CVE-2026-26963
published 2026-02-20CVE-2026-26963: Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from…
PriorityP423medium5.4CVSS 3.1
AVAACLPRNUINSUCLILAN
EPSS
0.13%
3.2th percentile
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from Pods on other nodes when Native Routing, WireGuard and Node Encryption are enabled. This issue has been fixed in version 1.18.6.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cilium | cilium | — | — |
| cilium | cilium | >= 1.18.0 < 1.18.6 | 1.18.6 |
| github.com | cilium_cilium | >= 1.18.0 < 1.18.6 | 1.18.6 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv5.4MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Cilium may not enforce host firewall policies when Native Routing, WireGuard and Node Encryption are enabled in github.com/cilium/cilium
osv·2026-02-23
CVE-2026-26963 Cilium may not enforce host firewall policies when Native Routing, WireGuard and Node Encryption are enabled in github.com/cilium/cilium
Cilium may not enforce host firewall policies when Native Routing, WireGuard and Node Encryption are enabled in github.com/cilium/cilium
Cilium may not enforce host firewall policies when Native Routing, WireGuard and Node Encryption are enabled in github.com/cilium/cilium
OSV
CVE-2026-26963: Cilium is a networking, observability, and security solution with an eBPF-based dataplane
osv·2026-02-20·CVSS 5.4
CVE-2026-26963 [MEDIUM] CVE-2026-26963: Cilium is a networking, observability, and security solution with an eBPF-based dataplane
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from Pods on other nodes when Native Routing, WireGuard and Node Encryption are enabled. This issue has been fixed in version 1.18.6.
GHSA
Cilium may not enforce host firewall policies when Native Routing, WireGuard and Node Encryption are enabled
ghsa·2026-02-19
CVE-2026-26963 [MEDIUM] CWE-863 Cilium may not enforce host firewall policies when Native Routing, WireGuard and Node Encryption are enabled
Cilium may not enforce host firewall policies when Native Routing, WireGuard and Node Encryption are enabled
### Impact
[Host Policies](https://docs.cilium.io/en/stable/security/policy/language/#host-policies) will incorrectly permit traffic from Pods on other nodes when all of the following configurations are enabled:
* [Native Routing](https://docs.cilium.io/en/stable/network/concepts/routing/#native-routing)
* [WireGuard](https://docs.cilium.io/en/stable/security/policy/language/#host-policies)
* [Node Encryption](https://docs.cilium.io/en/stable/security/network/encryption-wireguard/#node-to-node-encryption-beta) (beta)
These options are disabled by default in Cilium.
### Patches
This issue was fixed by #42892.
This issue affects:
* Cilium v1.18 between v1.18.0 and v1.18.5 inclu
OSV
Cilium may not enforce host firewall policies when Native Routing, WireGuard and Node Encryption are enabled
osv·2026-02-19
CVE-2026-26963 [MEDIUM] Cilium may not enforce host firewall policies when Native Routing, WireGuard and Node Encryption are enabled
Cilium may not enforce host firewall policies when Native Routing, WireGuard and Node Encryption are enabled
### Impact
[Host Policies](https://docs.cilium.io/en/stable/security/policy/language/#host-policies) will incorrectly permit traffic from Pods on other nodes when all of the following configurations are enabled:
* [Native Routing](https://docs.cilium.io/en/stable/network/concepts/routing/#native-routing)
* [WireGuard](https://docs.cilium.io/en/stable/security/policy/language/#host-policies)
* [Node Encryption](https://docs.cilium.io/en/stable/security/network/encryption-wireguard/#node-to-node-encryption-beta) (beta)
These options are disabled by default in Cilium.
### Patches
This issue was fixed by #42892.
This issue affects:
* Cilium v1.18 between v1.18.0 and v1.18.5 inclu
Red Hat
cilium: Cilium: Information disclosure via incorrect traffic permitting with specific network configurations
vendor_redhat·2026-02-19·CVSS 6.1
CVE-2026-26963 [MEDIUM] CWE-266 cilium: Cilium: Information disclosure via incorrect traffic permitting with specific network configurations
cilium: Cilium: Information disclosure via incorrect traffic permitting with specific network configurations
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from Pods on other nodes when Native Routing, WireGuard and Node Encryption are enabled. This issue has been fixed in version 1.18.6.
A flaw was found in Cilium. When specific network configurations, including Native Routing, WireGuard, and Node Encryption, are enabled, Cilium incorrectly allows network traffic from Pods on other nodes. This can lead to unauthorized access to network communications and potential information disclosure.
Package: openshift-sandboxed-containers/osc-monitor-rhel9 (Confidential Compute Attestation) -
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-33726 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.4
CVE-2026-33726 [LOW] CVE-2026-33726 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33726 :
Cilium vulnerability analysis and mitigation
eni.enabled
alibabacloud.enabled
azure.enabled
gke.enabled
Source : NVD
## 4.3
Score
Published March 27, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Cilium
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kubescape-operator
kubescape-operator-fips
Sources
Chainguard Has Fix Added at: Mar 29, 2026
GoLang Severity MEDIUM Has Fix Added at: Mar 29, 2026
MinimOS Severity MEDIUM Has Fix Added at: Mar 29, 2026
Linux Severity MEDIUM Has Fix Added at: Mar 29, 2026
Wolfi Has Fix Added at: Mar 29, 2026
Linux Severity MEDIUM Has F
Wiz
CVE-2026-26963 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.4
CVE-2026-26963 [LOW] CVE-2026-26963 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-26963 :
Cilium vulnerability analysis and mitigation
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from Pods on other nodes when Native Routing, WireGuard and Node Encryption are enabled. This issue has been fixed in version 1.18.6.
Source : NVD
## 5.4
Score
Published February 20, 2026
Severity MEDIUM
CNA Score 6.1
Affected Technologies
Cilium
MinimOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
github.com/cilium/cilium
cilium-1.18
Sources
GoLang Severity MEDIUM Has Fix Added at: Feb 20,
Bugzilla
CVE-2026-26963 cilium: Cilium: Information disclosure via incorrect traffic permitting with specific network configurations
bugzilla·2026-02-20·CVSS 5.4
CVE-2026-26963 [MEDIUM] CVE-2026-26963 cilium: Cilium: Information disclosure via incorrect traffic permitting with specific network configurations
CVE-2026-26963 cilium: Cilium: Information disclosure via incorrect traffic permitting with specific network configurations
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from Pods on other nodes when Native Routing, WireGuard and Node Encryption are enabled. This issue has been fixed in version 1.18.6.
2026-02-20
Published