{"schema_version":1,"title":"Suse vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 43 vulnerabilities in Suse: 0 in the last 7 days and 27 in the last 90 days, 6 of them critical and 2 exploited in the wild. The most recent, CVE-2026-78427, was published on 17 September 2026. 6 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/suse","json_url":"https://junglewise.ai/threats/vendors/suse.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/suse","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":20,"all_time":43,"critical":6,"exploited":2,"last_7_days":0,"last_30_days":11,"last_90_days":27,"last_365_days":36},"latest":[{"cve":"CVE-2026-78427","cvss":4.3,"epss":0.0037,"slug":"cve-2026-78427-neuvector-admission-webhook-policy-bypass-via-hardcoded-sidecar","title":"NeuVector admission webhook policy bypass via hardcoded sidecar image exemption","severity":"medium","exploited":false,"published_at":"2026-09-17T10:17:03.637+00:00","url":"https://junglewise.ai/threats/cve-2026-78427-neuvector-admission-webhook-policy-bypass-via-hardcoded-sidecar"},{"cve":"CVE-2026-44940","cvss":5.7,"epss":0.0022,"slug":"cve-2026-44940-suse-observability-rancher-extension-service-token-exposure","title":"SUSE Observability Rancher Extension service token exposure","severity":"medium","exploited":false,"published_at":"2026-09-17T07:16:28.167+00:00","url":"https://junglewise.ai/threats/cve-2026-44940-suse-observability-rancher-extension-service-token-exposure"},{"cve":"CVE-2025-46808","cvss":6.8,"epss":0.002,"slug":"cve-2025-46808-suse-neuvector-manager-sensitive-information-insertion-into-logs","title":"SUSE NeuVector Manager sensitive information insertion into logs","severity":"medium","exploited":false,"published_at":"2026-09-09T09:17:10.013+00:00","url":"https://junglewise.ai/threats/cve-2025-46808-suse-neuvector-manager-sensitive-information-insertion-into-logs"},{"cve":"CVE-2026-75035","cvss":7.7,"epss":0.0034,"slug":"cve-2026-75035-rancher-manager-access-control-bypass-in-token-api","title":"Rancher Manager access control bypass in Token API","severity":"high","exploited":false,"published_at":"2026-09-03T16:18:22.477+00:00","url":"https://junglewise.ai/threats/cve-2026-75035-rancher-manager-access-control-bypass-in-token-api"},{"cve":"CVE-2026-75034","cvss":7.4,"epss":0.0032,"slug":"cve-2026-75034-rancher-manager-saml-assertion-replay-protection-bypass","title":"Rancher Manager SAML assertion replay protection bypass","severity":"high","exploited":false,"published_at":"2026-09-03T16:18:22.343+00:00","url":"https://junglewise.ai/threats/cve-2026-75034-rancher-manager-saml-assertion-replay-protection-bypass"},{"cve":"CVE-2026-75033","cvss":7.7,"epss":0.0034,"slug":"cve-2026-75033-rancher-manager-secret-propagation-bypass-via-namespace","title":"Rancher Manager secret propagation bypass via namespace annotation","severity":"high","exploited":false,"published_at":"2026-09-03T15:17:32.873+00:00","url":"https://junglewise.ai/threats/cve-2026-75033-rancher-manager-secret-propagation-bypass-via-namespace"},{"cve":"CVE-2026-71404","cvss":8.7,"epss":0.0042,"slug":"cve-2026-71404-rancher-manager-globalrole-controller-privilege-escalation","title":"Rancher Manager GlobalRole controller privilege escalation","severity":"high","exploited":false,"published_at":"2026-09-03T15:17:32.327+00:00","url":"https://junglewise.ai/threats/cve-2026-71404-rancher-manager-globalrole-controller-privilege-escalation"},{"cve":"CVE-2026-71403","cvss":6.1,"epss":0.0037,"slug":"cve-2026-71403-rancher-manager-privilege-escalation-via-user-identity-injection","title":"Rancher Manager privilege escalation via user identity injection","severity":"medium","exploited":false,"published_at":"2026-09-03T15:17:32.18+00:00","url":"https://junglewise.ai/threats/cve-2026-71403-rancher-manager-privilege-escalation-via-user-identity-injection"},{"cve":"CVE-2026-59681","cvss":8.8,"epss":0.0148,"slug":"cve-2026-59681-suse-yast2-auth-client-os-command-injection-in-active-directory","title":"SUSE