VulnSea

SUSE has 11 CVEs on record between 2022 and 2026. Disclosure cadence is accelerating: 9 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 9. The median CVSS is 7.7 (high), with 2 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-639 (4). Most affected products: rancher (5), libXfont2-2 (2), manager (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.7
Publish → KEV
Last 90 days
9 prev 0

Products

  • rancher 5
  • libXfont2-2 2
  • manager 1
  • manager_server 1
  • pam-config 1
  • rancher-extension-stackstate 1
11
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

SUSE vulnerabilities

CVEs affecting SUSE, newest first. Open any entry for full detail, references, and exploit status.

11 CVEsRSS

CVE-2026-44940Medium· 5.7
5d ago

The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely

The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access could obtain the token to gain unaut…

SunlitSUSE · rancher-extension-stackstateEPSS 0.13%via NVD
CVE-2026-59679Critical· 9.0
1w ago

fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the…

fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the…

MidnightSUSE · libXfont2-2EPSS 0.41%via NVD
CVE-2026-44950Critical· 9.0
1w ago

fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont2

fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer. It does…

MidnightSUSE · libXfont2-2EPSS 0.44%via CVEORG
CVE-2025-46808Medium· 6.8
1w ago

An Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive information into the manager container’s log This issue affects neuvector: before 5.4.5.

An Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive information into the manager container’s log This issue affects neuvector: before 5.4.5.

SunlitSUSE · managerEPSS 0.20%via NVD
CVE-2026-75034High· 7.4
2w ago

A flaw was found in Rancher Manager

A flaw was found in Rancher Manager. The SAML assertion replay protection introduced by the fix for CVE-2026-44946 recorded consumed assertion IDs in a per-process cache, so each replica only detected replays that reached the same pod. I…

Twilightsuse · rancherEPSS 0.20%via NVD
CVE-2026-75033High· 7.7
2w ago

A flaw was found in Rancher Manager

A flaw was found in Rancher Manager. Project Secrets were propagated into a namespace based only on its `field.cattle.io/projectId` annotation, without verifying that the referenced project belonged to the same downstream cluster. A user…

Twilightsuse · rancherEPSS 0.21%via NVD
CVE-2026-71404High· 8.7
2w ago

A flaw was found in Rancher Manager

A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable `authz.management.cattle.io/cr-name` annotation and overwrote that object's rules without verifying ownership. A us…

Twilightsuse · rancherEPSS 0.24%via NVD
CVE-2026-71403Medium· 6.1
2w ago

A flaw was found in Rancher Manager

A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a User resource's `username` and `principalIds` fields. A user holding the `update` verb on `users.management.cattle.io` could inject a foreig…

Sunlitsuse · rancherEPSS 0.21%via NVD
CVE-2026-75035High· 7.7
2w ago

A flaw was found in Rancher Manager

A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its internal owner filter instead of returning an empty result. Any authent…

Twilightsuse · rancherEPSS 0.20%via NVD
CVE-2025-6018High· 7.8PoC
1y ago

A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM)

A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM). This flaw allows an unprivileged local attacker (for example, a user logged in via SSH) to obtain the…

Midnightsuse · pam-configEPSS 1.0%via NVD
CVE-2022-21952High· 7.5
4y ago

A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS

A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS. This issue affects: SUS…

Twilightsuse · manager_serverEPSS 1.5%via NVD
SUSE vulnerabilities (CVEs) · VulnSea