Chapter 1. Red Hat Advanced Cluster Security for Kubernetes 4.11
Red Hat Advanced Cluster Security for Kubernetes (RHACS) is an enterprise-ready, Kubernetes-native container security solution that protects your vital applications across the build, deploy, and runtime stages of the application lifecycle.
RHACS deploys into your infrastructure and integrates with your DevOps tools and workflows. This integration provides better security and compliance, enabling DevOps and InfoSec teams to operationalize security.
1.1. Release dates Copy linkLink copied to clipboard!
Review the official release dates and update schedule for RHACS 4.11.
| RHACS version | Released on |
|---|---|
|
| 15 June 2026 |
|
| 7 July 2026 |
|
| 30 July 2026 |
1.2. About release 4.11 Copy linkLink copied to clipboard!
RHACS 4.11 includes new features, improvements, and updates.
1.3. New features Copy linkLink copied to clipboard!
This release adds new features and enhanced functionality for existing features.
1.3.1. Enhanced vulnerability management reporting Copy linkLink copied to clipboard!
This update includes enhancements in vulnerability management reporting that provide more data, additional filtering options, and scheduling flexibility.
This release includes the following changes:
- Vulnerability reports now include a column showing the current version of each affected component. This eliminates the need to manually cross-reference external inventories when examining and assigning fixable CVEs.
- Administrators can now specify an exact time of hour and minute for scheduled vulnerability report generation, replacing the earlier randomized delivery window. This provides predictable, consistent report delivery aligned with audit, compliance, and operational schedules.
- Scheduled vulnerability reports now use the same filtering options available in the Vulnerability Management workflow views. Using these options, you can now create more granular scheduled reports. You can also begin a new report configuration directly from your active workflow filters, carrying over applied filter criteria without manual re-entry.
1.3.2. Red Hat hardened image scanning Copy linkLink copied to clipboard!
Red Hat Advanced Cluster Security Clair can scan Red Hat hardened images (Project Hummingbird) and cross-reference findings with Red Hat VEX metadata, supporting validation and ongoing monitoring of hardened image CVE posture.
1.3.2.1. Known issue as of July 15, 2026 Copy linkLink copied to clipboard!
Due to a recently identified data gap in the Red Hat VEX security data feed, RHACS version 4.11 no longer supports vulnerability reporting for Red Hat hardened images (Project Hummingbird). The Red Hat Product Security Team is working to address this identified data gap so that RHACS can re-introduce support for Red Hat hardened images.
1.3.3. Policy scope support for cluster and namespace labels Copy linkLink copied to clipboard!
Policy scope selection capabilities have been expanded, allowing you to include clusters by label.
1.3.4. Policy-based detection and enforcement for oc debug and pods attach operations Copy linkLink copied to clipboard!
RHACS policies now cover Kubernetes pod attach requests, including oc debug and oc debug node, in addition to the existing pod exec and port forward controls. The default Kubernetes Actions: Attach to Pod policy alerts on interactive attach sessions and can block them when you enable enforcement.
1.3.5. Support for Compliance Operator tailored profiles scheduling and maintenance Copy linkLink copied to clipboard!
RHACS now supports seamless integration of existing tailored profiles from Compliance Operator. You can now schedule and manage your custom security configurations directly from the RHACS interface. This update fully accommodates profiles with suppressed rules or multi-profile combinations and profiles that are using the latest CustomRules functionality.
1.3.6. Splunk integration improvements Copy linkLink copied to clipboard!
The Splunk Technology Add On has been updated, adding support for File Activity violations and aligning with recent Splunk changes. The new version, 3.0.0, is available for download on SplunkBase.
1.4. Performance and operations Copy linkLink copied to clipboard!
This release includes performance and operational improvements.
1.4.1. Image scan accuracy Copy linkLink copied to clipboard!
Images are now uniquely identified by the combination of name and digest, rather than by digest alone. This new data model resolves several long-standing issues when multiple images share the same digest but have different names, for example, different registries or tags.
1.4.2. Lightweight runtime data collection Copy linkLink copied to clipboard!
RHACS now uses a more efficient runtime data collection mechanism that reduces resource consumption while maintaining comprehensive security monitoring capabilities.
