Multiple SUSE yast2-users Vulnerabilities Addressed in September 2026 Updates

Multiple SUSE yast2-users Vulnerabilities Addressed in September 2026 Updates

First seen 3 Sep 2026, 17:39 UTC Linuxsecurity 60.8

Article Content

Browse articles
ThreatCluster

On September 1, 2026, SUSE released updates addressing a critical OS command injection vulnerability (CVE-2026-59680) affecting yast2-users. This vulnerability allows attackers to exploit LDAP-supplied attributes, potentially leading to unauthorized command execution. Multiple versions of SUSE Linux Enterprise Server and openSUSE are affected, with updates released for versions 12 SP5, 15 SP4, 15 SP5, 15 SP6, and 15 SP7. The updates are crucial for maintaining system security and preventing exploitation. Another vulnerability, CVE-2026-37458, related to the Quagga routing software, was also disclosed, allowing for denial-of-service attacks. The updates are rated important, and users are urged to apply them promptly to mitigate risks.

Key Points: • CVE-2026-59680 allows OS command injection via LDAP attributes. • Multiple SUSE and openSUSE versions are affected, requiring urgent updates. • CVE-2026-37458 poses a DoS threat in Quagga software.

Timeline

2026-05-04
CVE-2026-37458 published
SUSE disclosed a DoS vulnerability in Quagga affecting multiple versions.
Linuxsecurity
2026-09-01
CVE-2026-59680 published
SUSE announced a critical OS command injection vulnerability in yast2-users.
Linuxsecurity
2026-09-03
SUSE releases patches for yast2-users
Updates released for multiple SUSE versions to address CVE-2026-59680.
Linuxsecurity