The image cache bug is the one to remember, because it turns a routine permission into a write primitive against shared node state.
- containerd patched five Container Runtime Interface vulnerabilities on June 18. Three were rated critical.
- CVE-2026-50195 lets a crafted checkpoint image write an arbitrary local tag, so later pods on that node using an IfNotPresent or Never pull policy run the attacker’s image.
- CVE-2026-53488 flows Dockerfile labels into a container without validation and can reach command execution on the host.
- Fixed builds are 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2. September added CVE-2026-53495, fixed in 1.7.35, 2.0.12, 2.2.8 and 2.3.5.
- AWS covers Amazon EKS, Amazon ECS, AWS Fargate, Bottlerocket and Amazon Linux through managed patching. Self-managed nodes are on you.
- Restrict pod creation and image import rights, disable checkpoint restore where unused, and pin digests instead of tags.
Read the full analysis at why Kubernetes isolation keeps breaking at the runtime layer.
Get the next one before it is old news
Independent analysis of cloud-native infrastructure, Kubernetes and data centre economics. No vendor spin.
