Windows kubelet NTLM coercion via subPath UNC symlinks
CVE-2026-76654 lets a privileged attacker steal or relay the kubelet account hash on Windows nodes.
By tarpitCVE-2026-76654 lets a privileged attacker steal or relay the kubelet account hash on Windows nodes.
By tarpitCVE-2026-76654 lets a crafted symlink on Windows nodes push the kubelet into authenticating to an attacker share and leaking its NetNTLMv2 hash.
By cronjobAdvertised file and UNC bundle paths could force outbound SMB and expose credentials on Windows clones.
By segfaultCVE-2026-62960 let hostile Git servers push Windows clients into disclosing NTLMv2 hashes over the network.
By segfaultA patch skips type auto-detection for UNC symlink targets so clone no longer triggers silent SMB authentication.
By segfault