CMS Hybrid Cloud Launches the Q3 2026 CMS Enterprise Security Campaign
CMS Hybrid Cloud Logo

Summary

Starting August 26th, 2026, the CMS Hybrid Cloud Team will begin the Q3 2026 CMS Enterprise Security Campaign.

Any findings will be tracked via Jira tickets and assigned to the respective teams for remediation. The Q3 CMS Enterprise Security Campaign is targeting 46 Critical Common Vulnerabilities and Exposures (CVEs) that pose a high risk to CMS systems.

Benefits

Resolving findings in customers' Jira tickets ensures CMS systems remain secure. Participating in proactive, routine security activities, such as this CMS Enterprise Security Campaign, reduces the risk of unauthorized and/or malicious activity.

The CMS Enterprise Security Campaign will target and identify the following vulnerabilities and CVEs:

Targeted Vulnerabilities and Common Vulnerabilities and Exposures (CVEs)

319711 RHEL 9 : unbound (RHSA-2026:24369) Critical
322070 Amazon Linux 2023 : openssl, openssl-devel, openssl-fips-provider-latest (ALAS2023-2026-1853) Critical
318387 pyOpenSSL 22.0.x < 26.0.0 Buffer Overflow Critical
322796 Oracle Siebel Server <= 26.5 (June 2026 CSPU) Critical
319851 Amazon Linux 2023 : perl, perl-Attribute-Handlers, perl-AutoLoader (ALAS2023-2026-1819) Critical
315644 Amazon Linux 2023 : policycoreutils, policycoreutils-dbus, policycoreutils-devel (ALAS2023-2026-1663) Critical
326731 Apache Tomcat 10.1.0.M1 < 10.1.57 multiple vulnerabilities Critical
326866 KB5099540: Windows Server 2022 / Azure Stack HCI 22H2 Security Update (July 2026) Critical
326730 Apache Tomcat 9.0.13 < 9.0.120 multiple vulnerabilities Critical
317506 RHEL 9 : flatpak (RHSA-2026:21755) Critical
327970 RHEL 9 : httpd (RHSA-2026:41906) Critical
326236 libcurl 7.46.0 < 8.21.0 Super Cookie PSL Bypass (CVE-2026-8924) Critical
323016 libcurl 7.12.0 < 8.21.0 Cross-Proxy Digest Auth State Leak Critical
186721 RHEL 9 : apr (RHSA-2023:7711) Critical
319534 RHEL 8 : samba (RHSA-2026:22644) Critical
317046 RHEL 8 : gnutls (RHSA-2026:20611) Critical
276933 Fluent Bit < 4.0.12 / 4.1.x < 4.1.1 Multiple Vulnerabilities Critical
326875 KB5099538: Windows 10 version 1809 / Windows Server 2019 Security Update (July 2026) Critical
326732 Apache Tomcat 11.0.0.M1 < 11.0.24 multiple vulnerabilities Critical
322793 Node.js 22.x < 22.23.0 / 24.x < 24.17.0 / 26.x < 26.3.1 Multiple Vulnerabilities (Thursday, June 18, 2026 Security Releases). Critical
306785 RHEL 8 : libarchive (RHSA-2026:8534) Critical
324118 Oracle Identity Manager (June 2026 CSPU) Critical
323007 libcurl 7.10.6 < 8.21.0 Cross-Origin Digest Auth State Leak Critical
320136 OpenSSL 3.5.0 < 3.5.7 Multiple Vulnerabilities Critical
325585 Amazon Linux 2 : samba, --advisory ALAS2-2026-3493 (ALAS-2026-3493) Critical
314162 RHEL 9 : glib2 (RHSA-2026:15971) Critical
182308 OpenSSL SEoL (1.1.1.x) Critical
317395 IBM HTTP Server 8.5.0.0 < 8.5.5.30 / 9.0.0.0 < 9.0.5.29 Multiple Vulnerabilities (7274065) Critical
104324 Oracle Identity Manager Default Account Local Check (CVE-2017-10151) Critical
109345 Oracle WebLogic Unsupported Version Detection Critical
178010 Oracle Global Lifecycle Management (OPatch) (Jan 2023 CPU) Critical
183311 Oracle WebLogic Server (October 2023 CPU) Critical
306774 RHEL 9 : libarchive (RHSA-2026:8510) Critical
328811 Oracle Linux 9 : glib2 (ELSA-2026-42089) Critical
319782 Amazon Linux 2023 : perl-Archive-Tar, perl-Archive-Tar-tests (ALAS2023-2026-1805) Critical
322408 Containerd 2.1.x < 2.1.9 / 2.2.x < 2.2.5 / 2.3.x < 2.3.2 Multiple Vulnerabilities Critical
327369 JetBrains IntelliJ IDEA < 2026.1.4 Code Execution via Path Traversal (CVE-2026-59792) Critical
156935 Oracle Access Manager Unknown Vulnerability (Jan 2022 CPU) Critical
311316 Amazon Linux 2023 : mesa-dri-drivers, mesa-filesystem, mesa-libd3d (ALAS2023-2026-1623) Critical
314334 Apache Tomcat 9.0.0.M1 < 9.0.118 multiple vulnerabilities Critical
322988 Oracle Linux 9 : gnutls (ELSA-2026-20612) Critical
102082 Microsoft Access Unsupported Version Detection Critical
73756 Microsoft SQL Server Unsupported Version Detection (remote check) Critical
305956 RHEL 9 : cockpit: Unauthenticated remote code execution due to SSH command-line argument injection (Critical) (RHSA-2026:7384) Critical
329169 Oracle WebLogic Server Multiple Vulnerabilities (July 2026 CPU) (12.2.1.4.0 / 14.1.2.0.0) Critical
329171 Oracle WebLogic Server Multiple Vulnerabilities (July 2026 CPU) (12.2.1.4.0 / 14.1.1.0.0 / 15.1.1.0.0) Critical

Note: Operating System (OS)-level findings are remediated by the CMS Hybrid Cloud Team for customers who receive regular CMS Gold Image patching services. Please note that CMS customers are responsible for patching any software installed on top of the provided CMS Gold Image.

Additional Security Campaign Targets

In addition to the Tenable vulnerabilities, we will be performing a review of AWS Config settings across the enterprise. If your account does not meet the required AWS Config baseline for CMS Hybrid Cloud, our team will resolve the issue. No action is required by your team for these AWS Config updates. This is included here for notification purposes only.

Expected Actions

  • CMS customers with findings will receive a Jira ticket.
    • If you would like to obtain an exemption, you will need to complete an attestation.
  • CMS customers should resolve all received Jira tickets as soon as possible.
    • For help, please refer to the "Questions or Concerns" section below for instructions on how to submit a Hybrid Cloud Support ticket.
  • Failure to resolve findings can lead to compromised systems that result in greater risks for unauthorized and/or malicious activity.
  • Unresolved system flaws will result in Plan of Action and Milestones (POA&Ms) being issued against the Federal Information Security Modernization Act (FISMA) boundary.

Timeline

  • August 26, 2026: CMS customers with findings will receive Jira tickets for the findings noted in the "Benefits" section above.

Additional Information

Questions or Concerns

We look forward to helping you and your team. Reach out to your IUSG Hosting Coordinator with any questions. For further help, please fill out a Hybrid Cloud Support ticket as a CMS Cloud: Service Request specifying Request Type as "Security Posture Management - Findings".

 

This email was sent to NPxrji73qy@niepodam.pl using Granicus Communications Cloud 7500 Security Boulevard · Baltimore MD 21244