<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Gke on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/gke/</link><description>Recent content in Gke on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Wed, 18 Jun 2025 00:00:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/gke/index.xml" rel="self" type="application/rss+xml"/><item><title>GKE containerd Flaws CVE-2026-50195 &amp; More</title><link>https://zxcloudsecurity.co.uk/posts/gke-containerd-vulnerabilities-cve-2026-50195-cve-2026-53488-host-compromise/</link><pubDate>Thu, 18 Jun 2026 00:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/gke-containerd-vulnerabilities-cve-2026-50195-cve-2026-53488-host-compromise/</guid><description>Multiple containerd vulnerabilities in GKE allow Pod-privileged attackers to compromise hosts, poison caches, and cause DoS. Patch GKE nodes now.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-037">GCP GKE Security Bulletins</a></p>
<hr>
<p>Multiple high-severity vulnerabilities have been discovered in containerd, the container runtime used by Google Kubernetes Engine (GKE). Attackers with permissions to create Pods can exploit these flaws to bypass Kubernetes security boundaries, potentially compromising the underlying host, poisoning image caches, or causing denial of service. Although some CVEs are rated Critical in containerd upstream, GKE classifies them as High due to the prerequisite of cluster-level Pod creation privileges.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Prioritise upgrading affected GKE node pools to patched containerd versions immediately, and in the interim review RBAC policies to restrict Pod creation permissions to only trusted identities — limiting who can create Pods is the most effective compensating control given that privilege is the primary exploitation prerequisite.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-037">GCP-2026-037</a></p>
]]></content:encoded></item></channel></rss>