Review reviewHigh

CVE-2026-27970

angular angular, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Enterprise Linux 10

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Versions prior to 21.2.0, 21.1.16, 20.3.17, and 19.2.19 have a cross-Site scripting vulnerability in the Angular internationalization (i18n) pipeline. In ICU messages (International Components for Unicode), HTML from translated content was not properly sanitized and could execute arbitrary JavaScript. Angular i18n typically involves three steps, extracting all messages from an application in the source language, sending the messages to be translated, and then m...

CVSS
7.6
EPSS
0.47%
38.0% percentile
CISA KEV
Not listed
Published
2026.02.26
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.47%
Technical severityCVSS 7.6

Vulnerability overview

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Versions prior to 21.2.0, 21.1.16, 20.3.17, and 19.2.19 have a cross-Site scripting vulnerability in the Angular internationalization (i18n) pipeline. In ICU messages (International Components for Unicode), HTML from translated content was not properly sanitized and could execute arbitrary JavaScript. Angular i18n typically involves three steps, extracting all messages from an application in the source language, sending the messages to be translated, and then m...

Affected product and versions

Product
angular angular, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Enterprise Linux 10
Affected versions
>= >= 21.2.0-next.0, < 21.2.0, >= >= 21.0.0-next.0, < 21.1.6, >= >= 20.0.0-next.0, < 20.3.17, >= >= 19.0.0-next.0, < 19.2.19, >= <= 18.2.14, >= 20.0.0 < 20.3.17, >= 21.0.0 < 21.1.6, 21.2.0
Fixed versions
19.2.19, 20.3.17, 21.1.6

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that angular angular, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Enterprise Linux 10 and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE
CWE-79
CVE-2026-27970 — angular angular, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Enterprise Linux 10 | SECUFOCUS NOW