Skip to content
SUSE Patches Critical Auth Bypass and DoS Vulnerabilities

SUSE Patches Critical Auth Bypass and DoS Vulnerabilities

First seen 28 Sep 2026, 19:09 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 20:08 UTC

SUSE has released important security updates for its google-osconfig-agent and google-guest-agent due to multiple vulnerabilities. The updates address CVE-2026-41178, which allows denial-of-service (DoS) attacks via oversized inputs, and CVE-2026-33186, which enables authorization bypass through improper HTTP/2 header validation. Additionally, CVE-2026-56854 and CVE-2026-56855, affecting the golang.org/x/crypto/ssh library, are also patched. The vulnerabilities impact SUSE Linux Micro 6.0 systems. CISA has confirmed exploitation of these flaws, urging users to apply the patches immediately. The updates were released on September 18, 2026, and September 17, 2026, respectively, with CVE-2026-33186 first disclosed in March 2026. Administrators are advised to use SUSE's recommended installation methods for patching.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-03-20
CVE-2026-33186 published
Authorization bypass vulnerability disclosed affecting google-guest-agent.
Linuxsecurity
2026-06-04
CVE-2026-41178 published
Denial-of-service vulnerability disclosed affecting google-osconfig-agent.
Linuxsecurity
2026-08-28
CVE-2026-56854 published
Vulnerability in golang.org/x/crypto/ssh library disclosed.
Linuxsecurity
2026-09-02
CVE-2026-56855 published
Another vulnerability in golang.org/x/crypto/ssh library disclosed.
Linuxsecurity
2026-09-02
CVE-2026-78662 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-17
Patches released for google-guest-agent
SUSE released updates addressing multiple vulnerabilities including CVE-2026-33186.
Linuxsecurity
2026-09-18
Patches released for google-osconfig-agent
SUSE released updates addressing CVE-2026-41178 and others.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track Google and CVE-2026-33186 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed