suse
Latest CVEs
The 15 most recently published vulnerabilities affecting suse.
- CVE-2026-44940Service token exposure and potential privilege escalation in SUSE Observability5.7
- CVE-2026-44950fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont29.0
- CVE-2026-59679fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont29.0
- CVE-2025-46808Sensitive information is leaked into NeuVector’s manager container logs6.8
- CVE-2026-75036Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessing
- CVE-2026-75035Rancher: ext.cattle.io/v1 Token store: cross-user token disclosure via label-selector scoping bypass7.7
- CVE-2026-75034Rancher: SAML Assertion Replay7.4
- CVE-2026-75033Rancher: Cross-Cluster Secret Leakage via Namespace projectId Annotation Spoofing7.7
- CVE-2026-71404Rancher: Ownership-less ClusterRole overwrite via attacker-controlled cr-name annotation on GlobalRole8.7
- CVE-2026-71403Rancher: Identity-field mutation in /v3/users allows account hijack via principal rebind6.1
- CVE-2026-13348CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by performing an arbitrary number ...5.3
- CVE-2026-25706yast2-samba-client: OS command injection via attacker-controlled Organizational Unit (Active Directory-supplied)7.5
- CVE-2026-59681yast2-auth-client: OS command injection via unsanitized Organizational Unit / dnsHostName in AD join8.8
- CVE-2026-59680yast2-users: OS command injection via LDAP-supplied shadowLastChange/shadowExpire attribute8.0
- CVE-2026-71402wicked: out-of-bounds read in the DHCPv4 option parser due to payload length taken from the IP total length5.4