YaST2 auth-client OS command injection in Active Directory configuration","severity":"high","exploited":false,"published_at":"2026-09-01T10:17:13.3+00:00","url":"https://junglewise.ai/threats/cve-2026-59681-suse-yast2-auth-client-os-command-injection-in-active-directory"},{"cve":"CVE-2026-59680","cvss":8,"epss":0.0158,"slug":"cve-2026-59680-suse-yast2-users-os-command-injection-in-password-settings","title":"SUSE yast2-users OS command injection in password settings","severity":"high","exploited":false,"published_at":"2026-09-01T10:17:13.16+00:00","url":"https://junglewise.ai/threats/cve-2026-59680-suse-yast2-users-os-command-injection-in-password-settings"},{"cve":"CVE-2026-25706","cvss":7.5,"epss":0.0048,"slug":"cve-2026-25706-suse-yast2-samba-client-command-injection-in-active-directory","title":"SUSE yast2-samba-client command injection in Active Directory join","severity":"high","exploited":false,"published_at":"2026-09-01T10:17:12.993+00:00","url":"https://junglewise.ai/threats/cve-2026-25706-suse-yast2-samba-client-command-injection-in-active-directory"},{"cve":"CVE-2025-8412","cvss":2,"slug":"cve-2025-8412-suse-virtual-machine-driver-pack-buffer-overflow-in","title":"SUSE Virtual Machine Driver Pack buffer overflow in RtlQueryRegistryValues","severity":"info","exploited":false,"published_at":"2026-07-14T09:16:39.637+00:00","url":"https://junglewise.ai/threats/cve-2025-8412-suse-virtual-machine-driver-pack-buffer-overflow-in"},{"cve":"CVE-2026-59674","cvss":7.1,"slug":"cve-2026-59674-suse-opensuse-tumbleweed-privilege-escalation-in-suricata-package","title":"SUSE openSUSE Tumbleweed privilege escalation in suricata package","severity":"info","exploited":false,"published_at":"2026-07-14T08:16:22.963+00:00","url":"https://junglewise.ai/threats/cve-2026-59674-suse-opensuse-tumbleweed-privilege-escalation-in-suricata-package"},{"cve":"CVE-2026-44938","cvss":8.8,"slug":"cve-2026-44938-suse-rancher-fleet-pod-security-standards-bypass-in-agent-side","title":"SUSE Rancher Fleet Pod Security Standards bypass in agent-side deployer","severity":"high","exploited":false,"published_at":"2026-07-07T14:16:30.69+00:00","url":"https://junglewise.ai/threats/cve-2026-44938-suse-rancher-fleet-pod-security-standards-bypass-in-agent-side"},{"cve":"CVE-2026-44937","cvss":7.5,"slug":"cve-2026-44937-suse-rancher-fleet-webhook-request-forgery-via-regex-injection","title":"SUSE Rancher Fleet webhook request forgery via regex injection","severity":"high","exploited":false,"published_at":"2026-07-06T11:16:27.727+00:00","url":"https://junglewise.ai/threats/cve-2026-44937-suse-rancher-fleet-webhook-request-forgery-via-regex-injection"},{"cve":"CVE-2026-44936","cvss":5,"slug":"cve-2026-44936-suse-rancher-fleet-credential-leak-via-unvalidated-helm","title":"SUSE Rancher Fleet credential leak via unvalidated Helm repository URL","severity":"medium","exploited":false,"published_at":"2026-07-06T11:16:27.61+00:00","url":"https://junglewise.ai/threats/cve-2026-44936-suse-rancher-fleet-credential-leak-via-unvalidated-helm"},{"cve":"CVE-2026-44934","cvss":7,"slug":"cve-2026-44934-suse-rancher-ai-agent-information-disclosure-in-debug-logs","title":"SUSE Rancher AI Agent information disclosure in debug logs","severity":"info","exploited":false,"published_at":"2026-07-06T09:16:36.17+00:00","url":"https://junglewise.ai/threats/cve-2026-44934-suse-rancher-ai-agent-information-disclosure-in-debug-logs"},{"cve":"CVE-2026-53362","cvss":6.2,"epss":0.0071,"slug":"cve-2026-53362-linux-kernel-buffer-overflow-in-ipv6-paged-allocation","title":"Linux Kernel buffer overflow in IPv6 paged allocation","severity":"critical","exploited":true,"published_at":"2026-07-04T12:17:02.113+00:00","url":"https://junglewise.ai/threats/cve-2026-53362-linux-kernel-buffer-overflow-in-ipv6-paged-allocation"},{"cve":"CVE-2026-44935","cvss":9.9,"slug":"cve-2026-44935-suse-rancher-fleet-improper-validation-in-helm-deployer","title":"SUSE