News · via oss-security
[kubernetes] CVE-2026-76654: Subpath symlinking on Windows nodes permits NTLM coercion
Posted by Nathan Herz on Sep 23 Hello Kubernetes Community, An NTLM coercion vulnerability exists on Windows nodes when the subPath supplied in a pod's volumeMounts is set to a symbolic link that…
