Security Advisories and Security Release Notes
Follow this section for security advisory notifications
- Security Release Notes for CPC Gateway
- Security Release Notes for CFK 3.3.1
- Security Release Notes for Control Center Next Generation
- CONFSA-2026-21: Confluent Platform Vulnerability: Missing Per-User Authorization Check in ksqlDB /query-stream Pull Queries
- Security Release Notes for CFK 3.2.4
- Security Release Notes for CFK 3.1.4
- Security Release Notes for CFK 3.0.6
- Security Release Notes for CFK 2.11.7
- Security Release Notes for CFK 2.10.7
- Security Release Notes for USM agent
- Security Release Notes for CP 8.3.2
- Security Release Notes for CP 8.2.4
- Security Release Notes for CP 8.1.6
- Security Release Notes for CP 8.0.8
- Security Release Notes for CP 7.9.10
- Security Release Notes for CP 7.8.11
- Security Release Notes for CP 7.7.12
- Security Release Notes for CP 7.6.14
- CONFSA-2026-15: Confluent Cloud and Confluent Platform Vulnerability: Denial of Service in Schema Registry via external schema references
- CONFSA-2026-14: Confluent Platform Vulnerability - Server-Side Request Forgery (SSRF) to internal endpoints via cluster link token login handler configuration
- CONFSA-2026-13: Confluent Platform: Multiple Netty Vulnerabilities
- Security Release Notes for CP 8.3.1 (Out of band Critical Patch Release)
- Security Release Notes for CP 8.2.3 (Out of band Critical Patch Release)
- Security Release Notes for CP 8.1.5 (Out of band Critical Patch Release)
- Security Release Notes for CP 8.0.7 (Out of band Critical Patch Release)
- Security Release Notes for CP 7.9.9 (Out of band Critical Patch Release)
- Security Release Notes for CP 7.8.10 (Out of band Critical Patch Release)
- Security Release Notes for CP 7.7.11 (Out of band Critical Patch Release)
- Security Release Notes for CP 7.6.13 (Out of band Critical Patch Release)
- Security Release Notes for CP 7.5.16 (Out of band Critical Patch Release)