Linuxsecurity Multiple Vulnerabilities in OpenStack Keystone Affecting Ubuntu Systems
Article Content
- •Three critical vulnerabilities identified in OpenStack Keystone.
- •Affected Ubuntu versions include 20.04, 22.04, 24.04, and 26.04 LTS.
- •Patches are available; users must update to protect against potential exploits.
OpenStack Keystone has been found to have several vulnerabilities that could allow authenticated attackers to exploit delegated authentication tokens and role assignment queries. The vulnerabilities include CVE-2026-80182, which allows attackers to create credentials that outlast the delegated token, and CVE-2026-80183, which enables unauthorized access to sensitive information. CVE-2026-80184 also allows attackers to escape their intended project scope. These issues affect Ubuntu versions 20.04 LTS, 22.04 LTS, 24.04 LTS, and 26.04 LTS. The vulnerabilities were disclosed on August 25 and 26, 2026, and patches have been released. Users are advised to update their systems to mitigate these risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Ubuntu and CVE-2026-80182 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of Ubuntu are affected?
What should I do to protect my system?
Are these vulnerabilities currently being exploited?
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…