Is Kyverno 1.16.4 patched?
Current stable (1.17.2): 100/100
1.16.4 has 2 open critical-or-high vulnerabilities. Run 1.17.2 or later to clear them. See what 1.17.2 fixes →
Summary iPlain-English security status for Kyverno 1.16.4, built from its CVEs, active-exploitation data, end-of-life date and latest release.
Kyverno 1.16.4 is part of the 1.16 release line. 2 known vulnerabilities affect it. The minimum safe version is 1.17.2 — upgrade to it or later to clear the open critical/high issues. The latest supported Kyverno release is 1.17.2.
Known issues affecting 1.16.4
Exploited first, then by exploitation probability.
CVE-2026-4789 CRITICAL EPSS 1% → see advisory CVE-2026-41068 HIGH EPSS 0% → fixed in 1.17.2Other Kyverno versions
Check another release line of Kyverno.
Frequently asked
Is Kyverno 1.16.4 patched?
Kyverno 1.16.4 has 2 open critical-or-high vulnerabilities. The minimum safe version is 1.17.2 — upgrade to 1.17.2 or later to clear them.
What version should I upgrade Kyverno 1.16.4 to?
Upgrade Kyverno 1.16.4 to at least 1.17.2 to clear its 2 open critical-or-high vulnerabilities.
What is the latest version of Kyverno?
The latest supported Kyverno release is 1.17.2.
Is Kyverno 1.16.4 still receiving security updates?
Yes — the 1.16 line is still supported and receiving security updates. The latest release is 1.17.2.
Informational only, from public data (NVD · CISA KEV · EPSS · endoflife.date), and can lag or miss vendor-specific fixes. Always confirm against Kyverno's official advisory before you patch or upgrade — Kyverno official site ↗