Skip to content
Critical CVE Fixes for Fedora NetworkManager Plugins Released

Critical CVE Fixes for Fedora NetworkManager Plugins Released

First seen 29 Sep 2026, 03:07 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 05:09 UTC
  • •Critical vulnerabilities in Fedora NetworkManager plugins require immediate patching.
  • •CISA confirmed active exploitation of these vulnerabilities in the wild.
  • •Affected systems include Fedora 43, 44, and 45 with specific CVEs identified.

On September 29, 2026, Fedora released critical updates for NetworkManager-l2tp and NetworkManager-iodine plugins to address vulnerabilities CVE-2026-75131, CVE-2026-93337, and CVE-2026-91837. These vulnerabilities could allow local privilege escalation and exploitation of firewall flaws, affecting Fedora 43, 44, and 45 systems. CISA confirmed that these issues are being actively exploited in the wild, prompting urgent action from system administrators. Users are advised to apply the updates immediately using the dnf package manager. The updates were published in response to confirmed exploitation attempts targeting these vulnerabilities. The patches are crucial for maintaining the security of VPN connections integrated with NetworkManager.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-17
CVE-2026-93337 published
A vulnerability affecting NetworkManager-l2tp was disclosed, allowing potential exploitation.
Linuxsecurity
2026-09-23
CVE-2026-75131 published
Another critical vulnerability in NetworkManager-l2tp was disclosed, heightening security risks.
Linuxsecurity
2026-09-25
CVE-2026-91837 published
A local privilege escalation vulnerability in NetworkManager-iodine was disclosed, affecting multiple Fedora versions.
Linuxsecurity
2026-09-29
Critical updates released for Fedora
Fedora released updates for NetworkManager-l2tp and NetworkManager-iodine to address critical vulnerabilities.
Linuxsecurity

More articles in this cluster (6)

Following this threat?

Track CVE-2026-75131 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed