SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-53935

MEDIUM · CVSS 6.9 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

Cilium versions prior to 1.17.16, as well as 1.18.2 to 1.18.9 and 1.19.0 to 1.19.3, are vulnerable to a flaw that allows users to create CiliumLocalRedirectPolicies with arbitrary ClusterIPs, potentially hijacking traffic to Services across namespaces and undermining security controls. Additionally, deleting such policies may corrupt the internal service state, disrupting service translation. Organizations utilizing Cilium in their networking infrastructure should prioritize upgrading to the patched versions to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-53935
Severity
MEDIUM
CVSS
6.9
EPSS
0.21%

Original NVD Description

Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, enabling hijacking traffic to Services in any namespace and bypassing namespace scoping enforced by serviceMatcher; deleting such a policy can also corrupt Cilium internal service state and stop service translation for the affected Service. This issue is fixed in versions 1.17.16, 1.18.10, and 1.19.4.