1. Critical Confused Deputy Flaw in Kyverno Exposes Service Account Tokens to Attacker-Controlled Endpoints
A high-severity vulnerability in Kyverno, tracked as CVE-2026-40868, allows policy-controlled manipulation to redirect the Kubernetes controller service account token to attacker-controlled endpoints, enabling a classic confused deputy attack. The flaw exists in the apiCall servicecall helper, which implicitly injects ...