Red Hat has identified an Important OpenShift vulnerability that could enable attackers to bypass release-image signature verification and inject malicious payloads into disconnected registries. This issue, tracked as CVE-2026-75939, impacts the oc-mirror utility and carries a CVSS v3.1 score of 7.4. They could deliver a malicious PGP message that references a legitimate Red Hat release key ID, while containing a forged signature and an attacker-controlled release payload.
Organizations commonly use oc-mirror to transfer release images, Operator catalogs, and related content to an internal registry before deploying or updating clusters that cannot directly access external registries. The CVSS vector identifies network access, high attack complexity, no required privileges, and no user interaction: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N.
The weakness is classified as CWE-347, "Improper Verification of Cryptographic Signature." In practical terms, the defect does not break PGP cryptography itself; it undermines the logic that determines whether a signed object has been fully and successfully verified. Security teams should restrict and monitor outbound connectivity from mirroring hosts, prevent unauthorized traffic interception through trusted network controls, and investigate mirror logs for unexpected release sources, digest changes, or anomalous signature responses.
Until a vendor fix or updated errata becomes available, teams should review all disconnected-registry ingestion workflows, as successful exploitation could transform a trusted OpenShift update mechanism into a vehicle for malicious code deployment. Explore for your team.






![Top 10 Best Identity Threat Detection & Response (ITDR) Tools in 2026 [Ranked & Scored]](http://cybersecuritynews.com/wp-content/uploads/2026/09/Best-Identity-Threat-Detection-Response-ITDR-Tools.webp)