1.4.3. Faster admission controller Copy linkLink copied to clipboard!
Admission controller performance has been improved by keeping the image cache warm longer, and eliminating image fetches for policies that do not evaluate images. The default memory limit of admission controller pods is now 1 Gi, which has increased from 500 Mi.
1.4.4. API list performance optimizations Copy linkLink copied to clipboard!
API list performance was optimized to improve performance and resource consumption of certain endpoints returning List<Type> objects.
1.4.5. Migration to UBI 9 minimal base images Copy linkLink copied to clipboard!
All RHACS Operator and operand images are now built on UBI 9 Minimal base images. This improves your security posture by shrinking the attack surface and eliminating CVE noise from unnecessary packages.
This migration provides a smaller attack surface, reduced image size, and alignment with the latest Red Hat Universal Base Image standards.
1.4.6. Installation method consolidation to Operator-based deployment Copy linkLink copied to clipboard!
Installation methods have been consolidated to focus on Operator-based deployment as the primary installation approach.
This consolidation simplifies the installation experience and aligns with Kubernetes-native deployment patterns. The RHACS Operator provides a consistent, automated installation and upgrade experience across all supported platforms.
1.4.7. Cluster registration secrets improvements Copy linkLink copied to clipboard!
Cluster registration secrets (CRSes) were generally available in an earlier release and make the bootstrapping process more secure. In this release, you can configure the CRS maximum expiration time and the maximum number of clusters that can generate and use CRSes through the RHACS web console. This flexibility provides additional hardening and strengthening for CRSes. Credential management is key to the secure functioning of your fleet application and helps prevent exfiltration attacks.
1.5. Technology Preview features Copy linkLink copied to clipboard!
This release includes Technology Preview features that provide early access to upcoming product innovations.
Technology Preview features are not supported with Red Hat production service level agreements (SLAs) and might not be functionally complete. Red Hat does not recommend using them in production. These features provide early access to upcoming product features, enabling customers to test functionality and provide feedback during the development process.
For more information about the support scope of Red Hat Technology Preview features, see Technology Preview Features Support Scope.
1.5.1. Init container vulnerability scanning Copy linkLink copied to clipboard!
RHACS now scans images used by init containers and displays init container information, if it exists, in the deployment details.
This feature is available as a Technology Preview and is disabled by default. To enable init container scanning, set the ROX_INIT_CONTAINER_SUPPORT feature flag to true.
When enabled, RHACS extracts, scans, and displays init containers in the following RHACS locations:
- Violations Detail view
- Network Graph sidebar
- Risk Deployment details
- Vulnerability Management
Init containers are included in risk scores and compliance checks. However, policies do not evaluate init containers in this Technology Preview release.
Enabling this feature might increase scanner load, as deployments with init containers might require scanning additional images per deployment. Monitor scanner capacity after enabling this feature.
1.5.2. Dynamic path support for file activity monitoring Copy linkLink copied to clipboard!
File activity monitoring now supports user-defined path specifications with wildcard patterns, enhanced filtering options, and file rename operation detection.
With this feature, you can define custom paths to monitor using wildcard patterns, filter file activity based on criteria such as process name and ancestor, create policies for file rename operations, and combine process criteria with file access criteria in deployment and node policies.
1.5.3. Policy differentiation for CVE origin from base images or application layers Copy linkLink copied to clipboard!
You can use this Technology Preview feature to experiment with the planned user interface. To use this feature, you must set the feature flag ROX_POLICY_FILTERS_UI to enabled.
1.6. Technology Preview features promoted to General Availability Copy linkLink copied to clipboard!
The following features were available earlier as Technology Preview and are now Generally Available (GA) in this release.
GA features are fully supported and suitable for production use.
1.6.1. RHACS vulnerability management in OpenShift console plugin Copy linkLink copied to clipboard!
The RHACS vulnerability management integration with the Red Hat OpenShift console plugin is now generally available.
This feature provides vulnerability information directly within the OpenShift Container Platform web console, enabling platform administrators and developers to view and manage security vulnerabilities without leaving their primary workflow interface.
