat rates this vulnerability as important/high severity with a CVSS score of 8.7, reflecting significant risk to affected systems if exploited.

Mitigation Recommendations

Red Hat has released version 4.9.3 of Red Hat Advanced Cluster Security for Kubernetes which includes fixes for this vulnerability. Users of earlier versions (>=4.9.0 <4.9.3) are strongly advised to upgrade to version 4.9.3 to apply the security patches and bug fixes. No alternative mitigations meeting Red Hat's criteria are currently available. Applying the official update is the recommended remediation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:2350
Cve Count
9
Additional Cves
["CVE-2025-15284","CVE-2025-58183","CVE-2025-66031","CVE-2025-66506","CVE-2025-66564","CVE-2025-68428","CVE-2025-68973","CVE-2026-22029"]

Threat ID: 6a16096fe29bf47b50636ff3

Added to database: 05/26/2026, 20:58:23 UTC

Last enriched: 08/14/2026, 21:40:16 UTC

Last updated: 09/10/2026, 19:36:49 UTC

Views: 129

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses