Linuxsecurity
Multiple SUSE yast2-users Vulnerabilities Addressed in September 2026 Updates
Article Content
On September 1, 2026, SUSE released updates addressing a critical OS command injection vulnerability (CVE-2026-59680) affecting yast2-users. This vulnerability allows attackers to exploit LDAP-supplied attributes, potentially leading to unauthorized command execution. Multiple versions of SUSE Linux Enterprise Server and openSUSE are affected, with updates released for versions 12 SP5, 15 SP4, 15 SP5, 15 SP6, and 15 SP7. The updates are crucial for maintaining system security and preventing exploitation. Another vulnerability, CVE-2026-37458, related to the Quagga routing software, was also disclosed, allowing for denial-of-service attacks. The updates are rated important, and users are urged to apply them promptly to mitigate risks.
Key Points: • CVE-2026-59680 allows OS command injection via LDAP attributes. • Multiple SUSE and openSUSE versions are affected, requiring urgent updates. • CVE-2026-37458 poses a DoS threat in Quagga software.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.