White Rabbitx[verified]@TheRabbitPyDisclosure
The post announces a high‑severity (CVSS 9.9) vulnerability in Kyverno K8s policy engine versions below 1.12.3 that permits cluster‑role binding escape to full cluster control, and urges K8s administrators to patch immediately.
Israel[verified]@f1tym1Patch
The post announces CVE‑2026‑22039, a Kyverno RBAC isolation flaw, and notes that a patch has been released but is incomplete, indicating ongoing mitigation efforts.
Zero Day Wire[verified]@zerodaywireDisclosure
The post announces a critical Kyverno vulnerability (CVE‑2026‑22039) that can enable cluster admin takeover via policy abuse, but it provides no proof of concept, exploit code, active exploitation evidence, or remediation details.
Ville Vesilehto@thevilledevPatch
The user reported and fixed a critical Kyverno vulnerability (CVE-2026-22039) and linked to a write‑up that details the issue.
PulsePatch.io@pulsepatchioPatch
A cross‑namespace privilege escalation vulnerability (CVE‑2026‑22039) in Kyverno has been discovered and users are advised to apply updates to mitigate the risk.
CVE@CVEnewGeneral
The post briefly mentions CVE-2026-41068, referencing a patch for a related CVE and noting a privilege escalation flaw, but provides no exploitation or mitigation specifics.
DailyCVE@dailycveDisclosure
The text announces a critical Kyverno vulnerability (SSRF and privilege escalation) identified as CVE‑2026‑22039 and provides a link to a detailed report.
🐾 FAUN.dev()@joinFAUNDisclosure
The post announces a newly discovered critical authorization bypass in Kyverno that permits namespace hopping via hijacked ServiceAccounts, yet it offers no PoC, exploit, or patch information.