CVE-2026-26963

medium Red Hat
CVSS v3 Base Score
6.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
EPSS Score
0.0%
Exploitation probability in 30 days
Top 99% most likely to be exploited
Attack Characteristics
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Confidentiality
Low
Integrity
Low
Availability
None
Published: February 19, 2026 (83 days ago)
Last Modified: February 19, 2026
Vendor: Red Hat

Description

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from Pods on other nodes when Native Routing, WireGuard and Node Encryption are enabled. This issue has been fixed in version 1.18.6.

CWE

CWE-266

Affected Products

Confidential Compute AttestationMulticluster Global HubNetwork Observability OperatorOpenShift Developer Tools and ServicesOpenShift Service Mesh 2Red Hat Advanced Cluster Management for Kubernetes 2Red Hat Enterprise Linux 10Red Hat Enterprise Linux 8Red Hat Enterprise Linux 9Red Hat OpenShift Container Platform 4

References