Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:maven/org.apache.cloudstack/cloudstack

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-59654 is a resource management vulnerability in Apache CloudStack affecting scoped global configuration functionality across various modules and plugins. It impacts versions from 4.7.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0. The flaw may cause a denial of service (DoS) condition on the management server due to missing release of resources after their effective lifetime. Fixed versions are 4.20.3.1 and 4.22.1.1 or later.

Join the discussion

An improper access control vulnerability exists in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing unauthorized cross-tenant manipulation of Kubernetes clusters during node addition and removal. This affects Apache CloudStack versions from 4.21.0.0 through 4.22.1.0. The issue is resolved in version 4.22.1.1 and later.

Join the discussion

Apache heeft meerdere kwetsbaarheden verholpen in Apache CloudStack, specifiek in versies 4.12.0.0 tot en met 4.22.1.0.

Join the discussion

CVE-2026-47359 is an OS command injection vulnerability in Apache CloudStack's NAS backup provider plugin. It affects the addBackupRepository and updateBackupRepository APIs, which accept unsanitized command options. A malicious operator account can exploit this to execute arbitrary commands on the KVM hypervisor host during backup restore operations. The vulnerability affects Apache CloudStack versions from 4.20.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0. Upgrading to versions 4.20.3.1 or 4.22.1.1 or later mitigates the issue.

Join the discussion

CVE-2026-50112 is a high-severity OS command injection vulnerability in Apache CloudStack affecting versions from 4.14.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0. An authenticated tenant can exploit this by registering a VM template with a malicious metalink file, leading to remote code execution as root on the KVM hypervisor host. The issue arises because inner URLs in metalink XML files are not properly validated against allowed schemes. Fixed versions are 4.20.3.1 and 4.22.1.1 or later.

Join the discussion

CVE-2026-50222 is a high-severity vulnerability in Apache CloudStack affecting userdata-related APIs. Several APIs lack proper authorization checks, allowing unauthorized access to userdata resources across tenants. Affected versions include 4.18.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0. The issue also affects the deleteCniConfiguration API introduced in 4.21.0.0. Fixed versions are 4.20.3.1 and 4.22.1.1 or later.

Join the discussion

Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.

Join the discussion

CVE-2026-59085 is a critical Server-Side Request Forgery (SSRF) vulnerability in the webhook module of Apache CloudStack. It affects versions from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. The vulnerability allows unauthenticated attackers to send crafted webhook delivery requests that could lead to unauthorized information disclosure and impact confidentiality and integrity. The issue is fixed in versions 4.20.3.1 and 4.22.1.1 or later.

Join the discussion

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth authentication plugin while listing OAuth providers. This issue affects Apache CloudStack: from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.

Join the discussion

CVE-2026-59655 is a vulnerability in Apache CloudStack's OAuth authentication plugin that allows exposure of sensitive information to unauthorized actors when listing OAuth providers. This affects versions from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. The issue is fixed in versions 4.20.3.1 and 4.22.1.1 or later.

Join the discussion

Showing 1 to 10 of 48 results

Filters:Package: pkg:maven/org.apache.cloudstack/cloudstack
Page 1 of 5
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses