Cloud Foundry Logo

Cloud Foundry Blog: Cloud Foundry Foundation Security Team

CVE-2026-41011 – Package Name Command Injection
Security Advisory

CVE-2026-41011 – Package Name Command Injection

CVE-2026-41010 – Release Job Name Command Injection on BOSH Director
Security Advisory

CVE-2026-41010 – Release Job Name Command Injection on BOSH Director

CVE-2026-41860 – Missing tls-verify on bosh-monitor
Security Advisory

CVE-2026-41860 – Missing tls-verify on bosh-monitor

CVE-2026-41859 – Missing TLS in NATS sync
Security Advisory

CVE-2026-41859 – Missing TLS in NATS sync

CVE-2026-41858 – Brute forceable windows admin creds
Security Advisory

CVE-2026-41858 – Brute forceable windows admin creds

CVE-2026-41704 – Compromised VM can make arbitrary blobstore deletes
Security Advisory

CVE-2026-41704 – Compromised VM can make arbitrary blobstore deletes

CVE-2026-41009 – Local Blobstore may allow arbitrary reads/deletes
Security Advisory

CVE-2026-41009 – Local Blobstore may allow arbitrary reads/deletes

CVE-2026-22726 – Route Services Firewall Bypass
Security Advisory

CVE-2026-22726 – Route Services Firewall Bypass

CVE-2026-22734 – UAA SAML 2.0 Signature Bypass
Security Advisory

CVE-2026-22734 – UAA SAML 2.0 Signature Bypass

CVE-2026-22727 – Unprotected internal endpoints
Security Advisory

CVE-2026-22727 – Unprotected internal endpoints