Security Advisories and Security Release Notes
Follow this section for security advisory notifications
- Security Release Notes for CP 7.7.10
- Security Release Notes for CP 7.6.12
- Security Release Notes for CP 7.5.15
- CONFSA-2026-08: CVE-2026-35194: Confluent Cloud and Confluent Platform Vulnerability: Authenticated Remote Code Execution (RCE) via Flink SQL queries
- CONFSA-2026-07: CVE-2026-33558: Confluent Platform - DEBUG level logging could result in sensitive information exposure
- Security Release Notes for CP 8.2.1 (Out of band Critical Patch Release)
- Security Release Notes for CP 8.1.3 (Out of band Critical Patch Release)
- Security Release Notes for CP 8.0.5 (Out of band Critical Patch Release)
- Security Release Notes for CP 7.9.7 (Out of band Critical Patch Release)
- Security Release Notes for CP 7.8.8 (Out of band Critical Patch Release)
- Security Release Notes for CP 7.7.9 (Out of band Critical Patch Release)
- Security Release Notes for CP 7.6.11 (Out of band Critical Patch Release)
- Security Release Notes for CP 7.5.14 (Out of band Critical Patch Release)
- Security Release Notes for CP 7.4.15 (Out of band Critical Patch Release)
- CONFSA-2026-06: Confluent Cloud and Confluent Platform: Arbitrary Class Instantiation via JSON Schema Deserialization
- CONFSA-2026-05: Confluent Cloud and Confluent Platform Vulnerability: Authenticated users can override configuration property to exfiltrate internal Kafka credentials via ksqlDB operations
- CONFSA-2026-04: Confluent Cloud and Confluent Platform Vulnerability: Remote Code Execution (RCE) and Arbitrary File Read via /test Endpoint in ksqlDB clusters
- CONFSA-2026-03: Confluent Cloud and Confluent Platform Vulnerability: Authenticated Remote Code Execution (RCE) via ksqlDB SQL queries
- CONFSA-2026-02: CVE-2026-33557: Missing Java Web Token(JWT) Validation in Apache Kafka's OAUTHBEARER Authentication
- Security Release Notes for CFK 3.2.2
- Security Release Notes for USM agent
- Security Release Notes for CPC Gateway
- Security Release Notes for Control Center Next Generation
- CONFSA-2026-01: CVE-2026-35554: Producer Message Corruption and Misrouting in Apache Kafka Clients
- Security Release Notes for CFK 3.2.1
- Security Release Notes for CFK 3.1.2
- Security Release Notes for CFK 3.0.4
- Security Release Notes for CFK 3.0.3
- Security Release Notes for CFK 2.10.5
- Security Release Notes for CFK 2.11.5