Linuxsecurity Critical Vulnerabilities in Terraform Providers Affecting openSUSE and Ubuntu Server
Article Content
- •CVE-2026-25934 and CVE-2026-33186 are critical vulnerabilities in Terraform providers.
- •CVE-2026-33186 has a CVSS score of 9.1, indicating a high risk of exploitation.
- •Users of openSUSE and Ubuntu Server are urged to apply patches immediately.
Recent updates for terraform-provider-local, terraform-provider-random, and terraform-provider-tls address two critical vulnerabilities: CVE-2026-25934 and CVE-2026-33186. CVE-2026-25934, published on 2026-02-09, involves improper verification of data integrity for `.pack` and `.idx` files, potentially leading to the consumption of corrupted files. CVE-2026-33186, published on 2026-03-20, relates to improper validation of the HTTP/2 `:path` pseudo-header, which can result in authorization bypass. Both vulnerabilities affect openSUSE Leap 15.6 and Public Cloud Modules 15-SP4 and 15-SP5. The first public proof of concept for CVE-2026-33186 was released on 2026-04-07, raising the urgency for patching. Users are advised to apply the latest updates using SUSE's recommended installation methods. The vulnerabilities have varying CVSS scores, with CVE-2026-33186 rated as high as 9.1, indicating a significant risk. Immediate action is recommended to mitigate potential exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track OpenSUSE and CVE-2026-25934 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…