suse has 11 CVEs on record between 2022 and 2026. Disclosure cadence is accelerating: 9 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 9. The median CVSS is 7.7 (high), with 2 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-639 (4). Most affected products: rancher (5), libXfont2-2 (2), manager (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.7
- Publish → KEV
- —
- Last 90 days
- 9 prev 0
Products
- rancher 5
- libXfont2-2 2
- manager 1
- manager_server 1
- pam-config 1
- rancher-extension-stackstate 1
Worst active — by depth score
CVE-2025-6018High· 7.8A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM)55CVE-2026-59679Critical· 9.0fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the…50CVE-2026-44950Critical· 9.0fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont250CVE-2026-71404High· 8.7A flaw was found in Rancher Manager48CVE-2026-75035High· 7.7A flaw was found in Rancher Manager42
suse vulnerabilities
CVEs affecting suse, newest first. Open any entry for full detail, references, and exploit status.
11 CVEsRSS
CVE-2026-44940Medium· 5.7The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely
The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access could obtain the token to gain unaut…
CVE-2026-59679Critical· 9.0fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the…
fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the…
CVE-2026-44950Critical· 9.0fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont2
fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer. It does…
CVE-2025-46808Medium· 6.8An Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive information into the manager container’s log This issue affects neuvector: before 5.4.5.
An Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive information into the manager container’s log This issue affects neuvector: before 5.4.5.
CVE-2026-75034High· 7.4A flaw was found in Rancher Manager
A flaw was found in Rancher Manager. The SAML assertion replay protection introduced by the fix for CVE-2026-44946 recorded consumed assertion IDs in a per-process cache, so each replica only detected replays that reached the same pod. I…
CVE-2026-75033High· 7.7A flaw was found in Rancher Manager
A flaw was found in Rancher Manager. Project Secrets were propagated into a namespace based only on its `field.cattle.io/projectId` annotation, without verifying that the referenced project belonged to the same downstream cluster. A user…
CVE-2026-71404High· 8.7A flaw was found in Rancher Manager
A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable `authz.management.cattle.io/cr-name` annotation and overwrote that object's rules without verifying ownership. A us…
CVE-2026-71403Medium· 6.1A flaw was found in Rancher Manager
A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a User resource's `username` and `principalIds` fields. A user holding the `update` verb on `users.management.cattle.io` could inject a foreig…
CVE-2026-75035High· 7.7A flaw was found in Rancher Manager
A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its internal owner filter instead of returning an empty result. Any authent…
CVE-2025-6018High· 7.8PoCA Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM)
A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM). This flaw allows an unprivileged local attacker (for example, a user logged in via SSH) to obtain the…
CVE-2022-21952High· 7.5A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS
A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS. This issue affects: SUS…