Linuxsecurity SUSE and openSUSE Address Vulnerabilities in Google-Guest-Agent
Article Content
- •SUSE and openSUSE released updates for google-guest-agent addressing critical vulnerabilities.
- •Key vulnerabilities include CVE-2026-33814 and CVE-2026-33186, which could lead to unauthorized access.
- •Users are urged to update their systems to the latest versions to mitigate security risks.
SUSE and openSUSE have released important security updates for the google-guest-agent. The updates address multiple vulnerabilities, including CVE-2026-33814 and CVE-2026-33186, which were published on May 7, 2026, and March 20, 2026, respectively. The updates include dependency updates and fixes for telemetry features. Affected systems include SUSE Linux Enterprise and openSUSE Tumbleweed. The vulnerabilities could potentially allow unauthorized access or information disclosure. Users are advised to update to the latest versions to mitigate risks. The updates were released on June 3, 2026, and are rated important for SUSE and moderate for openSUSE. The updates reflect ongoing efforts to secure the guest agent software used in cloud environments.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (8)
Following this threat?
Track OpenSUSE and CVE-2025-22868 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…