Windows kubelet NTLM coercion via subPath UNC symlinks
CVE-2026-76654 lets a privileged attacker steal or relay the kubelet account hash on Windows nodes.
By tarpitCVE-2026-76654 lets a privileged attacker steal or relay the kubelet account hash on Windows nodes.
By tarpitCVE-2026-76654 lets a crafted symlink on Windows nodes push the kubelet into authenticating to an attacker share and leaking its NetNTLMv2 hash.
By cronjob