Database/Control plane, storage & DevOps
Assisted Migration Agent (hardcoded insecure TLS to vCenter): The agent hardcodes insecure TLS when talking to vCenter
CVSS 9.3CVE-2026-53475Control plane, storage & DevOpscurated
Impact
The agent hardcodes insecure TLS when talking to vCenter, so a machine-in-the-middle harvests vCenter administrator credentials in transit - unauthorized admin access to the virtualization estate.
Who can reach it
Network position between the migration agent and vCenter.
What to do
Update the assisted-migration-agent to a build including the upstream fix, and rotate the vCenter admin credentials the agent used. Retire the agent when the migration completes rather than leaving it deployed.
References
Related entries
- Linux liquidio driver (Marvell/Cavium, cached VF pci_dev lookup table): The LiquidIO PF caches VF `pci_dev` pointersCVE-2026-72329 · Linux liquidio driver (Marvell/Cavium, cached VF pci_dev lookup table)Critical
- Dell Secure Connect Gateway: exposed Docker socket gives a local user or container host rootCVE-2026-80238 · Dell Secure Connect Gateway 5.0 (orchestrator container / exposed Docker socket)Critical
- MinIO (OIDC authentication): JWT algorithm confusion in the OIDC login path lets an attacker present a token the serverCVE-2026-33322 · MinIO (OIDC authentication)Critical
- rclone (rc API, options/set): options/set is exposed pre-authentication and can rewrite the running instance's authCVE-2026-41176 · rclone (rc API, options/set)Critical
- rclone (rc API, operations/fsinfo): operations/fsinfo is reachable without authentication and accepts anCVE-2026-41179 · rclone (rc API, operations/fsinfo)Critical
- Renovate: unvalidated GitLab Link header redirects credential-bearing pagination requestsCVE-2026-88880 · Renovate (GitLab pagination, HTTP Link header host validation)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.