Linuxsecurity SUSE Patches Critical Auth Bypass and DoS Vulnerabilities
Article Content
- •SUSE released critical patches for google-osconfig-agent and google-guest-agent.
- •Exploitation of CVE-2026-41178 and CVE-2026-33186 has been confirmed by CISA.
- •Administrators must apply patches immediately to protect SUSE Linux Micro 6.0 systems.
SUSE has released important security updates for its google-osconfig-agent and google-guest-agent due to multiple vulnerabilities. The updates address CVE-2026-41178, which allows denial-of-service (DoS) attacks via oversized inputs, and CVE-2026-33186, which enables authorization bypass through improper HTTP/2 header validation. Additionally, CVE-2026-56854 and CVE-2026-56855, affecting the golang.org/x/crypto/ssh library, are also patched. The vulnerabilities impact SUSE Linux Micro 6.0 systems. CISA has confirmed exploitation of these flaws, urging users to apply the patches immediately. The updates were released on September 18, 2026, and September 17, 2026, respectively, with CVE-2026-33186 first disclosed in March 2026. Administrators are advised to use SUSE's recommended installation methods for patching.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Google and CVE-2026-33186 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Multiple Oracle Linux Security Updates Address Critical Vulnerabilities Oracle has released multiple security updates for its Linux distributions, addressing several critical vulnerabilities. Key updates include patches for CVE-2026-59090 and CVE-2026-18301 in GIMP, and multiple CVEs in FreeRDP, libssh, and Grafana. Affected systems include Oracle Linux 8, 9, and 10, with vulnerabilities…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…