Critical XSS and Code Execution Vulnerabilities in Fedora Prometheus Update
ID: 0e28883f-f609-531c-b384-c7193ef9d49c
STIX ID: report--0e28883f-f609-531c-b384-c7193ef9d49c
Feed Name: ThreatCluster
Threat Score
Fedora released a critical Prometheus update on July 2, 2026, addressing multiple vulnerabilities (CVE-2026-40186, CVE-2026-44990, CVE-2026-41567, CVE-2026-53606, CVE-2026-25681) that include cross-site scripting and potential arbitrary code execution via malicious container images; users are strongly urged to apply the patched packages using dnf to mitigate significant security risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
