Skip to content
Critical Vulnerabilities in openSUSE erlang27 Require Immediate Attention

Critical Vulnerabilities in openSUSE erlang27 Require Immediate Attention

First seen 29 Sep 2026, 03:07 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 05:09 UTC
  • •Multiple critical vulnerabilities in openSUSE erlang27 require urgent patching.
  • •CISA confirms active exploitation of these vulnerabilities.
  • •Affected systems include openSUSE Leap 15.3 across various architectures.

On September 29, 2026, openSUSE released an update addressing multiple vulnerabilities in erlang27, including CVE-2026-42792, which allows for a permanent denial of service (DoS) via EMFILE on accept(2) in erts. Other vulnerabilities include CVE-2026-47078, a relative path traversal issue, and CVE-2026-48855, which exposes sensitive information through the ssh_sftpd module. CVE-2026-48856 allows for sensitive data exposure via the httpc_response module. The vulnerabilities affect various architectures of openSUSE Leap 15.3. CISA has confirmed that these vulnerabilities are being actively exploited, urging users to apply the patches immediately. The update is critical for maintaining the security of systems running this software.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-10
CVE-2026-48858 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-10
CVE-2026-48855 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-10
CVE-2026-48860 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-10
CVE-2026-48856 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-27
CVE-2026-47078 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-27
CVE-2026-42792 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-29
openSUSE erlang27 update released
An update was released to fix critical vulnerabilities including CVE-2026-42792 and CVE-2026-47078, affecting openSUSE Leap 15.3.
Linuxsecurity
2026-09-29
CISA confirms exploitation
CISA confirmed that the vulnerabilities in openSUSE erlang27 are being actively exploited in the wild.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track CVE-2026-42792 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed