References https://etcd.io/blog/2026/mar20-patch-release/ https://github.com/etcd-io/etcd/security/advisories/GHSA-q8m4-xhhv-38mg https://www.rapid7.com/db/vulnerabilities/http-etcd-unauthenticated-api-data-leak/ https://github.com/etcd-io/etcd/issues/9475 https://hackviser.com/tactics/pentesting/services/etcd https://cybertechnologyinsights.com/cybersecurity/etcd-vulnerability-unauthorized-api-access-security/ https://nvd.nist.gov/vuln/detail/CVE-2026-33413 https://cve.imfht.com/poc_detail/5af208f771c8c3313d97fa478dd1e069e4ed8ac2 https://github.com/HXSecurity/TerraformGoat/releases https://www.cnblogs.com/qtzd/p/k8s_etcd.html
Related VulnerabilitiesPoCCVE-2026-10818: WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File UploadPoCCVE-2026-26216: Crawl4AI < 0.8.0 - Unauthenticated Remote Code Execution via Hooks ParameterPoCCVE-2026-29058: WWBN AVideo Encoder < 7.0 - Unauthenticated OS Command InjectionPoCCVE-2026-86242: Bifrost < 1.6.3 - Unauthenticated Remote Plugin URL FetchPoCCVE-2026-12227: Visual Composer <= 45.16.0 - Unauthenticated LFIPoCCVE-2026-61560: GitLab MCP Server < 2.1.27 - Unauthenticated SSE Transport AccessPoCCVE-2026-89063: Bookly <=28.1 - IDOR Unauthenticated Sensitive Data AccessPoCmcp-streamable-http-exposure: MCP Streamable HTTP Server - Unauthenticated InitializePoCCVE-2026-6639: AI Copilot Content Generator <=1.4.6 - Unauthenticated Task Data ExposurePoCCVE-2026-80099: Newfold WordPress Plugins - Unauthenticated Admin Bypass via Empty HMAC SecretPoCpowerdns-monitor-exposure: PowerDNS Authoritative Server Monitor - Unauthenticated ExposurePoCCVE-2026-82456: argocd-mcp 0.8.0 - Unauthenticated MCP Session and Tool AccessPoCCVE-2026-84434: WordPress Gravity Forms Plugin <=3.1.0.4 - Unauthenticated Arbitrary File Upload