The plugin is supported on OpenShift Container Platform versions 4.19 and later.
1.6.2. Standardized base image definition and layer detection Copy linkLink copied to clipboard!
Standardized base image definition and layer detection is now generally available.
1.7. Notable technical changes Copy linkLink copied to clipboard!
This release includes notable technical changes.
This release has the following changes:
- Update to Patternfly 6
- The RHACS web portal has been upgraded to PatternFly 6. PatternFly 6 provides an improved user experience with enhanced accessibility, better performance, and a modernized visual design.
- Security and other enhancements
- For security purposes, the functionality to export reports to PDF is removed. PDF report generation functionality was replaced with alternative implementations.
-
Istio support in RHACS was simplified and the
env.istioconfiguration parameter no longer exists. Existing instances of this variable will be ignored and Istio support is always enabled.
1.8. Deprecated and removed features Copy linkLink copied to clipboard!
Identify the deprecated and removed features in RHACS 4.11 to ensure your deployment remains secure and fully functional.
Some features available in earlier releases have been deprecated or removed.
Deprecated functionality is still included in RHACS and continues to be supported; however, it will be removed in a future release of this product and is not recommended for new deployments.
For the most recent list of major functionality deprecated and removed, see the following table. Information about additional removed or deprecated functionality is available after the table.
In the table, features are marked with the following statuses:
- GA: General Availability
- TP: Technology Preview
- DEP: Deprecated
- REM: Removed
- NA: Not applicable
| Feature | RHACS 4.9 | RHACS 4.10 | RHACS 4.11 |
|---|---|---|---|
| Admission controller configuration parameters:
| GA | DEP | DEP |
| API token authentication for Red Hat OpenShift Cluster Manager | DEP | DEP | DEP |
| Collections hierarchical implementation | GA | DEP | DEP |
| Compliance dashboard | DEP | DEP | REM |
|
| DEP | DEP | DEP |
| Google Container Registry integration | DEP | DEP | DEP |
| GraphQL endpoints | GA | DEP | DEP |
| Kernel support packages and driver download functionality | DEP | DEP | DEP |
| Reporting of Istio vulnerabilities | DEP | DEP | DEP |
|
| GA | DEP | DEP |
| Scanner V2 | DEP | DEP | DEP |
|
| DEP | DEP | DEP |
|
| DEP | DEP | DEP |
|
| DEP | DEP | DEP |
|
| DEP | DEP | DEP |
| Vulnerability Management (1.0) menu item | DEP | DEP | DEP |
| Vulnerability Report Creator permission | DEP | DEP | DEP |
| Init Bundle | GA | DEP | DEP |
|
| GA | DEP | DEP |
|
| GA | DEP | DEP |
| Configuration Management Dashboard and sub-menus | GA | DEP | DEP |
| OpenShift auth identity provider | GA | DEP | DEP |
| Compliance V1 | GA | DEP | DEP |
| Graph view in the Process discovery tab | GA | DEP | DEP |
| Vulnerability reports using attached collections | GA | DEP | DEP |
| Vulnerability Management Dashboard (1.0) and sub-menus | GA | DEP | DEP |
| Install-time Istio integration | GA | DEP | DEP |
| Kubernetes components view | GA | DEP | DEP |
|
Manifest install method and the related | DEP | DEP | DEP |
| Direct Helm chart installations (central-services and secured-cluster-services charts) | GA | GA | DEP |
|
Plain text (non-TLS) endpoints configured by using the | GA | GA | DEP |
- Deprecated features
- Manifest install method and related API
-
The manifest install method and the related
/v1/clustersAPI, which deployed and managed clusters, is deprecated and is anticipated to be removed in a future release. - Direct Helm chart installations
-
The direct Helm chart installations using the
central-servicesandsecured-cluster-servicescharts are deprecated and are anticipated to be removed in a future release. You can install RHACS by using the new Operator-based Helm chart, which deploys the RHACS Operator to manage your installation instead. - Init Bundle
-
The Init Bundle feature, which registers secured clusters with RHACS Central, is deprecated and is anticipated to be removed in a future release. The associated APIs
/v1/cluster-init/init-bundles/revokeand/v1/cluster-init/init-bundlesare also deprecated. You can register new clusters by using the cluster registration secret (CRS) instead. - Configuration Management Dashboard and sub-menus
- The Configuration Management Dashboard and all of its sub-menus, which provided security configuration data, are deprecated and are anticipated to be removed in a future release. API access for Secrets or role-based access control (RBAC) information remains available. Security configuration data integrates directly into risk and policy management workflows to enhance visibility without relying on a standalone dashboard.
