The Dual CVSS 10.0 RCE Flaws Threatening Spinnaker Pipelines
ID: a2502dda-334a-534f-a626-7d1d7c1c4963
STIX ID: report--a2502dda-334a-534f-a626-7d1d7c1c4963
Feed Name: securityonline.info
Threat Score
A pair of critical RCE vulnerabilities (CVE-2026-32604 and CVE-2026-32613) have been disclosed in Spinnaker affecting Clouddriver and Echo; both are rated CVSS 10.0. Organizations should upgrade to the listed patched releases (2026.1.0, 2026.0.1, 2025.4.2, or 2025.3.2) immediately or apply recommended mitigations (disable gitrepo artifacts and/or disable Echo) to prevent arbitrary command execution and full JVM access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
