<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Azure Kubernetes Service</title>
  <link>https://cvedaily.com/pages/tags/azure-kubernetes-service.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/azure-kubernetes-service.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Azure Kubernetes Service</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:57 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-33105 – Improper authorization in Microsoft Azure Kubernetes Service allows an unauthori...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33105</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33105</guid>
    <pubDate>Fri, 03 Apr 2026 00:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33105</strong></p>
  <p>Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33105">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33726 – Cilium is a networking, observability, and security solution with an eBPF-based ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33726</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33726</guid>
    <pubDate>Fri, 27 Mar 2026 01:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33726</strong></p>
  <p>Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.14, 1.18.8, and 1.19.2, Ingress Network Policies are not enforced for traffic from pods to L7 Services (Envoy, GAMMA) with a local backend on the same node, when Per-Endpoint Routing is enabled and BPF Host Routing is disabled. Per-Endpoint Routing is disabled by default, but is autom…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33726">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-29990 – Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-29990</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-29990</guid>
    <pubDate>Tue, 09 Apr 2024 17:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-29990</strong></p>
  <p>Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-29990">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-21400 – Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21400</guid>
    <pubDate>Tue, 12 Mar 2024 17:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-21400</strong></p>
  <p>Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-21403 – Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21403</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21403</guid>
    <pubDate>Tue, 13 Feb 2024 18:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-21403</strong></p>
  <p>Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-552</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21403">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-21376 – Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21376</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21376</guid>
    <pubDate>Tue, 13 Feb 2024 18:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-21376</strong></p>
  <p>Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21376">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-29332 – Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29332</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29332</guid>
    <pubDate>Tue, 12 Sep 2023 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-29332</strong></p>
  <p>Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29332">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-23551 – aad-pod-identity assigns Azure Active Directory identities to Kubernetes applica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23551</guid>
    <pubDate>Wed, 21 Dec 2022 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-23551</strong></p>
  <p>aad-pod-identity assigns Azure Active Directory identities to Kubernetes applications and has now been deprecated as of 24 October 2022. The NMI component in AAD Pod Identity intercepts and validates token requests based on regex. In this case, a token request made with backslash in the request (example: `/metadata/identity\oauth2\token/`) would bypass the NMI validation and be sent to IMDS allow…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-24109 – Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-24109</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-24109</guid>
    <pubDate>Thu, 25 Feb 2021 23:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-24109</strong></p>
  <p>Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-24109">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-6287 – The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks H...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-6287</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-6287</guid>
    <pubDate>Tue, 07 Oct 2014 10:55:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-6287</strong></p>
  <p>The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-6287">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
