Red Hat released Important security updates for Red Hat OpenStack Platform 17.1 and 16.2 that address multiple flaws, including CVE-2026-33413, an etcd authorization bypass that can expose cluster information and enable denial-of-service conditions. The etcd issue affects versions before 3.4.42, 3.5.28, and 3.6.9, and can let unauthorized users access certain gRPC API functions such as MemberList, Alarm, and Lease, as well as trigger compaction operations that interfere with leases or delete historical revisions. Red Hat shipped the etcd fix in RHSA-2026:28047 for OpenStack Platform 17.1 on RHEL 9 x86_64 and included related remediation in RHSA-2026:54757 for OpenStack Platform 16.2 and associated products.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-08-13, Red Hat published RHSA-2026:54757, an Important security advisory for Red Hat OpenStack Platform 16.2 (Train). The update fixes multiple vulnerabilities across Nova, Glance, Keystone, oslo.messaging, etcd, Go libraries, pyasn1, gRPC-Go, and Erlang OTP for x86_64 and IBM Power-related products.
On 2026-06-22, Red Hat Bugzilla documented that etcd versions prior to 3.4.42, 3.5.28, and 3.6.9 allow authorization bypass on certain gRPC API functions, enabling information disclosure and denial of service. The entry notes the issue was fixed upstream in those etcd versions and remediated by Red Hat in OpenStack Platform 17.1 and 16.2.
On 2026-06-22, Red Hat published RHSA-2026:28047, an Important security advisory for etcd in Red Hat OpenStack Platform 17.1 (Wallaby). The update provides patched etcd packages for RHEL 9 x86_64 and addresses CVE-2026-33413 along with multiple Go- and gRPC-related vulnerabilities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.