CVE-2026-44950fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont2 Exploitation status Not known exploited Fix YesAffected product C Container suse/kiosk/tigervnc-x11vnc:1.14-63.8 Published 09/10/2026 Severity Critical CVE-2026-59679fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont2 Exploitation status Not known exploited Fix YesAffected product C Container suse/kiosk/tigervnc-x11vnc:1.14-63.8 Published 09/10/2026 Severity Critical CVE-2025-46808Sensitive information is leaked into NeuVector’s manager container logs Exploitation status Not known exploited Fix YesAffected product N neuvector Published 09/09/2026 Severity Medium CVE-2026-75036Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessing Exploitation status Not known exploited Fix YesAffected product F Fleet Published 09/03/2026 Severity Medium CVE-2026-75035Rancher: ext.cattle.io/v1 Token store: cross-user token disclosure via label-selector scoping bypass Exploitation status Not known exploited Fix YesAffected product R rancher Published 09/03/2026 Severity High CVE-2026-75034Rancher: SAML Assertion Replay Exploitation status Not known exploited Fix YesAffected product R rancher Published 09/03/2026 Severity High CVE-2026-75033Rancher: Cross-Cluster Secret Leakage via Namespace projectId Annotation Spoofing Exploitation status Not known exploited Fix YesAffected product R rancher Published 09/03/2026 Severity High CVE-2026-71404Rancher: Ownership-less ClusterRole overwrite via attacker-controlled cr-name annotation on GlobalRole Exploitation status Not known exploited Fix YesAffected product R rancher Published 09/03/2026 Severity High CVE-2026-71403Rancher: Identity-field mutation in /v3/users allows account hijack via principal rebind Exploitation status Not known exploited Fix YesAffected product R rancher Published 09/03/2026 Severity Medium CVE-2026-25706yast2-samba-client: OS command injection via attacker-controlled Organizational Unit (Active Directory-supplied) Exploitation status Not known exploited Fix YesAffected product Y yast2-samba-client Published 09/01/2026 Severity High CVE-2026-59681yast2-auth-client: OS command injection via unsanitized Organizational Unit / dnsHostName in AD join Exploitation status Not known exploited Fix YesAffected product Y yast2-auth-client Published 09/01/2026 Severity High CVE-2026-59680yast2-users: OS command injection via LDAP-supplied shadowLastChange/shadowExpire attribute Exploitation status Not known exploited Fix YesAffected product Y yast2-users Published 09/01/2026 Severity High CVE-2026-71402wicked: out-of-bounds read in the DHCPv4 option parser due to payload length taken from the IP total length Exploitation status Not known exploited Fix YesAffected product W wicked Published 08/27/2026 Severity Medium CVE-2026-71401wicked: integer underflow of the UDP length in ni_capture_inspect_udp_header() leads to an out-of-bounds read Exploitation status Not known exploited Fix YesAffected product W wicked Published 08/27/2026 Severity Medium CVE-2026-44945Cross-Cluster Impersonation Confused-Deputy Privilege Escalation Exploitation status Not known exploited Fix YesAffected product R rancher Published 08/05/2026 Severity Critical CVE-2026-25703Potential information leakage from manager /network/graph API in NeuVector Exploitation status Not known exploited Fix YesAffected product N neuvector Published 08/05/2026 Severity High CVE-2026-55998Cluster Existence Oracle via Unauthenticated Import Endpoint Exploitation status Not known exploited Fix YesAffected product R rancher Published 08/05/2026 Severity Medium CVE-2026-59675Rancher Audit-Log Middleware Unauthenticated Memory Exhaustion Denial of Service Exploitation status Not known exploited Fix YesAffected product R rancher Published 08/05/2026 Severity High CVE-2026-55996Unauthenticated Denial-of-Service via TLS SAN Stuffing in Rancher and cattle-cluster-agent Exploitation status Not known exploited Fix YesAffected