Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

SUSE — Vulnerabilities & Security Advisories 241

Browse all 241 CVE security advisories affecting SUSE. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SUSE operates primarily as a provider of enterprise Linux distributions and cloud-native solutions, serving critical infrastructure in hybrid and multi-cloud environments. With 185 recorded CVEs, its vulnerability profile reflects the complexity of managing large-scale open-source codebases. Historically, common flaw classes include remote code execution (RCE), buffer overflows, and privilege escalation vulnerabilities, often stemming from misconfigurations or outdated dependencies within its core operating system components. Notable security characteristics involve its focus on container security and Kubernetes integration, which introduces attack surfaces related to orchestration layers. While no single catastrophic incident defines its history, the sheer volume of vulnerabilities highlights the ongoing challenge of maintaining security in widely deployed, long-term support releases. This necessitates rigorous patch management and continuous monitoring to mitigate risks associated with its extensive ecosystem of integrated services and third-party libraries.

CVE ID Title CVSS Severity Published
CVE-2026-88804 Unauthenticated update of public UI settings leading to stored cross-site scripting in Rancher — Rancher CWE-79 9.6 Critical 2026-09-28
CVE-2026-88805 Session Not Revoked Server-Side on Logout in Rancher — Rancher CWE-613 8.1 High 2026-09-28
CVE-2026-88808 Fleet agent copies downstream resources with cluster-admin privileges, allowing cross-namespace writes on downstream clusters — Rancher CWE-250 8.8 High 2026-09-28
CVE-2026-93540 Fleet applies namespace labels and annotations without the bundle's service account privileges — Rancher CWE-266 6.5 Medium 2026-09-28
CVE-2026-93539 Unauthenticated GitRepo Spec Mutation via Fleet Git Webhook Receiver — Rancher CWE-306 5.4 Medium 2026-09-28
CVE-2026-93538 Cross-tenant BundleDeployment and Secret disclosure via spoofed cluster labels during agent-initiated registration in Fleet — Rancher CWE-290 7.1 High 2026-09-28
CVE-2026-93537 Path traversal in Fleet Helm valuesFiles allows disclosure of files outside the bundle directory — Rancher CWE-23 6.5 Medium 2026-09-28
CVE-2026-78424 OS Command Injection in Packet-Capture (Sniffer) Filter leading to Remote Code Execution on Kubernetes Nodes — NeuVector CWE-78 8.8 High 2026-09-28
CVE-2026-78427 Admission Control Bypass via Hardcoded Sidecar Image Exemption — github.com/neuvector/neuvector CWE-807 5.3 Medium 2026-09-17
CVE-2026-78425 SAML Audience Confusion Allows Cross-SP Authentication — github.com/neuvector/neuvector CWE-287 7.6 High 2026-09-17
CVE-2026-78426 Logout bypass via alternate JWT spelling — neuvector CWE-863 2.0 Low 2026-09-17
CVE-2026-78428 Flaw in Neuvector can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently — neuvector 8.8 High 2026-09-17
CVE-2026-44940 Service token exposure and potential privilege escalation in SUSE Observability — SUSE Observability CWE-312 5.7 Medium 2026-09-17
CVE-2026-44950 fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont2 — Container suse/kiosk/tigervnc-x11vnc:1.14-63.8 9.0 Critical 2026-09-10
CVE-2026-59679 fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont2 — Container suse/kiosk/tigervnc-x11vnc:1.14-63.8 9.0 Critical 2026-09-10
CVE-2025-46808 Sensitive information is leaked into NeuVector’s manager container logs — neuvector CWE-532 6.8 Medium 2026-09-09
CVE-2026-75036 Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessing — Fleet CWE-918 5.3 Medium 2026-09-03
CVE-2026-75035 Rancher: ext.cattle.io/v1 Token store: cross-user token disclosure via label-selector scoping bypass — Rancher CWE-639 7.7 High 2026-09-03
CVE-2026-75034 Rancher: SAML Assertion Replay — Rancher CWE-294 7.4 High 2026-09-03
CVE-2026-75033 Rancher: Cross-Cluster Secret Leakage via Namespace projectId Annotation Spoofing — Rancher CWE-639 7.7 High 2026-09-03
CVE-2026-71404 Rancher: Ownership-less ClusterRole overwrite via attacker-controlled cr-name annotation on GlobalRole — Rancher CWE-639 8.7 High 2026-09-03
CVE-2026-71403 Rancher: Identity-field mutation in /v3/users allows account hijack via principal rebind — Rancher CWE-639 6.1 Medium 2026-09-03
CVE-2026-25706 yast2-samba-client: OS command injection via attacker-controlled Organizational Unit (Active Directory-supplied) — yast2-samba-client CWE-78 7.5 High 2026-09-01
CVE-2026-59681 yast2-auth-client: OS command injection via unsanitized Organizational Unit / dnsHostName in AD join — yast2-auth-client CWE-78 8.8 High 2026-09-01
CVE-2026-59680 yast2-users: OS command injection via LDAP-supplied shadowLastChange/shadowExpire attribute — yast2-users CWE-78 8.0 High 2026-09-01
CVE-2026-71402 wicked: out-of-bounds read in the DHCPv4 option parser due to payload length taken from the IP total length — wicked CWE-125 5.4 Medium 2026-08-27
CVE-2026-71401 wicked: integer underflow of the UDP length in ni_capture_inspect_udp_header() leads to an out-of-bounds read — wicked CWE-191 5.3 Medium 2026-08-27
CVE-2026-44945 Cross-Cluster Impersonation Confused-Deputy Privilege Escalation — Rancher CWE-441 9.1 Critical 2026-08-05
CVE-2026-25703 Potential information leakage from manager /network/graph API in NeuVector — NeuVector CWE-306 7.3 High 2026-08-05
CVE-2026-55998 Cluster Existence Oracle via Unauthenticated Import Endpoint — Rancher CWE-204 5.3 Medium 2026-08-05

This page lists every published CVE security advisory associated with SUSE. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.