Rancher Fleet improper validation in Helm Deployer","severity":"critical","exploited":false,"published_at":"2026-07-02T17:16:59.667+00:00","url":"https://junglewise.ai/threats/cve-2026-44935-suse-rancher-fleet-improper-validation-in-helm-deployer"},{"cve":"CVE-2026-44941","cvss":8.4,"slug":"cve-2026-44941-suse-libzypp-path-traversal-in-repomd-xml-keyhint-parsing","title":"SUSE libzypp path traversal in repomd.xml keyhint parsing","severity":"high","exploited":false,"published_at":"2026-07-02T16:16:30.55+00:00","url":"https://junglewise.ai/threats/cve-2026-44941-suse-libzypp-path-traversal-in-repomd-xml-keyhint-parsing"},{"cve":"CVE-2026-44948","cvss":5.3,"slug":"cve-2026-44948-suse-rancher-fleet-path-traversal-in-imagescan-subsystem","title":"SUSE Rancher Fleet path traversal in ImageScan subsystem","severity":"info","exploited":false,"published_at":"2026-06-30T16:16:52.607+00:00","url":"https://junglewise.ai/threats/cve-2026-44948-suse-rancher-fleet-path-traversal-in-imagescan-subsystem"},{"cve":"CVE-2026-44949","cvss":7,"slug":"cve-2026-44949-suse-rancher-webhook-rbac-injection-in-fleetworkspace","title":"SUSE Rancher Webhook RBAC injection in FleetWorkspace","severity":"info","exploited":false,"published_at":"2026-06-30T15:16:56.853+00:00","url":"https://junglewise.ai/threats/cve-2026-44949-suse-rancher-webhook-rbac-injection-in-fleetworkspace"},{"cve":"CVE-2026-44947","cvss":6.9,"slug":"cve-2026-44947-suse-rancher-improper-preservation-of-permissions-in-prtb","title":"SUSE Rancher improper preservation of permissions in PRTB reconciler","severity":"info","exploited":false,"published_at":"2026-06-30T15:16:56.727+00:00","url":"https://junglewise.ai/threats/cve-2026-44947-suse-rancher-improper-preservation-of-permissions-in-prtb"},{"cve":"CVE-2026-44946","cvss":9.5,"slug":"cve-2026-44946-suse-rancher-saml-authentication-replay-in-acs-handler","title":"SUSE Rancher SAML authentication replay in ACS handler","severity":"info","exploited":false,"published_at":"2026-06-30T13:18:42.19+00:00","url":"https://junglewise.ai/threats/cve-2026-44946-suse-rancher-saml-authentication-replay-in-acs-handler"},{"cve":"CVE-2026-41053","cvss":8.8,"epss":0.0037,"slug":"cve-2026-41053-suse-rancher-privilege-escalation-in-github-app-authentication","title":"SUSE Rancher privilege escalation in GitHub App authentication provider","severity":"high","exploited":false,"published_at":"2026-06-30T12:16:23.58+00:00","url":"https://junglewise.ai/threats/cve-2026-41053-suse-rancher-privilege-escalation-in-github-app-authentication"}],"vendor":{"hub":true,"name":"Suse","slug":"suse","homepage":"https://www.suse.com/","description":"SUSE is a global software company that develops and supports enterprise-grade Linux distributions and open-source infrastructure solutions.","url":"https://junglewise.ai/threats/vendors/suse"},"weekly":[{"week":"2026-06-29","critical":2,"exploited":1,"vulnerabilities":10},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":8},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2023-29552","cvss":7.5,"slug":"cve-2023-29552-service-location-protocol-slp-denial-of-service-vulnerability","title":"Service Location Protocol (SLP) Denial-of-Service Vulnerability","severity":"critical","exploited":true,"published_at":"2023-11-08T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-29552-service-location-protocol-slp-denial-of-service-vulnerability"},{"cve":"CVE-2026-53362","cvss":6.2,"epss":0.0071,"slug":"cve-2026-53362-linux-kernel-buffer-overflow-in-ipv6-paged-allocation","title":"Linux Kernel buffer overflow in IPv6 paged allocation","severity":"critical","exploited":true,"published_at":"2026-07-04T12:17:02.113+00:00","url":"https://junglewise.ai/threats/cve-2026-53362-linux-kernel-buffer-overflow-in-ipv6-paged-allocation"},{"cve":"CVE-2026-44935","cvss":9.9,"slug":"cve-2026-44935-suse-rancher-fleet-improper-validation-in-helm-deployer","title":"SUSE