logo

Patch Now: Apache CloudStack Plugs Proxmox and KVM Exploits in New LTS Release

ID: ff1b3989-58b2-5229-8cec-d3a3cd55c3bf

STIX ID: report--ff1b3989-58b2-5229-8cec-d3a3cd55c3bf

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-11

Date Updated: 2026-05-22

Author: Ddos

...
...

Apache CloudStack published urgent LTS patches (4.20.3.0 and 4.22.0.1) addressing seven vulnerabilities — notably a Proxmox cross-tenant VM hijack, KVM host RCE, and multiple Backup plugin authorization flaws — that allow unauthorized VM control, hypervisor compromise, and restoration/creation of VMs from other accounts; administrators should upgrade or apply provided workarounds immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.