Moderate Vulnerability in wget Affects SUSE Systems

Moderate Vulnerability in wget Affects SUSE Systems

First seen 8 Sep 2026, 12:03 UTC Linuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

A moderate vulnerability identified as CVE-2026-16599 has been discovered in wget, allowing for a server-controlled unbounded MD5 loop in FTP OPIE. This issue affects multiple SUSE Linux systems, including SUSE Linux Enterprise Server 15 SP7 and SUSE Linux Enterprise Micro 5.5. The vulnerability was published on August 25, 2026, and has been assigned a CVSS score of 4.0. Users are advised to apply the latest patches using SUSE's recommended installation methods. The patches are available for various architectures including aarch64, ppc64le, s390x, and x86_64. Both articles emphasize the importance of keeping systems updated to mitigate this vulnerability. The patches were released on September 7, 2026, shortly before the articles were published.

Key Points: • CVE-2026-16599 affects wget in SUSE systems. • The vulnerability allows for a server-controlled unbounded MD5 loop. • Patches are available for multiple SUSE Linux architectures.

Ask AI about this cluster

Timeline

2026-08-25
CVE-2026-16599 published
A vulnerability in wget was disclosed, allowing for a server-controlled unbounded MD5 loop in FTP OPIE.
Linuxsecurity
2026-09-07
Patches released for wget
SUSE released updates to fix the CVE-2026-16599 vulnerability for various Linux systems.
Linuxsecurity
2026-09-07
Second patch released for SUSE Micro
An additional patch for SUSE Linux Enterprise Micro 5.5 was also released to address the same vulnerability.
Linuxsecurity