CVE-2026-15911: Confluent Confluent-Kafka

High severity, CVSS 7.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation.

Affected products

  • Confluent Confluent-Kafka: up to and including 2.14.2

Published 2026-10-01. Last modified 2026-10-06.