- OpenShift auth identity provider
- The OpenShift auth identity provider, which served as an identity provider (IdP) for RHACS, is deprecated and is anticipated to be removed in a future release. You can authenticate users by using OpenID Connect (OIDC) IdP integrations instead.
- Compliance V1
The Compliance V1 functionality, including the Compliance Dashboard, compliance APIs, and compliance configuration management board, which provided the earlier compliance implementation, was deprecated in release 4.10. The Compliance Dashboard was removed in release 4.11.
NIST SP 800-190 and HIPAA benchmarks are currently not supported by the Compliance Operator and were only visible in the Compliance Dashboard, which has been removed.
Additionally, Compliance support for non-OpenShift Kubernetes distributions is deprecated and is anticipated to be removed in a future release. If you rely on this functionality, you should prepare for a loss of functionality. For clusters running OpenShift, you can access improved compliance features by using the new compliance version instead.
- Graph view in the Process discovery tab
- The Graph view, within the Risk section of the Event Timeline in the Process discovery tab, is deprecated and is anticipated to be removed in a future release.
- Scanner V2
- Starting with RHACS 4.6, Scanner V2, also known as StackRox Scanner is deprecated and is anticipated to be removed in a future release. To maintain supported vulnerability scanning capabilities and access the latest security features, you should migrate to Scanner V4.
- Vulnerability reports by using attached collections
- The vulnerability reports by using attached collections, which provided report scoping through hierarchical relationships, are deprecated and are anticipated to be removed in a future release. You can prepare for future updates to the scoping mechanism by avoiding attached collections.
- Vulnerability Management Dashboard (1.0) and sub-menus
- Starting with RHACS 4.3, the Vulnerability Management Dashboard (1.0) and all of its sub-menus, which provided traditional vulnerability management views, are deprecated and is anticipated to be removed in a future release. You can access vulnerability information by using the current Vulnerability Management Dashboard instead.
- Install-time Istio integration
-
The creation of
networking.istio.io/v1alpha3/DestinationRuleresources by RHACS installation, which automatically generated networking configurations during setup, is deprecated and is anticipated to be removed in a future release. You can manage Istio configurations by creatingDestinationRuleresources out-of-band instead. - Kubernetes components view
-
The Kubernetes components view available in the RHACS portal at Vulnerability Management
Results More Views is deprecated and is anticipated to be removed in a future release.
- Plain text (non-TLS) endpoints configured by using the
ROX-PLAINTEXT_ENDPOINTSenvironment variable - These are deprecated and will be removed in a future release. Modern load balancers and ingress controllers support TLS passthrough, making plain text endpoints unnecessary.
1.9. Known issues in version 4.11 Copy linkLink copied to clipboard!
The following known issues exist in RHACS 4.11. Review these items before deploying or upgrading to this version.
- Due to a recently identified data gap in the Red Hat VEX security data feed, RHACS version 4.11 no longer supports vulnerability reporting for Red Hat hardened images (Project Hummingbird). See "Red Hat hardened image scanning" for more information.
1.10. Bug fixes in version 4.11 Copy linkLink copied to clipboard!
This release contains bug fixes and enhancements.
- In RHACS release 4.8 through release 4.10, the timestamp for the "Days since CVE was first discovered in system" policy criteria and the "CVE Created Time" search term were not properly maintained and could be reset to a newer timestamp. This release has a fix for this issue and the timestamp will no longer be reset.
-
Starting with RHACS 4.11, the command
roxctl deployment check -f <deployment.yaml> --cluster <cluster name or id>will evaluate the deployment against the policies as if the deployment is running on the cluster as specified.