product R rancher Published 08/05/2026 Severity Medium CVE-2025-8412VMDP: Potential buffer overflow in the RtlQueryRegistryValues function Exploitation status Not known exploited Fix YesAffected product V Virtual Machine Driver Pack Published 07/14/2026 Severity Low CVE-2026-59674LPE from suricata user to root due to chown in %post in suricata packaging Exploitation status Not known exploited Fix YesAffected product O openSUSE Tumbleweed Published 07/14/2026 Severity High CVE-2026-44938Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent Exploitation status Not known exploited Fix YesAffected product R rancher Published 07/07/2026 Severity High CVE-2026-44937SUSE Rancher Fleet had an Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components Exploitation status Not known exploited Fix YesAffected product R rancher Published 07/06/2026 Severity High CVE-2026-44936Rancher Fleet SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml Exploitation status Not known exploited Fix YesAffected product R rancher Published 07/06/2026 Severity Medium CVE-2026-44934Exposed tokens in SUSE Rancher AI Agent logs Exploitation status Not known exploited Fix YesAffected product R rancher Published 07/06/2026 Severity High CVE-2026-44935Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer Exploitation status Not known exploited Fix YesAffected product R rancher Published 07/02/2026 Severity Critical CVE-2026-44941libzypp path traversal via "keyhint" in repomd.xml Exploitation status Not known exploited Fix YesAffected product L libzypp Published 07/02/2026 Severity High CVE-2026-44948Path Traversal in Rancher Fleet ImageScan GitRepo Path Handler Exploitation status Not known exploited Fix YesAffected product R rancher Published 06/30/2026 Severity Medium CVE-2026-44949Unauthenticated namespace creation and RBAC injection via rancher-webhook FleetWorkspace mutating webhook Exploitation status Not known exploited Fix YesAffected product R rancher Published 06/30/2026 Severity High CVE-2026-44947Stale PSA ClusterRoleBinding Persists After RoleTemplate Downgrade in Rancher Exploitation status Not known exploited Fix YesAffected product R rancher Published 06/30/2026 Severity Medium CVE-2026-44946SAML Authentication Replay in Rancher Exploitation status Not known exploited Fix YesAffected product R rancher Published 06/30/2026 Severity Critical CVE-2026-41053Over-inclusive team membership expansion in GitHub App authentication provider for Rancher Exploitation status Not known exploited Fix YesAffected product R rancher Published 06/30/2026 Severity High CVE-2026-41052Rancher Privilege Escalation from Project Owner to Host Exploitation status Not known exploited Fix YesAffected product R rancher Published 06/29/2026 Severity Critical CVE-2026-25707Handcrafted repo metadata may cause arbitrary local files to be overwritten by libzypp Exploitation status Not known exploited Fix YesAffected product L libzypp Published 06/29/2026 Severity High CVE-2026-44939Command injection through unsanitized YAML parameter in Rancher Exploitation status Not known exploited Fix YesAffected product R rancher Published 06/19/2026 Severity Critical CVE-2026-44942libzypp .repo files can have an optional path which can lead to path traversal attacks Exploitation status Not known exploited Fix YesAffected product L libzypp Published 06/18/2026 Severity Medium CVE-2025-71261Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS Exploitation status Not known exploited Fix YesAffected product H harvester Published 06/16/2026 Severity High CVE-2026-44932indirect remote shell command injection via unsanitized DHCP options in wicked Exploitation status Not known exploited Fix YesAffected product W wicked Published 06/16/2026 Severity High CVE-2026-44543Local Path Provisioner: HelperPod Template Injection Exploitation status Not known exploited Fix YesAffected product L local-path-provisioner Published 05/28/2026 Severity High