CVE-2026-62185: Argoproj Argo-Helm

High severity, CVSS 7.6. EPSS: 0.5% chance of exploitation in the next 30 days.

Argo CD Helm Chart before 10.0.0 fails to install network policies by default, allowing any pod on a cluster to access repo-server and other Argo APIs. Attackers can exploit this unrestricted network access through combined attacks to achieve cluster compromise and remote code execution.

Affected products

  • Argoproj Argo-Helm: before 10.0.0 (fixed in 10.0.0)

Published 2026-07-13. Last modified 2026-07-15.