Vulnerabilitiesadvisory
CVE-2026-19444
The brief
Kubernetes has disclosed CVE-2026-19444, a medium-severity vulnerability in kubectl's Windows file-copy function. Copying data from a container an operator does not control can allow unauthorized writes on their computer within their existing permissions. The advisory lists fixes in releases 1.34.12, 1.35.9 and 1.36.5, and recommends avoiding copies from untrusted containers before upgrading. Only Windows clients are affected.
AI-assisted brief
Source KubernetesCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.
Read full article