CVE-2026-41054Missing exit out of permission check in haveged could lead to root exploit Exploitation status Not known exploited Fix YesAffected product C Container suse/sle-micro-rancher/5.3:latest Published 05/20/2026 Severity High CVE-2026-44933Path Traversal in Plugin Loading in libzypp Exploitation status Not known exploited Fix YesAffected product S SUSE Linux Enterprise Published 05/20/2026 Severity High CVE-2026-41051csync2 uses insecure temporary directories when compiled with C99 or later Exploitation status Not known exploited Fix YesAffected product O openSUSE Tumbleweed Published 05/13/2026 Severity Medium CVE-2026-41050Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering Exploitation status Not known exploited Fix YesAffected product R rancher Published 05/13/2026 Severity Critical CVE-2026-25705Rancher Extensions have arbitrary file access via path traversal Exploitation status Not known exploited Fix YesAffected product R rancher Published 05/13/2026 Severity High CVE-2026-31431crypto: algif_aead - Revert to operating out-of-place Exploitation status KEV Fix YesAffected product L Linux Published 04/22/2026 Severity High CVE-2026-25702nftables disabled due to incorrect kernel backport Exploitation status Not known exploited Fix YesAffected product S SUSE Linux Enterprise Server Published 03/05/2026 Severity High CVE-2025-62879Rancher Backup Operator pod's logs leak S3 tokens Exploitation status Not known exploited Fix YesAffected product R rancher Published 03/04/2026 Severity Medium CVE-2025-62878Local Path Provisioner vulnerable to Path Traversal via parameters.pathPattern Exploitation status Not known exploited Fix YesAffected product R rancher Published 02/25/2026 Severity Critical CVE-2025-67601Rancher CLI skips TLS verification on Rancher CLI login command Exploitation status Not known exploited Fix YesAffected product R rancher Published 02/25/2026 Severity High CVE-2025-67860NeuVector scanner insecurely handles passwords as command arguments Exploitation status Not known exploited Fix YesAffected product H harvester Published 02/25/2026 Severity Low CVE-2025-62877Harvest may expose OS default ssh login password via SUSE Virtualization Interactive Installer Exploitation status Not known exploited Fix Not confirmed Affected product H harvester Published 01/08/2026 Severity Critical CVE-2025-66001NeuVector OpenID Connect is vulnerable to man-in-the-middle (MITM) Exploitation status Not known exploited Fix YesAffected product N neuvector Published 01/08/2026 Severity High CVE-2025-62875Local DoS in OpenSMTPD via UNIX domain socket smtpd.sock Exploitation status Public exploit Fix YesAffected product O openSUSE Tumbleweed Published 11/20/2025 Severity Medium CVE-2025-62876CVE-2025-62876 Exploitation status Not known exploited Fix YesAffected product O openSUSE Published 11/12/2025 Severity Medium CVE-2025-53883spacewalk-java has various XSS issues on search page Exploitation status Not known exploited Fix YesAffected product C Container suse manager 5.0 Published 10/30/2025 Severity Critical CVE-2025-53880susemanager-tftpsync-recv allows arbitrary file creation and deletion due to path traversal Exploitation status Not known exploited Fix YesAffected product C Container suse/manager/4.3/proxy-httpd:latest Published 10/30/2025 Severity High CVE-2025-54471NeuVector is shipping cryptographic material into its binary Exploitation status Not known exploited Fix YesAffected product N neuvector Published 10/30/2025 Severity Medium CVE-2025-54469NeuVector Enforcer is vulnerable to Command Injection and Buffer overflow Exploitation status Not known exploited Fix YesAffected product N neuvector Published 10/30/2025 Severity Critical CVE-2025-54470NeuVector telemetry sender is vulnerable to MITM and DoS Exploitation status Not known exploited Fix YesAffected product N neuvector Published 10/30/2025 Severity High CVE-2024-58269Rancher exposes sensitive information through