tlder@devCVEs/Advisories
tlder@dev:~$

CVE-2026-32604: Critical Spinnaker vulnerability (CVSS 9.9)

Apr 14·Security·CVEs/Advisories·shipped·from digest 2026-04-21

CVE-2026-32604 is a Critical-severity vulnerability in Spinnaker, the open-source multi-cloud continuous delivery platform widely used at large-scale tech shops. CVSS 9.9 places it at near-maximum severity; TheHackerWire's writeup describes the exposure as allowing deep pipeline compromise once exploited. Spinnaker sits inside CI/CD infrastructure, so compromise here maps directly to release-pipeline takeover. Organizations running Spinnaker should check the advisory for patched versions and apply updates across all regions immediately. Where patches are not yet applied, restrict access to the Spinnaker API and UI to known operator IPs and rotate credentials the platform uses against cloud providers.