Cert Manager is a Kubernetes-native certificate lifecycle-management tool with a focused, single-product scope that occupies a critical position in cloud-native deployments by automating certificate issuance, renewal, and validation. The observed vulnerability surface remains minimal in volume and does not yet present a durable pattern of recurring weakness classes. Current exposure counts and severity details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cert Manager over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25518MEDIUM cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the process of obtaining, renewing and using those certificates. In | Feb 4, 2026 | 5.9 | 20 | NO | NO |
CVE-2024-36537HIGH Insecure permissions in cert-manager v1.14.4 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token. | Jul 24, 2024 | 7.2 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cert Manager.
Media articles that mention a CVE ID that affects a product developed by Cert Manager — matched by CVE ID, not by vendor name.