audit logs Exploitation status Not known exploited Fix YesAffected product R rancher Published 10/29/2025 Severity Medium CVE-2023-32199Rancher user retains access to clusters despite Global Role removal Exploitation status Not known exploited Fix YesAffected product R rancher Published 10/29/2025 Severity Medium CVE-2024-58260Rancher update on users can deny the service to the admin Exploitation status Not known exploited Fix YesAffected product R rancher Published 10/02/2025 Severity High CVE-2024-58267Rancher CLI SAML authentication is vulnerable to phishing attacks Exploitation status Not known exploited Fix YesAffected product R rancher Published 10/02/2025 Severity High CVE-2025-54468Rancher sends sensitive information to external services through the `/meta/proxy` endpoint Exploitation status Not known exploited Fix YesAffected product R rancher Published 10/02/2025 Severity Medium CVE-2025-8077NeuVector admin account has insecure default password Exploitation status Not known exploited Fix YesAffected product N neuvector Published 09/17/2025 Severity Critical CVE-2025-54467NeuVector process with sensitive arguments lead to leakage Exploitation status Not known exploited Fix YesAffected product N neuvector Published 09/17/2025 Severity Medium CVE-2025-53884NeuVector has an insecure password storage vulnerable to rainbow attack Exploitation status Not known exploited Fix YesAffected product N neuvector Published 09/17/2025 Severity Medium CVE-2024-58259Rancher affected by unauthenticated Denial of Service Exploitation status Not known exploited Fix YesAffected product R rancher Published 09/02/2025 Severity High CVE-2024-52284Rancher Fleet Helm Values are stored inside BundleDeployment in plain text Exploitation status Not known exploited Fix YesAffected product R rancher Published 09/02/2025 Severity High CVE-2025-46809Multi Linux Manager epxoses the plain text HTTP Proxy user:password in logs Exploitation status Not known exploited Fix YesAffected product C Container suse/manager/4.3/proxy-httpd:4.3.16.9.67.1 Published 07/31/2025 Severity Medium CVE-2025-46811SUSE Multi Linux Manager allows code execution via unprotected websocket endpoint Exploitation status Not known exploited Fix YesAffected product C Container suse/manager/5.0/x86_64/server:5.0.5.7.30.1 Published 07/30/2025 Severity Critical CVE-2025-6018Pam-config: lpe from unprivileged to allow_active in pam Exploitation status Public exploit Fix YesAffected product P pam Published 07/23/2025 Severity High CVE-2025-53882The logrotate configuration in the python-mailman of openSUSE allows the mailman user to sent SIGHUP to arbitrary proceess Exploitation status Not known exploited Fix YesAffected product O openSUSE Tumbleweed Published 07/23/2025 Severity Medium CVE-2025-32463CVE-2025-32463 Exploitation status KEV Fix YesAffected product S Sudo Published 06/30/2025 Severity Critical CVE-2025-23393Reflected XSS in spacewalk-java Exploitation status Not known exploited Fix YesAffected product C Container suse/manager/5.0/x86_64/server:5.0.4.7.19.1 Published 05/27/2025 Severity Medium CVE-2025-23392Reflected XSS in SystemsController.java in spacewalk-java Exploitation status Not known exploited Fix YesAffected product C Container suse/manager/5.0/x86_64/server:5.0.4.7.19.1 Published 05/26/2025 Severity Medium CVE-2025-23394daily-backup.sh script in cyrus-imapd allows escalation from cyrus to root Exploitation status Not known exploited Fix YesAffected product O openSUSE Tumbleweed Published 05/26/2025 Severity Critical CVE-2025-46802Temporary chown() of users' TTY to mode 0666 allows PTY hijacking in screen Exploitation status Public exploit Fix YesAffected product S SUSE Linux Enterprise Micro 5.3 Published 05/26/2025 Severity Medium CVE-2023-32197Rancher's External RoleTemplates can lead to privilege escalation Exploitation status Not known exploited Fix YesAffected product R rancher Published 04/16/2025 Severity High