Rancher Fleet improper validation in Helm Deployer","severity":"critical","exploited":false,"published_at":"2026-07-02T17:16:59.667+00:00","url":"https://junglewise.ai/threats/cve-2026-44935-suse-rancher-fleet-improper-validation-in-helm-deployer"},{"cve":"CVE-2026-41050","cvss":9.9,"slug":"cve-2026-41050-rancher-fleet-helm-impersonation-bypass-in-restclientgetter","title":"Rancher Fleet Helm impersonation bypass in RESTClientGetter","severity":"critical","exploited":false,"published_at":"2026-05-13T08:16:16.78+00:00","url":"https://junglewise.ai/threats/cve-2026-41050-rancher-fleet-helm-impersonation-bypass-in-restclientgetter"},{"cve":"CVE-2025-8077","cvss":9.8,"epss":0.0052,"slug":"cve-2025-8077-suse-neuvector-insecure-default-password-for-admin-account","title":"SUSE NeuVector insecure default password for admin account","severity":"critical","exploited":false,"published_at":"2025-08-28T13:33:36+00:00","url":"https://junglewise.ai/threats/cve-2025-8077-suse-neuvector-insecure-default-password-for-admin-account"},{"cve":"CVE-2026-44939","cvss":9.6,"epss":0.0111,"slug":"cve-2026-44939-suse-rancher-command-injection-in-cluster-import-endpoint","title":"SUSE Rancher command injection in cluster import endpoint","severity":"critical","exploited":false,"published_at":"2026-06-19T13:16:30.583+00:00","url":"https://junglewise.ai/threats/cve-2026-44939-suse-rancher-command-injection-in-cluster-import-endpoint"},{"cve":"CVE-2026-59681","cvss":8.8,"epss":0.0148,"slug":"cve-2026-59681-suse-yast2-auth-client-os-command-injection-in-active-directory","title":"SUSE YaST2 auth-client OS command injection in Active Directory configuration","severity":"high","exploited":false,"published_at":"2026-09-01T10:17:13.3+00:00","url":"https://junglewise.ai/threats/cve-2026-59681-suse-yast2-auth-client-os-command-injection-in-active-directory"},{"cve":"CVE-2026-41053","cvss":8.8,"epss":0.0037,"slug":"cve-2026-41053-suse-rancher-privilege-escalation-in-github-app-authentication","title":"SUSE Rancher privilege escalation in GitHub App authentication provider","severity":"high","exploited":false,"published_at":"2026-06-30T12:16:23.58+00:00","url":"https://junglewise.ai/threats/cve-2026-41053-suse-rancher-privilege-escalation-in-github-app-authentication"},{"cve":"CVE-2026-44938","cvss":8.8,"slug":"cve-2026-44938-suse-rancher-fleet-pod-security-standards-bypass-in-agent-side","title":"SUSE Rancher Fleet Pod Security Standards bypass in agent-side deployer","severity":"high","exploited":false,"published_at":"2026-07-07T14:16:30.69+00:00","url":"https://junglewise.ai/threats/cve-2026-44938-suse-rancher-fleet-pod-security-standards-bypass-in-agent-side"},{"cve":"CVE-2026-25707","cvss":8.8,"slug":"cve-2026-25707-suse-libzypp-path-traversal-in-repository-metadata-processing","title":"SUSE libzypp path traversal in repository metadata processing","severity":"high","exploited":false,"published_at":"2026-06-29T10:16:30.33+00:00","url":"https://junglewise.ai/threats/cve-2026-25707-suse-libzypp-path-traversal-in-repository-metadata-processing"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"Suse Fleet","slug":"fleet","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/fleet"},{"name":"Suse Rancher","slug":"rancher","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/rancher"},{"name":"Suse NeuVector","slug":"neuvector","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/neuvector"},{"name":"Suse Libzypp","slug":"libzypp","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/libzypp"},{"name":"Suse Linux Enterprise Server","slug":"linux-enterprise-server","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/linux-enterprise-server"},{"name":"Suse Rancher Manager","slug":"rancher-manager","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/rancher-manager"}]}