CVE-2026-4404 – Harbor Critical Vulnerability

CVSS 9.4 CRITICAL

“A trusted registry can become the attacker’s entry point.”

This patch addresses CVE-2026-4404 in Harbor, a critical vulnerability that could allow attackers to compromise container registry environments. Successful exploitation may lead to unauthorized access, manipulation of stored images, or disruption of software supply chains. The CVSS score is 9.4, which is Critical severity.

There is no verified evidence of active exploitation or publicly available proof-of-concept code at this time. However, due to Harbor’s central role in managing and distributing container images, this vulnerability poses a serious risk to application integrity and deployment pipelines.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-798
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.