Linuxsecurity Multiple High-Risk Vulnerabilities Discovered in Gentoo Linux Packages
Article Content
- •Multiple high-severity vulnerabilities identified in Gentoo Linux packages.
- •Affected packages include libssh2, acl, attr, quickjs-ng, and Emacs.
- •No known workarounds; users urged to apply updates promptly.
On August 20, 2026, Gentoo Linux announced multiple high-severity vulnerabilities affecting various packages, including libssh2, acl, attr, quickjs-ng, and Emacs. The vulnerabilities allow for high remote code execution risks, impacting users running these packages. Specific CVEs include CVE-2025-15661, CVE-2026-7598, CVE-2026-54369, CVE-2026-54370, CVE-2026-54371, CVE-2026-55199, CVE-2026-55200, CVE-2026-0821, CVE-2026-1144, and CVE-2026-1145. No known workarounds are available, and users are advised to monitor for updates. The vulnerabilities were disclosed in advisories published on the same day, indicating an urgent need for remediation. The scope of impact includes all systems utilizing the affected packages, emphasizing the critical nature of the vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Following this threat?
Track CVE-2025-15661 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…