- Fixed an issue where the Integrations page tile layout spacing was excessively large when using the Mozilla Firefox browser. Large gaps between tiles on the integration page have been fixed, and the display is now a more uniform grid.
1.11. Bug fixes and security updates in version 4.11.1 Copy linkLink copied to clipboard!
This release includes the following bug fixes:
- Before this update, Scanner V4 could report the same vulnerability multiple times for a single component due to multiple entries in the OSV data source. With this release, Scanner V4 implements deduplication logic to ensure that it reports each CVE only once per component, reducing false positives and improving vulnerability report accuracy.
- Before this update, Scanner V4 did not use Red Hat VEX data to filter out packages marked as "not affected" by specific vulnerabilities. With this release, Scanner V4 supports Red Hat CSAF/VEX "not vulnerable" assertions, reducing false positives by not reporting vulnerabilities for packages that are not affected.
- Before this update, loading Compliance Operator profiles on large-scale deployments could cause Central startup to crash due to query timeouts. This release fixes this issue.
- Fixed an issue where under certain circumstances, clusters might not appear in the OpenShift Coverage section under the Compliance tab. Red Hat has improved compliance scan watcher behavior to prevent this issue.
- Before this update, the RHACS Helm chart versions in the mirror and GitHub repositories showed wrong version strings. This release corrects the Helm charts to display the proper version string.
-
Before this update, the Artifactory "test" function always returned
true, even when authentication failed. The test endpoint did not require authentication, causing confusion about integration status. With this release, the test function now performs an authenticated operation to properly validate credentials before reporting success. - Images built with erroneous quotes in metadata can now be properly scanned by Scanner V4.
RHACS includes fixes for the following security vulnerabilities:
Go and golang.org:
- golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions (CVE-2026-39828)
- golang.org/x/crypto/ssh: Denial of service via crafted public key with excessive parameters (CVE-2026-39829)
- golang.org/x/crypto/ssh: Denial of service via resource leak from unsolicited SSH responses (CVE-2026-39830)
- golang.org/x/crypto/ssh: Denial of service via crafted SSH certificate (CVE-2026-39835)
- golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation (CVE-2026-46595)
- golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)
- golang.org/x/net/html: Arbitrary HTML parsing and rendering can permit cross-site scripting attacks (CVE-2026-25681) and (CVE-2026-27136)
- Go net package: Denial of service via long CNAME response in LookupCNAME (CVE-2026-33811)
- Flaw in RHACS potentially could allow excessive resource consumption leading to denial of service (CVE-2026-9165)
- Prototype pollution flaw in Axios (CVE-2026-42264)
- github.com/containerd: Command execution vulnerability (CVE-2026-53488)
1.12. Bug fixes and security updates in version 4.11.2 Copy linkLink copied to clipboard!
RHACS includes fixes for the following security vulnerabilities:
Go and golang.org:
- Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504)
- Go os.Root: Symlink following vulnerability allows directory traversal (CVE-2026-39822)
- Brace-expansion: Denial of service due to exponential-time complexity (CVE-2026-13149)
- js-yaml: Denial of service via crafted YAML documents (CVE-2026-59869)
- DOMPurify: Cross-site scripting vulnerability allows code execution (CVE-2026-49978)
1.13. Image versions Copy linkLink copied to clipboard!
You can manually pull, retag, and push Red Hat Advanced Cluster Security for Kubernetes (RHACS) images to your registry. The current version includes the following images:
| Image | Description | Current version |
|---|---|---|
| Main |
Includes Central, Sensor, Admission controller, and Compliance components. Also includes |
|
| Central DB | PostgreSQL instance that provides the database storage for Central. |
|
| Scanner | Scans images and nodes. |
|
| Scanner DB | Stores image scan results and vulnerability definitions. |
|
| Scanner V4 | Scans images. |
|
| Scanner V4 DB | Stores image scan results and vulnerability definitions for Scanner V4. |
|
| Collector | Collects runtime activity in Kubernetes or OpenShift Container Platform clusters. |
|