CVE-2024-22036Rancher Remote Code Execution via Cluster/Node Drivers Exploitation status Not known exploited Fix YesAffected product R rancher Published 04/16/2025 Severity Critical CVE-2024-52281Stored Cross-site Scripting vulnerability in Rancher UI Exploitation status Not known exploited Fix YesAffected product R rancher Published 04/16/2025 Severity High CVE-2024-52280Users can issue watch commands for arbitrary resources Exploitation status Not known exploited Fix YesAffected product R rancher Published 04/11/2025 Severity High CVE-2024-52282Rancher Helm Applications may have sensitive values leaked Exploitation status Not known exploited Fix YesAffected product R rancher Published 04/11/2025 Severity Medium CVE-2025-23387Rancher's SAML-based login via CLI can be denied by unauthenticated users Exploitation status Not known exploited Fix YesAffected product R rancher Published 04/11/2025 Severity Medium CVE-2025-23388Unauthenticated stack overflow in /v3-public/authproviders API Exploitation status Not known exploited Fix YesAffected product R rancher Published 04/11/2025 Severity High CVE-2025-23389Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First Login Exploitation status Not known exploited Fix YesAffected product R rancher Published 04/11/2025 Severity High CVE-2025-23391Rancher: Restricted Administrator can change Administrator's passwords Exploitation status Not known exploited Fix YesAffected product R rancher Published 04/11/2025 Severity Critical CVE-2025-23386gerbera: Privilege escalation from user gerbera to root because of insecure %post script Exploitation status Not known exploited Fix YesAffected product O openSUSE Tumbleweed Published 04/10/2025 Severity High CVE-2024-12087Rsync: path traversal vulnerability in rsync Exploitation status Public exploit Fix YesAffected product R rsync Published 01/14/2025 Severity Medium CVE-2024-12086Rsync: rsync server leaks arbitrary client files Exploitation status Public exploit Fix YesAffected product R rsync Published 01/14/2025 Severity Medium CVE-2024-12085Rsync: info leak via uninitialized stack contents Exploitation status Public exploit Fix YesAffected product R rsync Published 01/14/2025 Severity High CVE-2024-22037Database password leaked by systemd uyuni-server-attestation service Exploitation status Not known exploited Fix YesAffected product S SUSE Manager Server 5.0 Published 11/28/2024 Severity Medium CVE-2024-22038DoS attacks, information leaks etc. with crafted Git repositories in obs-scm-bridge Exploitation status Not known exploited Fix YesAffected product O openSUSE Factory Published 11/28/2024 Severity Medium CVE-2024-49502Reflected XSS in Setup Wizard, HTTP Proxy credentials pane in spacewalk-web Exploitation status Not known exploited Fix YesAffected product C Container suse/manager/5.0/x86_64/server:5.0.2.7.8.1 Published 11/28/2024 Severity Medium CVE-2024-49503Reflected XSS in Setup Wizard, Organization Credentials in spacewalk-web Exploitation status Not known exploited Fix YesAffected product C Container suse/manager/5.0/x86_64/server:5.0.2.7.8.1 Published 11/28/2024 Severity Medium CVE-2024-52283CVE-2024-52283 Exploitation status Not known exploited Fix YesAffected product H hackweek Published 11/28/2024 Severity Medium CVE-2024-49504grub2 allows bypassing TPM-bound disk encryption on SL(E)M encrypted Images Exploitation status Not known exploited Fix YesAffected product O openSUSE Tumbleweed Published 11/13/2024 Severity High CVE-2022-45157Exposure of vSphere's CPI and CSI credentials in Rancher Exploitation status Not known exploited Fix YesAffected product R rancher Published 11/13/2024 Severity High CVE-2024-46953CVE-2024-46953 Exploitation status Not known exploited Fix Not confirmed Affected product Not confirmed Published 11/10/2024 Severity High CVE-2024-46955CVE-2024-46955 Exploitation status Not known exploited Fix Not confirmed Affected product Not confirmed Published 11/10/2024 Severity Medium