Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Fleet versions before 4.89.0 fail to properly filter MDM command results by team authorization in the commands/results endpoint. Team-scoped users can read MDM command results for hosts on other teams when a shared command UUID targets hosts across multiple teams, exposing host UUIDs, command payloads, and device responses. Join the discussion | CVE Database V5 | 10/01/2026, 10:42:06 UTC Added: 10/01/2026, 14:56:20 UTC |
0 Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to device UUIDs. Unauthenticated attackers who know or guess these non-secret identifiers can authenticate as iOS/iPadOS hosts to read device data and trigger device-scoped actions including software installation and MDM migration. Join the discussion | CVE Database V5 | 10/01/2026, 10:42:06 UTC Added: 10/01/2026, 14:56:06 UTC |
CVE-2026-88808 is a high-severity vulnerability in SUSE Rancher Fleet where the Fleet agent improperly uses cluster-admin credentials instead of the intended ServiceAccount credentials when writing resources to downstream clusters. This affects multi-tenant environments sharing downstream clusters, potentially allowing unauthorized overwriting of configuration files. The issue impacts SUSE Rancher Fleet versions 0.14 before 0.14.11, 0.15 before 0.15.7, and 0.16 before 0.16.2. Join the discussion | CVE Database V5 | 09/28/2026, 15:36:13 UTC Added: 09/28/2026, 18:03:15 UTC |
A privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the namespaceLabels and namespaceAnnotations options, the resulting namespace metadata update was not subject to the same authorization as the rest of the bundle's deployment. As a result, a bundle could change labels and annotations on a target namespace even when the identity it was pinned to was not authorized to modify that namespace. This affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16 and potentially older versions. Join the discussion | CVE Database V5 | 09/28/2026, 14:45:42 UTC Added: 09/28/2026, 15:03:29 UTC |
A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhook requests are accepted without verification, and processing a request can change the spec.pollingInterval field of a matching GitRepo resource in any namespace. A caller with network access to the webhook service and no Kubernetes credentials can therefore alter GitRepo configuration outside the namespaces they are authorized for. This only affects SUSE Rancher Fleet 0.16 before 0.16.2, older versions are not affected. Join the discussion | CVE Database V5 | 09/28/2026, 14:19:55 UTC Added: 09/28/2026, 14:33:15 UTC |
A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such as the cluster display name label, were applied to the resulting upstream Cluster object. Because Fleet resolves GitRepo and Bundle targets from those cluster labels, a party able to register a cluster into a Fleet workspace namespace shared with other tenants could cause its own cluster to satisfy targeting rules that administrators intended for a different cluster. This affects SUSE Rancher Fleet 0.16 before 0.16.1, 0.15 before 0.15.6, 0.14 before 0.14.10, 0.13 before 0.13.15, 0.12 before 0.12.19 and older versions. Join the discussion | CVE Database V5 | 09/28/2026, 14:10:21 UTC Added: 09/28/2026, 14:33:15 UTC |
A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or modify a GitRepo, can cause SUSE Rancher Fleet to read files from the filesystem of the environment that processes the bundle and include their contents in the generated Bundle resource. This can expose configuration or credential material that the user has no Kubernetes RBAC permission to read, including Helm registry credentials made available to the bundle-processing job when per-path Helm credentials are configured. This affects Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16, 0.12 before 0.12.20 and potentially older unsupported versions. Join the discussion | CVE Database V5 | 09/28/2026, 13:29:10 UTC Added: 09/28/2026, 13:48:22 UTC |
0 Fleet versions before 4.87.0 have a vulnerability where two endpoints serving in-house iOS application packages and manifests are not protected by the intended random, time-limited URL token. This allows unauthenticated attackers with network access to the Fleet server to download in-house IPA binaries and metadata by guessing sequential title identifiers. The issue affects only the enterprise tier and does not impact the free tier. The vulnerability results in read-only information disclosure without privilege escalation or write access. Join the discussion | CVE Database V5 | 09/27/2026, 17:02:35 UTC Added: 09/28/2026, 01:57:40 UTC |
0 Fleet before 4.89.0 contains an SQL injection vulnerability in the activity list endpoints (GET /api/v1/fleet/activities and GET /api/v1/fleet/hosts/{id}/activities). The deprecated cursor-pagination helper appendListOptionsWithCursorToSQL interpolated the caller-supplied sort/order key into the SQL ORDER BY clause without an allowlist, so an authenticated user with read access to Activity could order results by arbitrary columns. The impact is read-only and bounded to columns on the activity_past table that are not otherwise returned in these responses (e.g. details), allowing their values to be inferred through the resulting sort order; there is no write access, privilege escalation, or reachability of node_key or other host-join columns through these endpoints. Fixed in 4.89.0, which removes the deprecated helper and passes the sort column through SanitizeColumn. Join the discussion | CVE Database V5 | 09/27/2026, 17:02:35 UTC Added: 09/28/2026, 01:57:40 UTC |
0 CVE-2026-101045 is an OS command injection vulnerability in fleetdm's fleet product affecting macOS app install and uninstall scripts generated from Homebrew cask metadata before 2026-08-19. The vulnerability arises because some shell metacharacters in the metadata were not properly escaped, allowing crafted metadata to execute arbitrary commands as root on managed macOS hosts. Exploitation requires the malicious metadata to pass both upstream Homebrew cask review and Fleet's automated ingestion review. The issue was fixed in Fleet v4.92.0 with a patch applied centrally on 2026-08-19, which escapes all interpolation sites in the generated manifests. This fix was distributed to all deployments with no customer action required. Join the discussion | CVE Database V5 | 09/27/2026, 17:02:34 UTC Added: 09/28/2026, 01:57:40 UTC |
Showing 1 to 10 of 39 results