Search

Find a vulnerability

Search criteria

    2924 vulnerabilities by suse

    CVE-2026-88804 (GCVE-0-2026-88804)

    Vulnerability from cvelistv5 – Published: 2026-09-28 15:58 – Updated: 2026-09-28 18:02
    VLAI
    Title
    Unauthenticated update of public UI settings leading to stored cross-site scripting in Rancher
    Summary
    An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before 2.12.14 and 2.11 before 2.11.18.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 16:31 UTC
    CWE
    • CWE-79 - Improper neutralization of input during web page generation ('cross-site scripting')
    References
    Impacted products
    Vendor Product Version
    SUSE Rancher Affected: 2.15.0 , < 2.15.2 (semver)
    Affected: 2.14.0 , < 2.14.6 (semver)
    Affected: 2.13.0 , < 2.13.10 (semver)
    Affected: 2.12.0 , < 2.12.14 (semver)
    Affected: 2.11.0se , < 2.11.18 (semver)
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 15:53
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88804",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T16:31:06.472253Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T18:02:56.882Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "Rancher",
              "product": "Rancher",
              "repo": "https://github.com/rancher/rancher/",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.15.2",
                  "status": "affected",
                  "version": "2.15.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.14.6",
                  "status": "affected",
                  "version": "2.14.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.13.10",
                  "status": "affected",
                  "version": "2.13.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.12.14",
                  "status": "affected",
                  "version": "2.12.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.11.18",
                  "status": "affected",
                  "version": "2.11.0se",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2.15.2",
                      "versionStartIncluding": "2.15.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2.14.6",
                      "versionStartIncluding": "2.14.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2.13.10",
                      "versionStartIncluding": "2.13.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2.12.14",
                      "versionStartIncluding": "2.12.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2.11.18",
                      "versionStartIncluding": "2.11.0se",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "stopvvar@proton.me"
            }
          ],
          "datePublic": "2026-09-28T15:53:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before 2.12.14 and 2.11 before 2.11.18."
                }
              ],
              "value": "An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before 2.12.14 and 2.11 before 2.11.18."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-104",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-104 Cross Zone Scripting"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.6,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper neutralization of input during web page generation (\u0027cross-site scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T15:58:34.657Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/rancher/rancher/security/advisories/GHSA-992f-xh8r-jg2f"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Unauthenticated update of public UI settings leading to stored cross-site scripting in Rancher",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-88804",
        "datePublished": "2026-09-28T15:58:34.657Z",
        "dateReserved": "2026-09-10T08:35:07.010Z",
        "dateUpdated": "2026-09-28T18:02:56.882Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88805 (GCVE-0-2026-88805)

    Vulnerability from cvelistv5 – Published: 2026-09-28 15:50 – Updated: 2026-09-29 03:55
    VLAI
    Title
    Session Not Revoked Server-Side on Logout in Rancher
    Summary
    Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the account was logged out. Affected is SUSE Rancher 2.15 before 2.15.2.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 00:00 UTC
    CWE
    • CWE-613 - Insufficient session expiration
    References
    Impacted products
    Vendor Product Version
    SUSE Rancher Affected: 2.15.0 , < 2.15.2 (semver)
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 15:40
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88805",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T03:55:25.070Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "Rancher",
              "product": "Rancher",
              "repo": "https://github.com/rancher/rancher/",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.15.2",
                  "status": "affected",
                  "version": "2.15.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2.15.2",
                      "versionStartIncluding": "2.15.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "info@cyberobserve.com"
            }
          ],
          "datePublic": "2026-09-28T15:40:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the account was logged out. Affected is SUSE Rancher 2.15 before 2.15.2."
                }
              ],
              "value": "Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the account was logged out. Affected is SUSE Rancher 2.15 before 2.15.2."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-21",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-21 Exploitation of Trusted Identifiers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-613",
                  "description": "CWE-613 Insufficient session expiration",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T15:50:34.591Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/rancher/rancher/security/advisories/GHSA-6vpq-mf48-9794"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Session Not Revoked Server-Side on Logout in Rancher",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-88805",
        "datePublished": "2026-09-28T15:50:34.591Z",
        "dateReserved": "2026-09-10T08:35:07.010Z",
        "dateUpdated": "2026-09-29T03:55:25.070Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88808 (GCVE-0-2026-88808)

    Vulnerability from cvelistv5 – Published: 2026-09-28 15:36 – Updated: 2026-09-29 03:55
    VLAI
    Title
    Fleet agent copies downstream resources with cluster-admin privileges, allowing cross-namespace writes on downstream clusters
    Summary
    A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment. It affects multi-tenancy environments where different tenants share the same downstream clusters, for example different privileged or untrusted teams inside the same organization. This could lead to overwritten configuration files. This issue affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, and 0.14 before 0.14.11.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 00:00 UTC
    CWE
    • CWE-250 - Execution with unnecessary privileges
    References
    Impacted products
    Vendor Product Version
    SUSE Rancher Affected: 0.16.0 , < 0.16.2 (semver)
    Affected: 0.15.0 , < 0.15.7 (semver)
    Affected: 0.14.0 , < 0.14.11 (semver)
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 15:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88808",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T03:55:24.347Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "Fleet",
              "product": "Rancher",
              "repo": "https://github.com/rancher/fleet/",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "0.16.2",
                  "status": "affected",
                  "version": "0.16.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.15.7",
                  "status": "affected",
                  "version": "0.15.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.14.11",
                  "status": "affected",
                  "version": "0.14.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.16.2",
                      "versionStartIncluding": "0.16.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.15.7",
                      "versionStartIncluding": "0.15.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.14.11",
                      "versionStartIncluding": "0.14.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "g.mygenie@gmail.com"
            }
          ],
          "datePublic": "2026-09-28T15:21:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003eA vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment. It affects multi-tenancy environments where different tenants share the same downstream clusters, for example different privileged or untrusted teams inside the same organization. This could lead to overwritten configuration files.\u003c/div\u003e\u003cdiv\u003eThis issue affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, and 0.14 before 0.14.11.\u003c/div\u003e"
                }
              ],
              "value": "A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment. It affects multi-tenancy environments where different tenants share the same downstream clusters, for example different privileged or untrusted teams inside the same organization. This could lead to overwritten configuration files.\n\nThis issue affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, and 0.14 before 0.14.11."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-180",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-180 Exploiting Incorrectly Configured Access Control Security Levels"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-250",
                  "description": "CWE-250 Execution with unnecessary privileges",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T15:36:13.506Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/rancher/fleet/security/advisories/GHSA-q9v4-358v-r8q5"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Fleet agent copies downstream resources with cluster-admin privileges, allowing cross-namespace writes on downstream clusters",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-88808",
        "datePublished": "2026-09-28T15:36:13.506Z",
        "dateReserved": "2026-09-10T08:35:07.010Z",
        "dateUpdated": "2026-09-29T03:55:24.347Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-93540 (GCVE-0-2026-93540)

    Vulnerability from cvelistv5 – Published: 2026-09-28 14:45 – Updated: 2026-09-28 16:22
    VLAI
    Title
    Fleet applies namespace labels and annotations without the bundle's service account privileges
    Summary
    A privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the namespaceLabels and namespaceAnnotations options, the resulting namespace metadata update was not subject to the same authorization as the rest of the bundle's deployment. As a result, a bundle could change labels and annotations on a target namespace even when the identity it was pinned to was not authorized to modify that namespace. This affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16 and potentially older versions.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 15:25 UTC
    CWE
    • CWE-266 - Incorrect privilege assignment
    References
    Impacted products
    Vendor Product Version
    SUSE Rancher Affected: 0.16.0 , < 0.16.1 (semver)
    Affected: 0.15.0 , < 0.15.7 (semver)
    Affected: 0.14.0 , < 0.14.11 (semver)
    Affected: 0.13.0 , < 0.13.16 (semver)
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 14:28
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-93540",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T15:25:53.294940Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T16:22:25.780Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "Fleet",
              "product": "Rancher",
              "repo": "https://github.com/rancher/fleet/",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "0.16.1",
                  "status": "affected",
                  "version": "0.16.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.15.7",
                  "status": "affected",
                  "version": "0.15.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.14.11",
                  "status": "affected",
                  "version": "0.14.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.13.16",
                  "status": "affected",
                  "version": "0.13.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.16.1",
                      "versionStartIncluding": "0.16.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.15.7",
                      "versionStartIncluding": "0.15.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.14.11",
                      "versionStartIncluding": "0.14.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.13.16",
                      "versionStartIncluding": "0.13.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "g.mygenie@gmail.com"
            }
          ],
          "datePublic": "2026-09-28T14:28:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003eA privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the \u003ccode\u003enamespaceLabels\u003c/code\u003e and \u003ccode\u003enamespaceAnnotations\u003c/code\u003e options, the resulting namespace metadata update was not subject to the same authorization as the rest of the bundle\u0027s deployment. As a result, a bundle could change labels and annotations on a target namespace even when the identity it was pinned to was not authorized to modify that namespace.\u003c/div\u003e\u003cdiv\u003eThis affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16 and potentially older versions.\u003c/div\u003e"
                }
              ],
              "value": "A privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the namespaceLabels and namespaceAnnotations options, the resulting namespace metadata update was not subject to the same authorization as the rest of the bundle\u0027s deployment. As a result, a bundle could change labels and annotations on a target namespace even when the identity it was pinned to was not authorized to modify that namespace.\n\nThis affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16 and potentially older versions."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-690",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-690 Metadata Spoofing"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-266",
                  "description": "CWE-266 Incorrect privilege assignment",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T14:45:42.336Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/rancher/fleet/security/advisories/GHSA-m93g-8438-2cgg"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Fleet applies namespace labels and annotations without the bundle\u0027s service account privileges",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-93540",
        "datePublished": "2026-09-28T14:45:42.336Z",
        "dateReserved": "2026-09-18T09:08:10.294Z",
        "dateUpdated": "2026-09-28T16:22:25.780Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-93539 (GCVE-0-2026-93539)

    Vulnerability from cvelistv5 – Published: 2026-09-28 14:19 – Updated: 2026-09-28 16:22
    VLAI
    Title
    Unauthenticated GitRepo Spec Mutation via Fleet Git Webhook Receiver
    Summary
    A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhook requests are accepted without verification, and processing a request can change the spec.pollingInterval field of a matching GitRepo resource in any namespace. A caller with network access to the webhook service and no Kubernetes credentials can therefore alter GitRepo configuration outside the namespaces they are authorized for.  This only affects SUSE Rancher Fleet 0.16 before 0.16.2, older versions are not affected.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 14:59 UTC
    CWE
    • CWE-306 - Missing authentication for critical function
    References
    Impacted products
    Vendor Product Version
    SUSE Rancher Affected: 0.16.0 , < 0.16.2 (semver)
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 14:16
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-93539",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T14:59:38.674475Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T16:22:26.433Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "Fleet",
              "product": "Rancher",
              "repo": "https://github.com/rancher/fleet/",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "0.16.2",
                  "status": "affected",
                  "version": "0.16.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.16.2",
                      "versionStartIncluding": "0.16.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "https://github.com/Pig-Tail"
            }
          ],
          "datePublic": "2026-09-28T14:16:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A vulnerability was discovered in Fleet\u0027s Git webhook receiver (the \u003ccode\u003egitjob\u003c/code\u003e webhook service). When a webhook secret is not configured, incoming webhook requests are accepted without verification, and processing a request can change the \u003ccode\u003espec.pollingInterval\u003c/code\u003e field of a matching \u003ccode\u003eGitRepo\u003c/code\u003e resource in any namespace. A caller with network access to the webhook service and no Kubernetes credentials can therefore alter \u003ccode\u003eGitRepo\u003c/code\u003e configuration outside\u003cbr\u003e\nthe namespaces they are authorized for.\u0026nbsp; This only affects SUSE Rancher Fleet 0.16 before 0.16.2, older versions are not affected."
                }
              ],
              "value": "A vulnerability was discovered in Fleet\u0027s Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhook requests are accepted without verification, and processing a request can change the spec.pollingInterval field of a matching GitRepo resource in any namespace. A caller with network access to the webhook service and no Kubernetes credentials can therefore alter GitRepo configuration outside\n\nthe namespaces they are authorized for.\u00a0 This only affects SUSE Rancher Fleet 0.16 before 0.16.2, older versions are not affected."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-176",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-176 Configuration/Environment Manipulation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "CWE-306 Missing authentication for critical function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T14:19:55.071Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/rancher/fleet/security/advisories/GHSA-8vfv-33cg-g75q"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Unauthenticated GitRepo Spec Mutation via Fleet Git Webhook Receiver",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-93539",
        "datePublished": "2026-09-28T14:19:55.071Z",
        "dateReserved": "2026-09-18T09:08:10.294Z",
        "dateUpdated": "2026-09-28T16:22:26.433Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-93538 (GCVE-0-2026-93538)

    Vulnerability from cvelistv5 – Published: 2026-09-28 14:10 – Updated: 2026-09-28 16:22
    VLAI
    Title
    Cross-tenant BundleDeployment and Secret disclosure via spoofed cluster labels during agent-initiated registration in Fleet
    Summary
    A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such as the cluster display name label, were applied to the resulting upstream Cluster object. Because Fleet resolves GitRepo and Bundle targets from those cluster labels, a party able to register a cluster into a Fleet workspace namespace shared with other tenants could cause its own cluster to satisfy targeting rules that administrators intended for a different cluster. This affects SUSE Rancher Fleet 0.16 before 0.16.1, 0.15 before 0.15.6, 0.14 before 0.14.10, 0.13 before 0.13.15, 0.12 before 0.12.19 and older versions.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 15:46 UTC
    CWE
    • CWE-290 - Authentication bypass by spoofing
    • CWE-639 - Authorization bypass through User-Controlled key
    References
    Impacted products
    Vendor Product Version
    SUSE Rancher Affected: 0.16.0 , < 0.16.1 (semver)
    Affected: 0.15.0 , < 0.15.6 (semver)
    Affected: 0.14.0 , < 0.14.10 (semver)
    Affected: 0.13.0 , < 0.13.15 (semver)
    Affected: 0.12.0 , < 0.12.19 (semver)
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 14:05
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-93538",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T15:46:41.479078Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T16:22:26.562Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "Fleet",
              "product": "Rancher",
              "repo": "https://github.com/rancher/fleet/",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "0.16.1",
                  "status": "affected",
                  "version": "0.16.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.15.6",
                  "status": "affected",
                  "version": "0.15.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.14.10",
                  "status": "affected",
                  "version": "0.14.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.13.15",
                  "status": "affected",
                  "version": "0.13.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.12.19",
                  "status": "affected",
                  "version": "0.12.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.16.1",
                      "versionStartIncluding": "0.16.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.15.6",
                      "versionStartIncluding": "0.15.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.14.10",
                      "versionStartIncluding": "0.14.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.13.15",
                      "versionStartIncluding": "0.13.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.12.19",
                      "versionStartIncluding": "0.12.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "https://github.com/Pig-Tail"
            }
          ],
          "datePublic": "2026-09-28T14:05:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated\u0026nbsp;cluster registration, cluster labels supplied by the registering agent, including labels in the reserved \u003ccode\u003emanagement.cattle.io/\u003c/code\u003e namespace such as the cluster display name label, were applied to the resulting upstream \u003ccode\u003eCluster\u003c/code\u003e object. Because Fleet resolves \u003ccode\u003eGitRepo\u003c/code\u003e and \u003ccode\u003eBundle\u003c/code\u003e targets from those cluster labels, a party able to register a cluster into a Fleet workspace namespace shared with other tenants could cause its own cluster to satisfy targeting rules that administrators intended for a different cluster.\u003cbr\u003eThis affects SUSE Rancher Fleet 0.16 before 0.16.1, 0.15 before 0.15.6, 0.14 before 0.14.10, 0.13 before 0.13.15, 0.12 before 0.12.19 and older versions."
                }
              ],
              "value": "A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated\u00a0cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such as the cluster display name label, were applied to the resulting upstream Cluster object. Because Fleet resolves GitRepo and Bundle targets from those cluster labels, a party able to register a cluster into a Fleet workspace namespace shared with other tenants could cause its own cluster to satisfy targeting rules that administrators intended for a different cluster.\nThis affects SUSE Rancher Fleet 0.16 before 0.16.1, 0.15 before 0.15.6, 0.14 before 0.14.10, 0.13 before 0.13.15, 0.12 before 0.12.19 and older versions."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-122",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-122 Privilege Abuse"
                }
              ]
            },
            {
              "capecId": "CAPEC-195",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-195 Principal Spoof"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-290",
                  "description": "CWE-290 Authentication bypass by spoofing",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "CWE-639 Authorization bypass through User-Controlled key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T14:10:21.720Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/rancher/fleet/security/advisories/GHSA-h9p5-fp5h-qpqr"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Cross-tenant BundleDeployment and Secret disclosure via spoofed cluster labels during agent-initiated registration in Fleet",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-93538",
        "datePublished": "2026-09-28T14:10:21.720Z",
        "dateReserved": "2026-09-18T09:08:10.294Z",
        "dateUpdated": "2026-09-28T16:22:26.562Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-93537 (GCVE-0-2026-93537)

    Vulnerability from cvelistv5 – Published: 2026-09-28 13:29 – Updated: 2026-09-28 17:54
    VLAI
    Title
    Path traversal in Fleet Helm valuesFiles allows disclosure of files outside the bundle directory
    Summary
    A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or modify a GitRepo, can cause SUSE Rancher Fleet to read files from the filesystem of the environment that processes the bundle and include their contents in the generated Bundle resource. This can expose configuration or credential material that the user has no Kubernetes RBAC permission to read, including Helm registry credentials made available to the bundle-processing job when per-path Helm credentials are configured. This affects Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16, 0.12 before 0.12.20 and potentially older unsupported versions.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 17:54 UTC
    CWE
    • CWE-23 - Relative path traversal
    References
    Impacted products
    Vendor Product Version
    SUSE Rancher Affected: 0.16.0 , < 0.16.2 (semver)
    Affected: 0.15.0 , < 0.15.7 (semver)
    Affected: 0.14.0 , < 0.14.11 (semver)
    Affected: 0.13.0 , < 0.13.16 (semver)
    Affected: 0.12.0 , < 0.12.20 (semver)
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 12:15
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-93537",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T17:54:00.943037Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T17:54:22.754Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "Fleet",
              "product": "Rancher",
              "repo": "https://github.com/rancher/fleet/",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "0.16.2",
                  "status": "affected",
                  "version": "0.16.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.15.7",
                  "status": "affected",
                  "version": "0.15.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.14.11",
                  "status": "affected",
                  "version": "0.14.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.13.16",
                  "status": "affected",
                  "version": "0.13.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.12.20",
                  "status": "affected",
                  "version": "0.12.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.16.2",
                      "versionStartIncluding": "0.16.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.15.7",
                      "versionStartIncluding": "0.15.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.14.11",
                      "versionStartIncluding": "0.14.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.13.16",
                      "versionStartIncluding": "0.13.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.12.20",
                      "versionStartIncluding": "0.12.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "https://github.com/Pig-Tail"
            }
          ],
          "datePublic": "2026-09-28T12:15:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A user who can supply bundle content to a repository referenced by a \u003ccode\u003eGitRepo\u003c/code\u003e resource, for example through Git push access, or through permission to create or modify a \u003ccode\u003eGitRepo\u003c/code\u003e, can cause SUSE Rancher Fleet to read files from the filesystem of the environment that processes the bundle and include their contents in the generated \u003ccode\u003eBundle\u003c/code\u003e resource. This can expose configuration or credential material that the user has no Kubernetes RBAC permission to read, including Helm registry credentials made available to the bundle-processing job when per-path Helm credentials are configured.\u003cbr\u003eThis affects Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16, 0.12 before 0.12.20 and potentially older unsupported versions."
                }
              ],
              "value": "A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or modify a GitRepo, can cause SUSE Rancher Fleet to read files from the filesystem of the environment that processes the bundle and include their contents in the generated Bundle resource. This can expose configuration or credential material that the user has no Kubernetes RBAC permission to read, including Helm registry credentials made available to the bundle-processing job when per-path Helm credentials are configured.\nThis affects Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16, 0.12 before 0.12.20 and potentially older unsupported versions."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-122",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-122 Privilege Abuse"
                }
              ]
            },
            {
              "capecId": "CAPEC-180",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-180"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-23",
                  "description": "CWE-23 Relative path traversal",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T13:29:10.263Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/rancher/fleet/security/advisories/GHSA-wpfm-r97v-3j4h"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Path traversal in Fleet Helm valuesFiles allows disclosure of files outside the bundle directory",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-93537",
        "datePublished": "2026-09-28T13:29:10.263Z",
        "dateReserved": "2026-09-18T09:08:10.294Z",
        "dateUpdated": "2026-09-28T17:54:22.754Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-78424 (GCVE-0-2026-78424)

    Vulnerability from cvelistv5 – Published: 2026-09-28 11:44 – Updated: 2026-09-29 03:55
    VLAI
    Title
    OS Command Injection in Packet-Capture (Sniffer) Filter leading to Remote Code Execution on Kubernetes Nodes
    Summary
    Improper parameter handling in NeuVector allows any authenticated user who holds the namespaced Runtime Policies (write) permission or anyone with access to NeuVector’s internal gRPC certificate key pair the ability to inject OS commands in the privileged enforcer container, which can lead to the complete compromise of the worker node. This affects NeuVector 5.4 before 5.4.11, NeuVector 5.5 before 5.5.4, NeuVector 5.6 before 5.6.2 and potentially older versions.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 00:00 UTC
    CWE
    • CWE-78 - Improper neutralization of special elements used in an OS command ('OS command injection')
    References
    Impacted products
    Vendor Product Version
    SUSE NeuVector Affected: 0 , < 5.4.11 (semver)
    Affected: 5.5.0 , < 5.5.4 (semver)
    Affected: 5.6.0 , < 5.6.2 (semver)
        cpe:2.3:a:suse:neuvector:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:neuvector:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:neuvector:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 11:39
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78424",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T03:55:17.618Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "neuvector",
              "product": "NeuVector",
              "repo": "https://github.com/neuvector/neuvector/",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "5.4.11",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.5.4",
                  "status": "affected",
                  "version": "5.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.6.2",
                  "status": "affected",
                  "version": "5.6.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:suse:neuvector:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.11",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:neuvector:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.5.4",
                      "versionStartIncluding": "5.5.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:neuvector:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.6.2",
                      "versionStartIncluding": "5.6.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Sergey Kanibor"
            }
          ],
          "datePublic": "2026-09-28T11:39:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Improper parameter handling in NeuVector allows any authenticated user who holds the namespaced Runtime Policies (write) permission or anyone with access to NeuVector\u2019s internal gRPC certificate key pair the ability to inject OS commands in the privileged enforcer container, which can lead to the complete compromise of the worker node. This affects NeuVector 5.4 before 5.4.11, NeuVector 5.5 before 5.5.4, NeuVector 5.6 before 5.6.2 and potentially older versions."
                }
              ],
              "value": "Improper parameter handling in NeuVector allows any authenticated user who holds the namespaced Runtime Policies (write) permission or anyone with access to NeuVector\u2019s internal gRPC certificate key pair the ability to inject OS commands in the privileged enforcer container, which can lead to the complete compromise of the worker node. This affects NeuVector 5.4 before 5.4.11, NeuVector 5.5 before 5.5.4, NeuVector 5.6 before 5.6.2 and potentially older versions."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-549",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-549 Local Execution of Code"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T11:44:05.235Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/neuvector/neuvector/security/advisories/GHSA-vr77-8vmq-qfmj"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "OS Command Injection in Packet-Capture (Sniffer) Filter leading to Remote Code Execution on Kubernetes Nodes",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-78424",
        "datePublished": "2026-09-28T11:44:05.235Z",
        "dateReserved": "2026-08-24T15:33:13.665Z",
        "dateUpdated": "2026-09-29T03:55:17.618Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-78427 (GCVE-0-2026-78427)

    Vulnerability from cvelistv5 – Published: 2026-09-17 09:33 – Updated: 2026-09-28 12:06
    VLAI
    Title
    Admission Control Bypass via Hardcoded Sidecar Image Exemption
    Summary
    The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images. Since the image path is entirely controlled by the workload author, any user capable of deploying workloads can evade admission deny rules simply by naming their image path after one of these sidecar images.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 12:10 UTC
    CWE
    • CWE-807 - Reliance on Untrusted Inputs in a Security Decision
    Impacted products
    Vendor Product Version
    SUSE github.com/neuvector/neuvector Affected: 0 , ≤ v5.6.1 (custom)
        cpe:2.3:a:suse:github.com_neuvector_neuvector:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 12:05
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78427",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T12:10:23.202569Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T12:10:55.525Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "github.com/neuvector/neuvector",
              "vendor": "SUSE",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "5.6.2",
                      "status": "unaffected"
                    },
                    {
                      "at": "5.5.4",
                      "status": "unaffected"
                    },
                    {
                      "at": "5.4.11",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "v5.6.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:suse:github.com_neuvector_neuvector:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "v5.6.1",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "datePublic": "2026-09-28T12:05:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\u003cspan\u003eThe NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images. Since the image path is entirely controlled by the workload author, any user capable of deploying workloads can evade admission deny rules simply by naming their image path after one of these sidecar images.\u003c/span\u003e\u003c/p\u003e"
                }
              ],
              "value": "The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images. Since the image path is entirely controlled by the workload author, any user capable of deploying workloads can evade admission deny rules simply by naming their image path after one of these sidecar images."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-807",
                  "description": "CWE-807 Reliance on Untrusted Inputs in a Security Decision",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T12:06:08.210Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "url": "https://github.com/neuvector/neuvector/security/advisories/GHSA-78r4-3wfq-r2xm"
            },
            {
              "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-78427"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Admission Control Bypass via Hardcoded Sidecar Image Exemption",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-78427",
        "datePublished": "2026-09-17T09:33:26.318Z",
        "dateReserved": "2026-08-24T15:33:13.665Z",
        "dateUpdated": "2026-09-28T12:06:08.210Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-78425 (GCVE-0-2026-78425)

    Vulnerability from cvelistv5 – Published: 2026-09-17 09:32 – Updated: 2026-09-28 12:04
    VLAI
    Title
    SAML Audience Confusion Allows Cross-SP Authentication
    Summary
    Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticketing system, an expenses tool, or anything they legitimately hold an account on can log into their system via SAML SSO. The IdP issues an assertion to them. If that assertion is presented to NeuVector, NeuVector accepts it because the only thing distinguishing "an assertion for NeuVector" from "an assertion for the wiki" is the element, and the `NotInAudience` warning that reports the mismatch is never read.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 12:12 UTC
    CWE
    • CWE-287 - Improper Authentication
    Impacted products
    Vendor Product Version
    SUSE github.com/neuvector/neuvector Affected: 0 , ≤ v5.6.1 (custom)
        cpe:2.3:a:suse:github.com_neuvector_neuvector:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 12:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78425",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T12:12:10.344911Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T12:13:08.680Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "github.com/neuvector/neuvector",
              "vendor": "SUSE",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "5.6.2",
                      "status": "unaffected"
                    },
                    {
                      "at": "5.5.4",
                      "status": "unaffected"
                    },
                    {
                      "at": "5.4.11",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "v5.6.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:suse:github.com_neuvector_neuvector:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "v5.6.1",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "datePublic": "2026-09-28T12:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\u003cspan\u003eAuthorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticketing system, an expenses tool, or anything they legitimately hold an account on can log into their system via SAML SSO. The IdP issues an assertion to them. If that assertion is presented to NeuVector, NeuVector accepts it because the only thing distinguishing \"an assertion for NeuVector\" from \"an assertion for the wiki\" is the element, and the `NotInAudience` warning that reports the mismatch is never read.\u003c/span\u003e\u003c/p\u003e"
                }
              ],
              "value": "Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticketing system, an expenses tool, or anything they legitimately hold an account on can log into their system via SAML SSO. The IdP issues an assertion to them. If that assertion is presented to NeuVector, NeuVector accepts it because the only thing distinguishing \"an assertion for NeuVector\" from \"an assertion for the wiki\" is the element, and the `NotInAudience` warning that reports the mismatch is never read."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 7.6,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-287",
                  "description": "CWE-287 Improper Authentication",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T12:04:24.695Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/neuvector/neuvector/security/advisories/GHSA-wgg5-24xq-px35"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-78425"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "SAML Audience Confusion Allows Cross-SP Authentication",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-78425",
        "datePublished": "2026-09-17T09:32:21.383Z",
        "dateReserved": "2026-08-24T15:33:13.665Z",
        "dateUpdated": "2026-09-28T12:04:24.695Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-78426 (GCVE-0-2026-78426)

    Vulnerability from cvelistv5 – Published: 2026-09-17 09:28 – Updated: 2026-09-28 12:03
    VLAI
    Title
    Logout bypass via alternate JWT spelling
    Summary
    The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 12:40 UTC
    CWE
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    SUSE neuvector Affected: 0 , ≤ v5.6.1 (custom)
        cpe:2.3:a:suse:neuvector:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78426",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T12:40:12.782525Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T12:40:32.383Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "neuvector",
              "product": "neuvector",
              "repo": "https://github.com/neuvector/neuvector/security/",
              "vendor": "SUSE",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "5.6.2",
                      "status": "unaffected"
                    },
                    {
                      "at": "5.5.4",
                      "status": "unaffected"
                    },
                    {
                      "at": "5.4.11",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "v5.6.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:suse:neuvector:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "v5.6.1",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\u003cspan\u003eThe NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires.\u003c/span\u003e\u003c/p\u003e"
                }
              ],
              "value": "The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 2,
                "baseSeverity": "LOW",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "ACTIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "CWE-863 Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T12:03:54.563Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/neuvector/neuvector/security/advisories/GHSA-wcx5-mq6c-c54j"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-78426"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Logout bypass via alternate JWT spelling",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-78426",
        "datePublished": "2026-09-17T09:28:19.683Z",
        "dateReserved": "2026-08-24T15:33:13.665Z",
        "dateUpdated": "2026-09-28T12:03:54.563Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-78428 (GCVE-0-2026-78428)

    Vulnerability from cvelistv5 – Published: 2026-09-17 09:19 – Updated: 2026-09-28 12:07
    VLAI
    Title
    Flaw in Neuvector can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
    Summary
    For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 12:15 UTC
    CWE
    Impacted products
    Vendor Product Version
    SUSE neuvector Affected: <5.6.1 (custom)
        cpe:2.3:a:suse:neuvector:_5.6.1:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 12:06
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78428",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T12:15:03.788838Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-384",
                    "description": "CWE-384 Session Fixation",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T15:16:41.723Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "neuvector",
              "product": "neuvector",
              "vendor": "SUSE",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c5.6.1",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:suse:neuvector:_5.6.1:*:*:*:*:*:*:*",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "datePublic": "2026-09-28T12:06:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\u003cspan\u003eFor users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user\u0027s authenticated session when multiple SSO login attempts occur concurrently\u003c/span\u003e\u003c/p\u003e"
                }
              ],
              "value": "For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user\u0027s authenticated session when multiple SSO login attempts occur concurrently"
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "ACTIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T12:07:55.498Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/neuvector/neuvector/security/advisories/GHSA-c6rx-pmvf-m3jx"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://bugzilla.suse.com/show_bug.cgi?id=1279937"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Flaw in Neuvector can result in one user receiving another user\u0027s authenticated session when multiple SSO login attempts occur concurrently",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-78428",
        "datePublished": "2026-09-17T09:19:21.262Z",
        "dateReserved": "2026-08-24T15:33:13.665Z",
        "dateUpdated": "2026-09-28T12:07:55.498Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-44940 (GCVE-0-2026-44940)

    Vulnerability from cvelistv5 – Published: 2026-09-17 06:43 – Updated: 2026-09-29 16:07
    VLAI
    Title
    Service token exposure and potential privilege escalation in SUSE Observability
    Summary
    The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access could obtain the token to gain unauthorized access or escalate privileges within the observability environment.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 12:34 UTC
    CWE
    • CWE-312 - Cleartext Storage of Sensitive Information
    • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
    Impacted products
    Vendor Product Version
    SUSE SUSE Observability Affected: 0 , < 2.13.6 (custom)
    Affected: 2.14.0 , < 2.14.2 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-44940",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T12:34:04.290434Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T16:07:34.098Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "rancher-extension-stackstate",
              "product": "SUSE Observability",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.13.6",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2.14.2",
                  "status": "affected",
                  "version": "2.14.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access could obtain the token to gain unauthorized access or escalate privileges within the observability environment.\u003c/p\u003e"
                }
              ],
              "value": "The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access could obtain the token to gain unauthorized access or escalate privileges within the observability environment."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.7,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-312",
                  "description": "CWE-312: Cleartext Storage of Sensitive Information",
                  "lang": "en",
                  "type": "CWE"
                },
                {
                  "cweId": "CWE-200",
                  "description": "CWE-200: Exposure of Sensitive Information to an Unauthorized Actor",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-17T06:43:19.297Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-44940"
            },
            {
              "url": "https://github.com/StackVista/rancher-extension-stackstate/security/advisories/GHSA-7c27-jc6w-pw95"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Service token exposure and potential privilege escalation in SUSE Observability",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eRevoke the existing service token inside SUSE Observability. Generate a new service token assigned to the `stackstate-guest` role (which enforces read-only access) rather than the default `stackstate-k8s-troubleshooter` role.\u003c/p\u003e"
                }
              ],
              "value": "Revoke the existing service token inside SUSE Observability. Generate a new service token assigned to the `stackstate-guest` role (which enforces read-only access) rather than the default `stackstate-k8s-troubleshooter` role."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-44940",
        "datePublished": "2026-09-17T06:43:19.297Z",
        "dateReserved": "2026-05-08T12:29:48.968Z",
        "dateUpdated": "2026-09-29T16:07:34.098Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-44950 (GCVE-0-2026-44950)

    Vulnerability from cvelistv5 – Published: 2026-09-10 08:19 – Updated: 2026-09-10 18:26
    VLAI
    Title
    fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont2
    Summary
    fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer. It does not check whether the running destination cursor has exceeded the allocation. A malicious font server can send overlapping source offsets -- for example 1000 glyphs each referencing {position:0, length:64} with nbytes=64. Each individual source range passes the existing validation, but the cumulative writes total 64000 bytes into a 64-byte destination buffer. This is a heap buffer overflow with attacker-controlled content.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 17:19 UTC
    CWE
    • CWE-122 - Heap-based Buffer Overflow
    Impacted products
    Vendor Product Version
    SUSE Container suse/kiosk/tigervnc-x11vnc:1.14-63.8 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Container suse/kiosk/xorg:21.1-83.7 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Azure-3P Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-BYOS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-BYOS-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-BYOS-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-BYOS-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-BYOS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-BYOS-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-BYOS-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-BYOS-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAPCAL Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAPCAL-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAPCAL-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAPCAL-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Azure-3P Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-BYOS-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-BYOS-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-BYOS-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-GCE-3P Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Hardened-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Hardened-BYOS-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Hardened-BYOS-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Hardened-BYOS-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Hardened-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAPCAL-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAPCAL-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAPCAL-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-Azure Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-Azure-3P Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-BYOS-Azure Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-BYOS-EC2 Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-BYOS-GCE Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-GCE Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-GCE-3P Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAPCAL-GCE Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES12-SP5-Azure-SAP-BYOS Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES12-SP5-Azure-SAP-On-Demand Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES12-SP5-EC2-SAP-BYOS Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES12-SP5-EC2-SAP-On-Demand Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES12-SP5-GCE-SAP-BYOS Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES12-SP5-GCE-SAP-On-Demand Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Liberty Linux 10 Affected: ? , < 2.0.6-5.el10_2.3 (custom)
    Create a notification for this product.
    SUSE SUSE Liberty Linux 8 Affected: ? , < 2.0.3-2.el8_10.3 (custom)
    Create a notification for this product.
    SUSE SUSE Liberty Linux 9 Affected: ? , < 2.0.3-12.el9_8.3 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Desktop 15 SP7 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Module for Basesystem 15 SP7 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server 15 SP7 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server for SAP Applications 15 SP7 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server 12 SP5-LTSS Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server 15 SP4-LTSS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server 15 SP5-LTSS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server 15 SP6-LTSS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server 16.0 Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server for SAP applications 16.0 Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server LTSS Extended Security 12 SP5 Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server for SAP Applications 15 SP4 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server for SAP Applications 15 SP5 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server for SAP Applications 15 SP6 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Manager Proxy LTS 4.3 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Manager Retail Branch Server LTS 4.3 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Manager Server LTS 4.3 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE openSUSE Leap 16.0 Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE openSUSE Tumbleweed Affected: ? , < 2.0.7-3.1 (custom)
    Create a notification for this product.
    libXfont libXfont Affected: ? , ≤ 2.0.8 (custom)
    Create a notification for this product.
    Date Public
    2026-08-05 08:17
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-44950",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T17:19:50.287306Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-122",
                    "description": "CWE-122 Heap-based Buffer Overflow",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T18:26:50.408Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Container suse/kiosk/tigervnc-x11vnc:1.14-63.8",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Container suse/kiosk/xorg:21.1-83.7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Azure-3P",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-BYOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-BYOS-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-BYOS-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-BYOS-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-BYOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-BYOS-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-BYOS-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-BYOS-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAPCAL",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAPCAL-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAPCAL-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAPCAL-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Azure-3P",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-BYOS-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-BYOS-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-BYOS-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-GCE-3P",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Hardened-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Hardened-BYOS-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Hardened-BYOS-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Hardened-BYOS-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Hardened-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAPCAL-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAPCAL-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAPCAL-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-Azure-3P",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-BYOS-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-BYOS-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-BYOS-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-GCE-3P",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAPCAL-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES12-SP5-Azure-SAP-BYOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES12-SP5-Azure-SAP-On-Demand",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES12-SP5-EC2-SAP-BYOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES12-SP5-EC2-SAP-On-Demand",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES12-SP5-GCE-SAP-BYOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES12-SP5-GCE-SAP-On-Demand",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2",
              "product": "SUSE Liberty Linux 10",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.6-5.el10_2.3",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Liberty Linux 10",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.6-5.el10_2.3",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2",
              "product": "SUSE Liberty Linux 8",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-2.el8_10.3",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Liberty Linux 8",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-2.el8_10.3",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2",
              "product": "SUSE Liberty Linux 9",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-12.el9_8.3",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Liberty Linux 9",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-12.el9_8.3",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Desktop 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Desktop 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Module for Basesystem 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Module for Basesystem 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server 12 SP5-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server 15 SP4-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server 15 SP4-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server 15 SP5-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server 15 SP5-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server 15 SP6-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server 15 SP6-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server 16.0",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server 16.0",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server for SAP applications 16.0",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server for SAP applications 16.0",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server LTSS Extended Security 12 SP5",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP4",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP4",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP5",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP5",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP6",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP6",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Manager Proxy LTS 4.3",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Manager Proxy LTS 4.3",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Manager Retail Branch Server LTS 4.3",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Manager Retail Branch Server LTS 4.3",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Manager Server LTS 4.3",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Manager Server LTS 4.3",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "openSUSE Leap 16.0",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "openSUSE Leap 16.0",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "openSUSE Tumbleweed",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-3.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2-32bit",
              "product": "openSUSE Tumbleweed",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-3.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "openSUSE Tumbleweed",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-3.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel-32bit",
              "product": "openSUSE Tumbleweed",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-3.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont",
              "product": "libXfont",
              "vendor": "libXfont",
              "versions": [
                {
                  "lessThanOrEqual": "2.0.8",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "zx (Jace)"
            }
          ],
          "datePublic": "2026-08-05T08:17:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cpre\u003efs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph\u0027s bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer. It does not check whether the running destination cursor has exceeded the allocation.\n\nA malicious font server can send overlapping source offsets -- for example 1000 glyphs each referencing {position:0, length:64} with nbytes=64. Each individual source range passes the existing validation, but the cumulative writes total 64000 bytes into a 64-byte destination buffer. This is a heap buffer overflow with attacker-controlled content.\u003c/pre\u003e"
                }
              ],
              "value": "fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph\u0027s bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer. It does not check whether the running destination cursor has exceeded the allocation.\n\nA malicious font server can send overlapping source offsets -- for example 1000 glyphs each referencing {position:0, length:64} with nbytes=64. Each individual source range passes the existing validation, but the cumulative writes total 64000 bytes into a 64-byte destination buffer. This is a heap buffer overflow with attacker-controlled content."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 9.5,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:19:55.462Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-44950"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont2",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-44950",
        "datePublished": "2026-09-10T08:19:55.462Z",
        "dateReserved": "2026-05-08T12:29:48.969Z",
        "dateUpdated": "2026-09-10T18:26:50.408Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-59679 (GCVE-0-2026-59679)

    Vulnerability from cvelistv5 – Published: 2026-09-10 08:15 – Updated: 2026-09-10 12:45
    VLAI
    Title
    fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont2
    Summary
    fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the separate FS_QueryXExtents16 reply. The two CARD32 fields are never cross-checked. A malicious or compromised font server can send a small num_extents (e.g. 1) in the extents reply, then a large num_chars (e.g. 100000) in the bitmaps reply. This causes attacker-controlled out-of-bounds heap read and writes.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 12:44 UTC
    CWE
    Impacted products
    Vendor Product Version
    SUSE Container suse/kiosk/tigervnc-x11vnc:1.14-63.8 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Container suse/kiosk/xorg:21.1-83.7 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Azure-3P Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-BYOS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-BYOS-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-BYOS-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-BYOS-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-BYOS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-BYOS-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-BYOS-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-BYOS-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAPCAL Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAPCAL-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAPCAL-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAPCAL-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Azure-3P Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-BYOS-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-BYOS-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-BYOS-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-GCE-3P Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Hardened-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Hardened-BYOS-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Hardened-BYOS-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Hardened-BYOS-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Hardened-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAPCAL-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAPCAL-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAPCAL-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-Azure Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-Azure-3P Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-BYOS-Azure Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-BYOS-EC2 Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-BYOS-GCE Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-GCE Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-GCE-3P Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAPCAL-GCE Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES12-SP5-Azure-SAP-BYOS Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES12-SP5-Azure-SAP-On-Demand Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES12-SP5-EC2-SAP-BYOS Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES12-SP5-EC2-SAP-On-Demand Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES12-SP5-GCE-SAP-BYOS Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES12-SP5-GCE-SAP-On-Demand Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Liberty Linux 10 Affected: ? , < 2.0.6-5.el10_2.3 (custom)
    Create a notification for this product.
    SUSE SUSE Liberty Linux 8 Affected: ? , < 2.0.3-2.el8_10.3 (custom)
    Create a notification for this product.
    SUSE SUSE Liberty Linux 9 Affected: ? , < 2.0.3-12.el9_8.3 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Desktop 15 SP7 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Module for Basesystem 15 SP7 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server 15 SP7 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server for SAP Applications 15 SP7 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server 12 SP5-LTSS Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server 15 SP4-LTSS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server 15 SP5-LTSS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server 15 SP6-LTSS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server 16.0 Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server for SAP applications 16.0 Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server LTSS Extended Security 12 SP5 Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server for SAP Applications 15 SP4 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server for SAP Applications 15 SP5 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server for SAP Applications 15 SP6 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Manager Proxy LTS 4.3 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Manager Retail Branch Server LTS 4.3 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Manager Server LTS 4.3 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE openSUSE Leap 16.0 Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE openSUSE Tumbleweed Affected: ? , < 2.0.7-3.1 (custom)
    Create a notification for this product.
    libXfont2 libXfont2 Affected: ? , ≤ 2.0.8 (custom)
    Create a notification for this product.
    Date Public
    2026-08-05 08:10
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-59679",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T12:44:48.987855Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-787",
                    "description": "CWE-787 Out-of-bounds Write",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T12:45:33.969Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Container suse/kiosk/tigervnc-x11vnc:1.14-63.8",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Container suse/kiosk/xorg:21.1-83.7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Azure-3P",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-BYOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-BYOS-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-BYOS-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-BYOS-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-BYOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-BYOS-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-BYOS-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-BYOS-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAPCAL",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAPCAL-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAPCAL-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAPCAL-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Azure-3P",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-BYOS-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-BYOS-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-BYOS-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-GCE-3P",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Hardened-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Hardened-BYOS-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Hardened-BYOS-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Hardened-BYOS-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Hardened-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAPCAL-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAPCAL-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAPCAL-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-Azure-3P",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-BYOS-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-BYOS-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-BYOS-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-GCE-3P",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAPCAL-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES12-SP5-Azure-SAP-BYOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES12-SP5-Azure-SAP-On-Demand",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES12-SP5-EC2-SAP-BYOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES12-SP5-EC2-SAP-On-Demand",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES12-SP5-GCE-SAP-BYOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES12-SP5-GCE-SAP-On-Demand",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2",
              "product": "SUSE Liberty Linux 10",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.6-5.el10_2.3",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Liberty Linux 10",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.6-5.el10_2.3",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2",
              "product": "SUSE Liberty Linux 8",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-2.el8_10.3",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Liberty Linux 8",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-2.el8_10.3",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2",
              "product": "SUSE Liberty Linux 9",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-12.el9_8.3",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Liberty Linux 9",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-12.el9_8.3",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Desktop 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Desktop 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Module for Basesystem 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Module for Basesystem 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server 12 SP5-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server 15 SP4-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server 15 SP4-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server 15 SP5-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server 15 SP5-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server 15 SP6-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server 15 SP6-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server 16.0",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server 16.0",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server for SAP applications 16.0",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server for SAP applications 16.0",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server LTSS Extended Security 12 SP5",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP4",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP4",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP5",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP5",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP6",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP6",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Manager Proxy LTS 4.3",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Manager Proxy LTS 4.3",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Manager Retail Branch Server LTS 4.3",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Manager Retail Branch Server LTS 4.3",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Manager Server LTS 4.3",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Manager Server LTS 4.3",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "openSUSE Leap 16.0",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "openSUSE Leap 16.0",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "openSUSE Tumbleweed",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-3.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2-32bit",
              "product": "openSUSE Tumbleweed",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-3.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "openSUSE Tumbleweed",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-3.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel-32bit",
              "product": "openSUSE Tumbleweed",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-3.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2",
              "product": "libXfont2",
              "vendor": "libXfont2",
              "versions": [
                {
                  "lessThanOrEqual": "2.0.8",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "zx (Jace)"
            }
          ],
          "datePublic": "2026-08-05T08:10:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cpre\u003efs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the separate FS_QueryXExtents16 reply. The two CARD32 fields are never cross-checked.\u003cbr\u003eA malicious or compromised font server can send a small num_extents (e.g. 1) in the extents reply, then a large num_chars (e.g. 100000) in the bitmaps reply. This causes attacker-controlled out-of-bounds heap read and writes. \u003c/pre\u003e"
                }
              ],
              "value": "fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the separate FS_QueryXExtents16 reply. The two CARD32 fields are never cross-checked.\nA malicious or compromised font server can send a small num_extents (e.g. 1) in the extents reply, then a large num_chars (e.g. 100000) in the bitmaps reply. This causes attacker-controlled out-of-bounds heap read and writes."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.2,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:15:24.892Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-59679"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont2",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-59679",
        "datePublished": "2026-09-10T08:15:24.892Z",
        "dateReserved": "2026-07-06T11:59:28.119Z",
        "dateUpdated": "2026-09-10T12:45:33.969Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-46808 (GCVE-0-2025-46808)

    Vulnerability from cvelistv5 – Published: 2026-09-09 08:25 – Updated: 2026-09-10 14:06
    VLAI
    Title
    Sensitive information is leaked into NeuVector’s manager container logs
    Summary
    An Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive information into the manager container’s log This issue affects neuvector: before 5.4.5.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 14:05 UTC
    CWE
    • CWE-532 - Insertion of Sensitive Information into Log File
    Impacted products
    Vendor Product Version
    SUSE neuvector Affected: 0 , < 5.4.5 (semver)
    Create a notification for this product.
    Date Public
    2025-11-07 09:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-46808",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T14:05:27.065483Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T14:06:23.527Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "manager",
              "product": "neuvector",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "5.4.5",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "datePublic": "2025-11-07T09:21:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003eAn Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive information into the manager container\u2019s log\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cp\u003eThis issue affects neuvector: before 5.4.5.\u003c/p\u003e"
                }
              ],
              "value": "An Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive information into the manager container\u2019s log\n\n\n\n\n\n\nThis issue affects neuvector: before 5.4.5."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.8,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-532",
                  "description": "CWE-532: Insertion of Sensitive Information into Log File",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-09T08:25:42.467Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-46808"
            },
            {
              "url": "https://github.com/neuvector/manager/security/advisories/GHSA-fggw-hv56-8m6r"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Sensitive information is leaked into NeuVector\u2019s manager container logs",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2025-46808",
        "datePublished": "2026-09-09T08:25:42.467Z",
        "dateReserved": "2025-04-30T11:28:04.728Z",
        "dateUpdated": "2026-09-10T14:06:23.527Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-75036 (GCVE-0-2026-75036)

    Vulnerability from cvelistv5 – Published: 2026-09-03 15:15 – Updated: 2026-09-05 01:32
    VLAI
    Title
    Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessing
    Summary
    A security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet controller could reach network resources outside the management cluster. A user who can supply bundle content to a repository referenced by a `GitRepo` resource can cause the Fleet controller to: - Disclose cluster metadata available to the templating context. - Reveal information about hosts reachable from the controller's network position. Because the disclosure channel is name resolution, it may remain effective in environments where outbound traffic is otherwise restricted. The disclosed information is limited to values exposed to the Fleet templating context and to name resolution results. Integrity and availability of managed clusters are not affected. This issue affects Fleet: from 0.12.0 before 0.12.19, from 0.13.0 before 0.13.15, from 0.14.0 before 0.14.10, from 0.15.0 before 0.15.6, and from 0.16.0 before 0.16.1.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-05 01:32 UTC
    CWE
    • CWE-918 - Server-Side request forgery (SSRF)
    • CWE-1336 - Improper neutralization of special elements used in a template engine
    References
    Impacted products
    Vendor Product Version
    SUSE Fleet Affected: 0.12.0 , < 0.12.19 (semver)
    Affected: 0.13.0 , < 0.13.15 (semver)
    Affected: 0.14.0 , < 0.14.10 (semver)
    Affected: 0.15.0 , < 0.15.6 (semver)
    Affected: 0.16.0 , < 0.16.1 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-75036",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-05T01:32:24.237639Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-05T01:32:33.141Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Fleet",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "0.12.19",
                  "status": "affected",
                  "version": "0.12.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.13.15",
                  "status": "affected",
                  "version": "0.13.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.14.10",
                  "status": "affected",
                  "version": "0.14.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.15.6",
                  "status": "affected",
                  "version": "0.15.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.16.1",
                  "status": "affected",
                  "version": "0.16.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A security vulnerability was discovered in Fleet\u0027s Helm template preprocessing where templates evaluated by the Fleet controller could reach network resources outside the management cluster. A user who can supply bundle content to a repository referenced by a `GitRepo` resource can cause the Fleet controller to:\u003cbr\u003e- Disclose cluster metadata available to the templating context.\u003cbr\u003e- Reveal information about hosts reachable from the controller\u0027s network position.\u003cbr\u003eBecause the disclosure channel is name resolution, it may remain effective in environments where outbound traffic is otherwise restricted. The disclosed information is limited to values exposed to the Fleet templating context and to name resolution results. Integrity and availability of managed clusters are not affected.\u003cbr\u003e\u003cbr\u003eThis issue affects Fleet:\u003cbr\u003efrom 0.12.0 before 0.12.19, \u003cbr\u003efrom 0.13.0 before 0.13.15, \u003cbr\u003efrom 0.14.0 before 0.14.10, \u003cbr\u003efrom 0.15.0 before 0.15.6, and\u003cbr\u003efrom 0.16.0 before 0.16.1."
                }
              ],
              "value": "A security vulnerability was discovered in Fleet\u0027s Helm template preprocessing where templates evaluated by the Fleet controller could reach network resources outside the management cluster. A user who can supply bundle content to a repository referenced by a `GitRepo` resource can cause the Fleet controller to:\n- Disclose cluster metadata available to the templating context.\n- Reveal information about hosts reachable from the controller\u0027s network position.\nBecause the disclosure channel is name resolution, it may remain effective in environments where outbound traffic is otherwise restricted. The disclosed information is limited to values exposed to the Fleet templating context and to name resolution results. Integrity and availability of managed clusters are not affected.\n\nThis issue affects Fleet:\nfrom 0.12.0 before 0.12.19, \nfrom 0.13.0 before 0.13.15, \nfrom 0.14.0 before 0.14.10, \nfrom 0.15.0 before 0.15.6, and\nfrom 0.16.0 before 0.16.1."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-664",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-664 Server Side Request Forgery"
                }
              ]
            },
            {
              "capecId": "CAPEC-116",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-116 Excavation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "CWE-918 Server-Side request forgery (SSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-1336",
                  "description": "CWE-1336 Improper neutralization of special elements used in a template engine",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-03T15:15:25.490Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/rancher/fleet/security/advisories/GHSA-x9m6-xcjr-hpjp"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessing",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-75036",
        "datePublished": "2026-09-03T15:15:25.490Z",
        "dateReserved": "2026-08-17T15:22:54.444Z",
        "dateUpdated": "2026-09-05T01:32:33.141Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-75035 (GCVE-0-2026-75035)

    Vulnerability from cvelistv5 – Published: 2026-09-03 15:07 – Updated: 2026-09-05 01:25
    VLAI
    Title
    Rancher: ext.cattle.io/v1 Token store: cross-user token disclosure via label-selector scoping bypass
    Summary
    A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its internal owner filter instead of returning an empty result. Any authenticated user could therefore list and watch every other user's tokens, disclosing token metadata and the stored salted hash of the bearer token. This issue affects Rancher: before 2.15.1.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-05 01:25 UTC
    CWE
    • CWE-639 - Authorization bypass through User-Controlled key
    Impacted products
    Vendor Product Version
    SUSE Rancher Affected: 0 , < 2.15.1 (semver)
    Create a notification for this product.
    Date Public
    2026-08-31 15:01
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-75035",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-05T01:25:28.809972Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-05T01:25:40.696Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Rancher",
              "repo": "https://github.com/rancher/rancher",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.15.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "datePublic": "2026-08-31T15:01:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eA flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its internal owner filter instead of returning an empty result. Any authenticated user could therefore list and watch every other user\u0027s tokens, disclosing token metadata and the stored salted hash of the bearer token.\u003c/p\u003e\u003cp\u003eThis issue affects Rancher: before 2.15.1.\u003c/p\u003e"
                }
              ],
              "value": "A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its internal owner filter instead of returning an empty result. Any authenticated user could therefore list and watch every other user\u0027s tokens, disclosing token metadata and the stored salted hash of the bearer token.\n\n\n\nThis issue affects Rancher: before 2.15.1."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-77",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-77 Manipulating User-Controlled Variables"
                }
              ]
            },
            {
              "capecId": "CAPEC-1",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs"
                }
              ]
            },
            {
              "capecId": "CAPEC-116",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-116 Excavation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.7,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "CWE-639 Authorization bypass through User-Controlled key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-03T15:07:11.685Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "url": "https://github.com/rancher/rancher/releases/tag/v2.15.1"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Rancher: ext.cattle.io/v1 Token store: cross-user token disclosure via label-selector scoping bypass",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-75035",
        "datePublished": "2026-09-03T15:07:11.685Z",
        "dateReserved": "2026-08-17T15:22:54.444Z",
        "dateUpdated": "2026-09-05T01:25:40.696Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-75034 (GCVE-0-2026-75034)

    Vulnerability from cvelistv5 – Published: 2026-09-03 15:01 – Updated: 2026-09-04 03:56
    VLAI
    Title
    Rancher: SAML Assertion Replay
    Summary
    A flaw was found in Rancher Manager. The SAML assertion replay protection introduced by the fix for CVE-2026-44946 recorded consumed assertion IDs in a per-process cache, so each replica only detected replays that reached the same pod. In a high-availability deployment, an attacker holding a captured assertion could replay it once against every other replica to obtain additional authenticated sessions as the victim. This issue affects Rancher: before 2.15.1.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-03 00:00 UTC
    CWE
    • CWE-294 - Authentication bypass by capture-replay
    Impacted products
    Vendor Product Version
    SUSE Rancher Affected: 0 , < 2.15.1 (semver)
    Create a notification for this product.
    Date Public
    2026-08-31 14:58
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-75034",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-03T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-04T03:56:03.896Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Rancher",
              "repo": "https://github.com/rancher/rancher",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.15.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Wade Sparks"
            }
          ],
          "datePublic": "2026-08-31T14:58:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A flaw was found in Rancher Manager. The SAML assertion replay protection introduced by the fix for CVE-2026-44946 recorded consumed assertion IDs in a per-process cache, so each replica only detected replays that reached the same pod. In a high-availability deployment, an attacker holding a captured assertion could replay it once against every other replica to obtain additional authenticated sessions as the victim.\u003cbr\u003e\u003cp\u003eThis issue affects Rancher: before 2.15.1.\u003c/p\u003e"
                }
              ],
              "value": "A flaw was found in Rancher Manager. The SAML assertion replay protection introduced by the fix for CVE-2026-44946 recorded consumed assertion IDs in a per-process cache, so each replica only detected replays that reached the same pod. In a high-availability deployment, an attacker holding a captured assertion could replay it once against every other replica to obtain additional authenticated sessions as the victim.\n\n\nThis issue affects Rancher: before 2.15.1."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-60",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-60 Reusing Session IDs (aka Session Replay)"
                }
              ]
            },
            {
              "capecId": "CAPEC-94",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-94 Adversary in the Middle (AiTM)"
                }
              ]
            },
            {
              "capecId": "CAPEC-593",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-593 Session Hijacking"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.4,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-294",
                  "description": "CWE-294 Authentication bypass by capture-replay",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-03T15:01:16.635Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "url": "https://github.com/rancher/rancher/releases/tag/v2.15.1"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Rancher: SAML Assertion Replay",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-75034",
        "datePublished": "2026-09-03T15:01:16.635Z",
        "dateReserved": "2026-08-17T15:22:54.444Z",
        "dateUpdated": "2026-09-04T03:56:03.896Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-75033 (GCVE-0-2026-75033)

    Vulnerability from cvelistv5 – Published: 2026-09-03 14:57 – Updated: 2026-09-03 15:13
    VLAI
    Title
    Rancher: Cross-Cluster Secret Leakage via Namespace projectId Annotation Spoofing
    Summary
    A flaw was found in Rancher Manager. Project Secrets were propagated into a namespace based only on its `field.cattle.io/projectId` annotation, without verifying that the referenced project belonged to the same downstream cluster. A user able to create namespaces on one cluster could set the annotation to a project ID from another cluster and have that project's secrets copied into a namespace under their control. This issue affects Rancher: before 2.15.1.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-03 15:13 UTC
    CWE
    • CWE-639 - Authorization bypass through User-Controlled key
    Impacted products
    Vendor Product Version
    SUSE Rancher Affected: 0 , < 2.15.1 (semver)
    Create a notification for this product.
    Date Public
    2026-08-31 14:52
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-75033",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-03T15:13:38.725376Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-03T15:13:54.624Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Rancher",
              "repo": "https://github.com/rancher/rancher",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.15.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Alex Seymour"
            }
          ],
          "datePublic": "2026-08-31T14:52:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A flaw was found in Rancher Manager. Project Secrets were propagated into a namespace based only on its `field.cattle.io/projectId` annotation, without verifying that the referenced project belonged to the same downstream cluster. A user able to create namespaces on one cluster could set the annotation to a project ID from another cluster and have that project\u0027s secrets copied into a namespace under their control.\u003cbr\u003e\u003cp\u003eThis issue affects Rancher: before 2.15.1.\u003c/p\u003e"
                }
              ],
              "value": "A flaw was found in Rancher Manager. Project Secrets were propagated into a namespace based only on its `field.cattle.io/projectId` annotation, without verifying that the referenced project belonged to the same downstream cluster. A user able to create namespaces on one cluster could set the annotation to a project ID from another cluster and have that project\u0027s secrets copied into a namespace under their control.\n\n\nThis issue affects Rancher: before 2.15.1."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-21",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-21 Exploitation of Trusted Identifiers"
                }
              ]
            },
            {
              "capecId": "CAPEC-116",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-116 Excavation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.7,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "CWE-639 Authorization bypass through User-Controlled key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-03T14:57:34.334Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "url": "https://github.com/rancher/rancher/releases/tag/v2.15.1"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Rancher: Cross-Cluster Secret Leakage via Namespace projectId Annotation Spoofing",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-75033",
        "datePublished": "2026-09-03T14:57:34.334Z",
        "dateReserved": "2026-08-17T15:22:54.443Z",
        "dateUpdated": "2026-09-03T15:13:54.624Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-71404 (GCVE-0-2026-71404)

    Vulnerability from cvelistv5 – Published: 2026-09-03 14:51 – Updated: 2026-09-03 15:07
    VLAI
    Title
    Rancher: Ownership-less ClusterRole overwrite via attacker-controlled cr-name annotation on GlobalRole
    Summary
    A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable `authz.management.cattle.io/cr-name` annotation and overwrote that object's rules without verifying ownership. A user with delegated GlobalRole create or update permission could point the annotation at any existing ClusterRole, such as `cluster-admin`, and revoke the permissions of every principal bound to it. The change persists after the malicious GlobalRole is deleted. This issue affects Rancher: before 2.15.1.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-03 15:06 UTC
    CWE
    • CWE-639 - Authorization bypass through User-Controlled key
    Impacted products
    Vendor Product Version
    SUSE Rancher Affected: 0 , < 2.15.1 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-71404",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-03T15:06:03.098792Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-03T15:07:12.467Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Rancher",
              "repo": "https://github.com/rancher/rancher",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.15.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "https://github.com/Pig-Tail"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable `authz.management.cattle.io/cr-name` annotation and overwrote that object\u0027s rules without verifying ownership. A user with delegated GlobalRole create or update permission could point the annotation at any existing ClusterRole, such as `cluster-admin`, and revoke the permissions of every principal bound to it. The change persists after the malicious GlobalRole is deleted.\u003cbr\u003e\u003cp\u003eThis issue affects Rancher: before 2.15.1.\u003c/p\u003e"
                }
              ],
              "value": "A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable `authz.management.cattle.io/cr-name` annotation and overwrote that object\u0027s rules without verifying ownership. A user with delegated GlobalRole create or update permission could point the annotation at any existing ClusterRole, such as `cluster-admin`, and revoke the permissions of every principal bound to it. The change persists after the malicious GlobalRole is deleted.\n\n\nThis issue affects Rancher: before 2.15.1."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-176",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-176 Configuration/Environment Manipulation"
                }
              ]
            },
            {
              "capecId": "CAPEC-77",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-77 Manipulating User-Controlled Variables"
                }
              ]
            },
            {
              "capecId": "CAPEC-240",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-240 Resource Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "CWE-639 Authorization bypass through User-Controlled key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-03T14:51:44.678Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/rancher/rancher/pull/56642"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/rancher/rancher/pull/56593"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Rancher: Ownership-less ClusterRole overwrite via attacker-controlled cr-name annotation on GlobalRole",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-71404",
        "datePublished": "2026-09-03T14:51:44.678Z",
        "dateReserved": "2026-08-06T11:38:54.896Z",
        "dateUpdated": "2026-09-03T15:07:12.467Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CERTFR-2026-AVI-1202

    Vulnerability from certfr_avis - Published: 2026-09-18 - Updated: 2026-09-18

    De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    SUSE Public Cloud Module Public Cloud Module 15-SP7
    SUSE SUSE Linux Enterprise High Performance Computing SUSE Linux Enterprise High Performance Computing 15 SP5
    SUSE openSUSE Leap openSUSE Leap 15.5
    SUSE SUSE Linux Enterprise Live Patching SUSE Linux Enterprise Live Patching 15-SP5
    SUSE SUSE Linux Enterprise Real Time SUSE Linux Enterprise Real Time 15 SP7
    SUSE SUSE Linux Enterprise Server SUSE Linux Enterprise Server for SAP Applications 15 SP6
    SUSE SUSE Linux Enterprise High Performance Computing SUSE Linux Enterprise High Performance Computing 12 SP5
    SUSE SUSE Linux Enterprise High Performance Computing SUSE Linux Enterprise High Performance Computing 15 SP4
    SUSE SUSE Linux Enterprise Live Patching SUSE Linux Enterprise Live Patching 12-SP5
    SUSE openSUSE Leap openSUSE Leap 15.4
    SUSE SUSE Linux Enterprise Desktop SUSE Linux Enterprise Desktop 15 SP7
    SUSE SUSE Linux Enterprise Live Patching SUSE Linux Enterprise Live Patching 15-SP6
    SUSE SUSE Linux Enterprise Server SUSE Linux Enterprise Server for SAP Applications 12 SP5
    SUSE SUSE Linux Enterprise Live Patching SUSE Linux Enterprise Live Patching 15-SP7
    SUSE SUSE Linux Enterprise Server SUSE Linux Enterprise Server 12 SP5
    SUSE SUSE Linux Enterprise Server SUSE Linux Enterprise Server 15 SP5
    SUSE SUSE Linux Micro Extras SUSE Linux Micro Extras 6.1
    SUSE SUSE Linux Enterprise Server SUSE Linux Enterprise Server for SAP Applications 15 SP5
    SUSE openSUSE Leap openSUSE Leap 15.6
    SUSE SUSE Linux Enterprise Micro SUSE Linux Enterprise Micro 5.3
    SUSE SUSE Linux Enterprise Real Time SUSE Linux Enterprise Real Time 15 SP5
    SUSE SUSE Linux Enterprise Server SUSE Linux Enterprise Server 15 SP6
    SUSE SUSE Linux Enterprise Workstation Extension SUSE Linux Enterprise Workstation Extension 15 SP7
    SUSE SUSE Linux Enterprise Real Time SUSE Linux Enterprise Real Time 15 SP4
    SUSE SUSE Linux Enterprise Server SUSE Linux Enterprise Server for SAP Applications 15 SP7
    SUSE SUSE Linux Enterprise Server SUSE Linux Enterprise Server 11 SP4
    SUSE SUSE Linux Enterprise Server SUSE Linux Enterprise Server for SAP Applications 15 SP4
    SUSE Basesystem Module Basesystem Module 15-SP7
    SUSE SUSE Linux Enterprise High Availability Extension SUSE Linux Enterprise High Availability Extension 15 SP7
    SUSE SUSE Linux Micro SUSE Linux Micro 6.2
    SUSE SUSE Linux Enterprise Micro SUSE Linux Enterprise Micro 5.5
    SUSE SUSE Linux Enterprise Server SUSE Linux Enterprise Server 15 SP4
    SUSE SUSE Linux Enterprise Real Time SUSE Linux Enterprise Real Time 15 SP6
    SUSE SUSE Linux Micro SUSE Linux Micro 6.1
    SUSE Legacy Module Legacy Module 15-SP7
    SUSE SUSE Linux Enterprise Server SUSE Linux Enterprise Server 15 SP7
    SUSE Development Tools Module Development Tools Module 15-SP7
    SUSE SUSE Linux Enterprise Micro SUSE Linux Enterprise Micro 5.4
    SUSE SUSE Linux Enterprise Live Patching SUSE Linux Enterprise Live Patching 15-SP4
    SUSE SUSE Linux Enterprise Server SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE
    References
    Bulletin de sécurité SUSE SUSE-SU-2026:23540-1 2026-09-08 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:4256-1 2026-09-17 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23686-1 2026-09-12 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23681-1 2026-09-12 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:4172-1 2026-09-14 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23536-1 2026-09-08 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23674-1 2026-09-12 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23678-1 2026-09-12 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23685-1 2026-09-12 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:4170-1 2026-09-14 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23687-1 2026-09-13 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23676-1 2026-09-12 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23680-1 2026-09-12 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:4224-1 2026-09-17 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:4190-1 2026-09-15 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23537-1 2026-09-08 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23528-1 2026-09-08 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23682-1 2026-09-12 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:4231-1 2026-09-17 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:4244-1 2026-09-17 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:4185-1 2026-09-15 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:4254-1 2026-09-17 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:4162-1 2026-09-14 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23510-1 2026-09-08 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23679-1 2026-09-12 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23684-1 2026-09-12 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23535-1 2026-09-08 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23531-1 2026-09-08 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23529-1 2026-09-08 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23672-1 2026-09-12 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23541-1 2026-09-08 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23673-1 2026-09-12 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:4193-1 2026-09-15 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23533-1 2026-09-08 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23683-1 2026-09-12 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:4215-1 2026-09-16 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:4168-1 2026-09-14 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23677-1 2026-09-12 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:4243-1 2026-09-17 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:4183-1 2026-09-15 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23532-1 2026-09-08 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:4192-1 2026-09-15 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23675-1 2026-09-12 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23534-1 2026-09-08 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:4255-1 2026-09-17 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Public Cloud Module 15-SP7",
          "product": {
            "name": "Public Cloud Module",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise High Performance Computing 15 SP5",
          "product": {
            "name": "SUSE Linux Enterprise High Performance Computing",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "openSUSE Leap 15.5",
          "product": {
            "name": "openSUSE Leap",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Live Patching 15-SP5",
          "product": {
            "name": "SUSE Linux Enterprise Live Patching",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Real Time 15 SP7",
          "product": {
            "name": "SUSE Linux Enterprise Real Time",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Server for SAP Applications 15 SP6",
          "product": {
            "name": "SUSE Linux Enterprise Server",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise High Performance Computing 12 SP5",
          "product": {
            "name": "SUSE Linux Enterprise High Performance Computing",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise High Performance Computing 15 SP4",
          "product": {
            "name": "SUSE Linux Enterprise High Performance Computing",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Live Patching 12-SP5",
          "product": {
            "name": "SUSE Linux Enterprise Live Patching",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "openSUSE Leap 15.4",
          "product": {
            "name": "openSUSE Leap",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Desktop 15 SP7",
          "product": {
            "name": "SUSE Linux Enterprise Desktop",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Live Patching 15-SP6",
          "product": {
            "name": "SUSE Linux Enterprise Live Patching",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Server for SAP Applications 12 SP5",
          "product": {
            "name": "SUSE Linux Enterprise Server",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Live Patching 15-SP7",
          "product": {
            "name": "SUSE Linux Enterprise Live Patching",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Server 12 SP5",
          "product": {
            "name": "SUSE Linux Enterprise Server",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Server 15 SP5",
          "product": {
            "name": "SUSE Linux Enterprise Server",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Micro Extras 6.1",
          "product": {
            "name": "SUSE Linux Micro Extras",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Server for SAP Applications 15 SP5",
          "product": {
            "name": "SUSE Linux Enterprise Server",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "openSUSE Leap 15.6",
          "product": {
            "name": "openSUSE Leap",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Micro 5.3",
          "product": {
            "name": "SUSE Linux Enterprise Micro",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Real Time 15 SP5",
          "product": {
            "name": "SUSE Linux Enterprise Real Time",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Server 15 SP6",
          "product": {
            "name": "SUSE Linux Enterprise Server",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Workstation Extension 15 SP7",
          "product": {
            "name": "SUSE Linux Enterprise Workstation Extension",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Real Time 15 SP4",
          "product": {
            "name": "SUSE Linux Enterprise Real Time",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Server for SAP Applications 15 SP7",
          "product": {
            "name": "SUSE Linux Enterprise Server",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Server 11 SP4",
          "product": {
            "name": "SUSE Linux Enterprise Server",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Server for SAP Applications 15 SP4",
          "product": {
            "name": "SUSE Linux Enterprise Server",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "Basesystem Module 15-SP7",
          "product": {
            "name": "Basesystem Module",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise High Availability Extension 15 SP7",
          "product": {
            "name": "SUSE Linux Enterprise High Availability Extension",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Micro 6.2",
          "product": {
            "name": "SUSE Linux Micro",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Micro 5.5",
          "product": {
            "name": "SUSE Linux Enterprise Micro",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Server 15 SP4",
          "product": {
            "name": "SUSE Linux Enterprise Server",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Real Time 15 SP6",
          "product": {
            "name": "SUSE Linux Enterprise Real Time",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Micro 6.1",
          "product": {
            "name": "SUSE Linux Micro",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "Legacy Module 15-SP7",
          "product": {
            "name": "Legacy Module",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Server 15 SP7",
          "product": {
            "name": "SUSE Linux Enterprise Server",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "Development Tools Module 15-SP7",
          "product": {
            "name": "Development Tools Module",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Micro 5.4",
          "product": {
            "name": "SUSE Linux Enterprise Micro",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Live Patching 15-SP4",
          "product": {
            "name": "SUSE Linux Enterprise Live Patching",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE",
          "product": {
            "name": "SUSE Linux Enterprise Server",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-68116",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68116"
        },
        {
          "name": "CVE-2025-71075",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-71075"
        },
        {
          "name": "CVE-2026-64214",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64214"
        },
        {
          "name": "CVE-2026-53091",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53091"
        },
        {
          "name": "CVE-2026-64376",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64376"
        },
        {
          "name": "CVE-2026-74395",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74395"
        },
        {
          "name": "CVE-2026-68343",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68343"
        },
        {
          "name": "CVE-2026-64552",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64552"
        },
        {
          "name": "CVE-2026-64287",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64287"
        },
        {
          "name": "CVE-2026-53381",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53381"
        },
        {
          "name": "CVE-2026-64275",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64275"
        },
        {
          "name": "CVE-2026-64274",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64274"
        },
        {
          "name": "CVE-2026-64538",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64538"
        },
        {
          "name": "CVE-2026-74394",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74394"
        },
        {
          "name": "CVE-2026-68450",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68450"
        },
        {
          "name": "CVE-2026-68480",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68480"
        },
        {
          "name": "CVE-2026-68271",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68271"
        },
        {
          "name": "CVE-2026-74297",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74297"
        },
        {
          "name": "CVE-2026-64561",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64561"
        },
        {
          "name": "CVE-2026-64133",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64133"
        },
        {
          "name": "CVE-2026-31658",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31658"
        },
        {
          "name": "CVE-2026-64047",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64047"
        },
        {
          "name": "CVE-2026-74481",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74481"
        },
        {
          "name": "CVE-2026-68138",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68138"
        },
        {
          "name": "CVE-2026-64192",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64192"
        },
        {
          "name": "CVE-2026-52955",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52955"
        },
        {
          "name": "CVE-2026-68193",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68193"
        },
        {
          "name": "CVE-2026-68204",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68204"
        },
        {
          "name": "CVE-2026-52925",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52925"
        },
        {
          "name": "CVE-2026-74669",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74669"
        },
        {
          "name": "CVE-2026-68302",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68302"
        },
        {
          "name": "CVE-2026-64452",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64452"
        },
        {
          "name": "CVE-2026-52929",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52929"
        },
        {
          "name": "CVE-2026-68081",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68081"
        },
        {
          "name": "CVE-2026-64483",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64483"
        },
        {
          "name": "CVE-2026-63980",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63980"
        },
        {
          "name": "CVE-2026-74482",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74482"
        },
        {
          "name": "CVE-2026-64322",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64322"
        },
        {
          "name": "CVE-2026-43448",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43448"
        },
        {
          "name": "CVE-2026-64470",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64470"
        },
        {
          "name": "CVE-2026-63923",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63923"
        },
        {
          "name": "CVE-2026-68339",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68339"
        },
        {
          "name": "CVE-2026-64513",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64513"
        },
        {
          "name": "CVE-2026-68218",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68218"
        },
        {
          "name": "CVE-2026-68088",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68088"
        },
        {
          "name": "CVE-2026-64388",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64388"
        },
        {
          "name": "CVE-2026-64512",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64512"
        },
        {
          "name": "CVE-2026-64409",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64409"
        },
        {
          "name": "CVE-2026-68129",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68129"
        },
        {
          "name": "CVE-2026-74571",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74571"
        },
        {
          "name": "CVE-2026-68245",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68245"
        },
        {
          "name": "CVE-2026-64268",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64268"
        },
        {
          "name": "CVE-2026-68428",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68428"
        },
        {
          "name": "CVE-2026-64099",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64099"
        },
        {
          "name": "CVE-2026-64489",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64489"
        },
        {
          "name": "CVE-2026-74581",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74581"
        },
        {
          "name": "CVE-2026-64480",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64480"
        },
        {
          "name": "CVE-2026-72494",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72494"
        },
        {
          "name": "CVE-2026-64257",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64257"
        },
        {
          "name": "CVE-2026-64006",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64006"
        },
        {
          "name": "CVE-2026-68313",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68313"
        },
        {
          "name": "CVE-2026-64385",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64385"
        },
        {
          "name": "CVE-2026-74537",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74537"
        },
        {
          "name": "CVE-2026-63995",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63995"
        },
        {
          "name": "CVE-2026-64217",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64217"
        },
        {
          "name": "CVE-2026-46319",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46319"
        },
        {
          "name": "CVE-2026-68326",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68326"
        },
        {
          "name": "CVE-2026-68184",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68184"
        },
        {
          "name": "CVE-2026-64454",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64454"
        },
        {
          "name": "CVE-2026-64407",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64407"
        },
        {
          "name": "CVE-2026-68417",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68417"
        },
        {
          "name": "CVE-2026-64527",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64527"
        },
        {
          "name": "CVE-2026-23227",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-23227"
        },
        {
          "name": "CVE-2026-74563",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74563"
        },
        {
          "name": "CVE-2026-23454",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-23454"
        },
        {
          "name": "CVE-2026-68248",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68248"
        },
        {
          "name": "CVE-2026-63886",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63886"
        },
        {
          "name": "CVE-2026-64365",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64365"
        },
        {
          "name": "CVE-2026-53260",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53260"
        },
        {
          "name": "CVE-2026-64128",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64128"
        },
        {
          "name": "CVE-2026-68277",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68277"
        },
        {
          "name": "CVE-2026-68288",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68288"
        },
        {
          "name": "CVE-2026-68410",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68410"
        },
        {
          "name": "CVE-2026-68437",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68437"
        },
        {
          "name": "CVE-2026-68261",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68261"
        },
        {
          "name": "CVE-2026-74345",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74345"
        },
        {
          "name": "CVE-2025-40204",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-40204"
        },
        {
          "name": "CVE-2026-72083",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72083"
        },
        {
          "name": "CVE-2026-64333",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64333"
        },
        {
          "name": "CVE-2026-68304",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68304"
        },
        {
          "name": "CVE-2026-68155",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68155"
        },
        {
          "name": "CVE-2026-63928",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63928"
        },
        {
          "name": "CVE-2026-68132",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68132"
        },
        {
          "name": "CVE-2026-64574",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64574"
        },
        {
          "name": "CVE-2026-63879",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63879"
        },
        {
          "name": "CVE-2026-68102",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68102"
        },
        {
          "name": "CVE-2026-74488",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74488"
        },
        {
          "name": "CVE-2026-68086",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68086"
        },
        {
          "name": "CVE-2025-39939",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-39939"
        },
        {
          "name": "CVE-2026-53220",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53220"
        },
        {
          "name": "CVE-2026-64246",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64246"
        },
        {
          "name": "CVE-2026-68085",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68085"
        },
        {
          "name": "CVE-2026-68446",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68446"
        },
        {
          "name": "CVE-2026-68408",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68408"
        },
        {
          "name": "CVE-2026-64386",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64386"
        },
        {
          "name": "CVE-2026-43163",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43163"
        },
        {
          "name": "CVE-2026-68226",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68226"
        },
        {
          "name": "CVE-2026-53365",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53365"
        },
        {
          "name": "CVE-2026-68350",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68350"
        },
        {
          "name": "CVE-2026-23210",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-23210"
        },
        {
          "name": "CVE-2026-68419",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68419"
        },
        {
          "name": "CVE-2026-68091",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68091"
        },
        {
          "name": "CVE-2026-68297",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68297"
        },
        {
          "name": "CVE-2026-53224",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53224"
        },
        {
          "name": "CVE-2026-53360",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53360"
        },
        {
          "name": "CVE-2026-68199",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68199"
        },
        {
          "name": "CVE-2026-64383",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64383"
        },
        {
          "name": "CVE-2026-68425",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68425"
        },
        {
          "name": "CVE-2026-64337",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64337"
        },
        {
          "name": "CVE-2026-63888",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63888"
        },
        {
          "name": "CVE-2026-52956",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52956"
        },
        {
          "name": "CVE-2026-80534",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-80534"
        },
        {
          "name": "CVE-2026-72466",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72466"
        },
        {
          "name": "CVE-2026-64178",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64178"
        },
        {
          "name": "CVE-2026-64497",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64497"
        },
        {
          "name": "CVE-2026-53163",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53163"
        },
        {
          "name": "CVE-2026-46195",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46195"
        },
        {
          "name": "CVE-2026-64599",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64599"
        },
        {
          "name": "CVE-2026-68293",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68293"
        },
        {
          "name": "CVE-2026-68365",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68365"
        },
        {
          "name": "CVE-2026-72254",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72254"
        },
        {
          "name": "CVE-2026-64598",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64598"
        },
        {
          "name": "CVE-2026-68320",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68320"
        },
        {
          "name": "CVE-2026-63810",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63810"
        },
        {
          "name": "CVE-2026-31531",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31531"
        },
        {
          "name": "CVE-2026-64098",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64098"
        },
        {
          "name": "CVE-2026-63801",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63801"
        },
        {
          "name": "CVE-2026-63827",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63827"
        },
        {
          "name": "CVE-2026-64304",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64304"
        },
        {
          "name": "CVE-2026-43014",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43014"
        },
        {
          "name": "CVE-2026-68280",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68280"
        },
        {
          "name": "CVE-2026-68362",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68362"
        },
        {
          "name": "CVE-2025-68179",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-68179"
        },
        {
          "name": "CVE-2026-63842",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63842"
        },
        {
          "name": "CVE-2026-68430",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68430"
        },
        {
          "name": "CVE-2026-68427",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68427"
        },
        {
          "name": "CVE-2026-43319",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43319"
        },
        {
          "name": "CVE-2026-64146",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64146"
        },
        {
          "name": "CVE-2026-72500",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72500"
        },
        {
          "name": "CVE-2026-53309",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53309"
        },
        {
          "name": "CVE-2026-68324",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68324"
        },
        {
          "name": "CVE-2026-68308",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68308"
        },
        {
          "name": "CVE-2026-64276",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64276"
        },
        {
          "name": "CVE-2026-64190",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64190"
        },
        {
          "name": "CVE-2026-68210",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68210"
        },
        {
          "name": "CVE-2026-64237",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64237"
        },
        {
          "name": "CVE-2026-64323",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64323"
        },
        {
          "name": "CVE-2026-68267",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68267"
        },
        {
          "name": "CVE-2026-68309",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68309"
        },
        {
          "name": "CVE-2026-68403",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68403"
        },
        {
          "name": "CVE-2026-68139",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68139"
        },
        {
          "name": "CVE-2026-64271",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64271"
        },
        {
          "name": "CVE-2026-74566",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74566"
        },
        {
          "name": "CVE-2026-52939",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52939"
        },
        {
          "name": "CVE-2026-63925",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63925"
        },
        {
          "name": "CVE-2026-68093",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68093"
        },
        {
          "name": "CVE-2026-72262",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72262"
        },
        {
          "name": "CVE-2026-68166",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68166"
        },
        {
          "name": "CVE-2026-63990",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63990"
        },
        {
          "name": "CVE-2026-64455",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64455"
        },
        {
          "name": "CVE-2026-72467",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72467"
        },
        {
          "name": "CVE-2026-64421",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64421"
        },
        {
          "name": "CVE-2026-64584",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64584"
        },
        {
          "name": "CVE-2026-64445",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64445"
        },
        {
          "name": "CVE-2026-52935",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52935"
        },
        {
          "name": "CVE-2026-68310",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68310"
        },
        {
          "name": "CVE-2026-64433",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64433"
        },
        {
          "name": "CVE-2026-68115",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68115"
        },
        {
          "name": "CVE-2026-68133",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68133"
        },
        {
          "name": "CVE-2026-68246",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68246"
        },
        {
          "name": "CVE-2026-64563",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64563"
        },
        {
          "name": "CVE-2026-68405",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68405"
        },
        {
          "name": "CVE-2026-68219",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68219"
        },
        {
          "name": "CVE-2026-68216",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68216"
        },
        {
          "name": "CVE-2026-64500",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64500"
        },
        {
          "name": "CVE-2026-53094",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53094"
        },
        {
          "name": "CVE-2026-64097",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64097"
        },
        {
          "name": "CVE-2026-68328",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68328"
        },
        {
          "name": "CVE-2026-68394",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68394"
        },
        {
          "name": "CVE-2026-53330",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53330"
        },
        {
          "name": "CVE-2025-23137",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-23137"
        },
        {
          "name": "CVE-2026-64348",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64348"
        },
        {
          "name": "CVE-2026-68196",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68196"
        },
        {
          "name": "CVE-2026-64362",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64362"
        },
        {
          "name": "CVE-2026-72464",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72464"
        },
        {
          "name": "CVE-2026-68269",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68269"
        },
        {
          "name": "CVE-2026-68255",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68255"
        },
        {
          "name": "CVE-2026-64102",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64102"
        },
        {
          "name": "CVE-2026-68363",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68363"
        },
        {
          "name": "CVE-2026-46091",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46091"
        },
        {
          "name": "CVE-2026-68213",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68213"
        },
        {
          "name": "CVE-2026-68278",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68278"
        },
        {
          "name": "CVE-2026-64486",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64486"
        },
        {
          "name": "CVE-2026-68145",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68145"
        },
        {
          "name": "CVE-2026-64517",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64517"
        },
        {
          "name": "CVE-2026-74454",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74454"
        },
        {
          "name": "CVE-2026-64341",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64341"
        },
        {
          "name": "CVE-2026-72342",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72342"
        },
        {
          "name": "CVE-2026-80580",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-80580"
        },
        {
          "name": "CVE-2026-64338",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64338"
        },
        {
          "name": "CVE-2026-68361",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68361"
        },
        {
          "name": "CVE-2026-64083",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64083"
        },
        {
          "name": "CVE-2026-68181",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68181"
        },
        {
          "name": "CVE-2026-46037",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46037"
        },
        {
          "name": "CVE-2026-46116",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46116"
        },
        {
          "name": "CVE-2026-64249",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64249"
        },
        {
          "name": "CVE-2026-72222",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72222"
        },
        {
          "name": "CVE-2026-64536",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64536"
        },
        {
          "name": "CVE-2026-43213",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43213"
        },
        {
          "name": "CVE-2026-64570",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64570"
        },
        {
          "name": "CVE-2026-63850",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63850"
        },
        {
          "name": "CVE-2026-31663",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31663"
        },
        {
          "name": "CVE-2026-68113",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68113"
        },
        {
          "name": "CVE-2026-68286",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68286"
        },
        {
          "name": "CVE-2026-64010",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64010"
        },
        {
          "name": "CVE-2026-64243",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64243"
        },
        {
          "name": "CVE-2026-52975",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52975"
        },
        {
          "name": "CVE-2026-68160",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68160"
        },
        {
          "name": "CVE-2026-46127",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46127"
        },
        {
          "name": "CVE-2026-64553",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64553"
        },
        {
          "name": "CVE-2026-68157",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68157"
        },
        {
          "name": "CVE-2026-64351",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64351"
        },
        {
          "name": "CVE-2026-64051",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64051"
        },
        {
          "name": "CVE-2026-23230",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-23230"
        },
        {
          "name": "CVE-2026-64039",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64039"
        },
        {
          "name": "CVE-2026-68368",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68368"
        },
        {
          "name": "CVE-2026-68281",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68281"
        },
        {
          "name": "CVE-2026-74474",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74474"
        },
        {
          "name": "CVE-2026-68335",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68335"
        },
        {
          "name": "CVE-2026-53353",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53353"
        },
        {
          "name": "CVE-2026-68426",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68426"
        },
        {
          "name": "CVE-2026-68329",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68329"
        },
        {
          "name": "CVE-2026-68189",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68189"
        },
        {
          "name": "CVE-2026-64375",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64375"
        },
        {
          "name": "CVE-2026-64296",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64296"
        },
        {
          "name": "CVE-2026-72307",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72307"
        },
        {
          "name": "CVE-2026-64546",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64546"
        },
        {
          "name": "CVE-2026-63926",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63926"
        },
        {
          "name": "CVE-2026-68212",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68212"
        },
        {
          "name": "CVE-2026-53110",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53110"
        },
        {
          "name": "CVE-2026-64593",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64593"
        },
        {
          "name": "CVE-2026-23240",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-23240"
        },
        {
          "name": "CVE-2026-64568",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64568"
        },
        {
          "name": "CVE-2026-63865",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63865"
        },
        {
          "name": "CVE-2026-64052",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64052"
        },
        {
          "name": "CVE-2026-68389",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68389"
        },
        {
          "name": "CVE-2026-64603",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64603"
        },
        {
          "name": "CVE-2026-53219",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53219"
        },
        {
          "name": "CVE-2026-68215",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68215"
        },
        {
          "name": "CVE-2026-64109",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64109"
        },
        {
          "name": "CVE-2026-64085",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64085"
        },
        {
          "name": "CVE-2026-64166",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64166"
        },
        {
          "name": "CVE-2026-31418",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31418"
        },
        {
          "name": "CVE-2026-64504",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64504"
        },
        {
          "name": "CVE-2026-68369",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68369"
        },
        {
          "name": "CVE-2026-63898",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63898"
        },
        {
          "name": "CVE-2026-64148",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64148"
        },
        {
          "name": "CVE-2026-72495",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72495"
        },
        {
          "name": "CVE-2026-64004",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64004"
        },
        {
          "name": "CVE-2026-31392",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31392"
        },
        {
          "name": "CVE-2026-63992",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63992"
        },
        {
          "name": "CVE-2026-64155",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64155"
        },
        {
          "name": "CVE-2026-72084",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72084"
        },
        {
          "name": "CVE-2026-68340",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68340"
        },
        {
          "name": "CVE-2026-72317",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72317"
        },
        {
          "name": "CVE-2026-68352",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68352"
        },
        {
          "name": "CVE-2026-68106",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68106"
        },
        {
          "name": "CVE-2026-46242",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46242"
        },
        {
          "name": "CVE-2026-63996",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63996"
        },
        {
          "name": "CVE-2026-68197",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68197"
        },
        {
          "name": "CVE-2026-64343",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64343"
        },
        {
          "name": "CVE-2026-64021",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64021"
        },
        {
          "name": "CVE-2026-68315",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68315"
        },
        {
          "name": "CVE-2026-68346",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68346"
        },
        {
          "name": "CVE-2026-68377",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68377"
        },
        {
          "name": "CVE-2026-68413",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68413"
        },
        {
          "name": "CVE-2026-68372",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68372"
        },
        {
          "name": "CVE-2026-64471",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64471"
        },
        {
          "name": "CVE-2026-64180",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64180"
        },
        {
          "name": "CVE-2026-68357",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68357"
        },
        {
          "name": "CVE-2026-53034",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53034"
        },
        {
          "name": "CVE-2024-57841",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-57841"
        },
        {
          "name": "CVE-2026-74318",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74318"
        },
        {
          "name": "CVE-2026-68399",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68399"
        },
        {
          "name": "CVE-2026-64539",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64539"
        },
        {
          "name": "CVE-2026-64602",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64602"
        },
        {
          "name": "CVE-2026-64583",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64583"
        },
        {
          "name": "CVE-2026-64125",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64125"
        },
        {
          "name": "CVE-2026-68418",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68418"
        },
        {
          "name": "CVE-2026-64551",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64551"
        },
        {
          "name": "CVE-2026-53111",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53111"
        },
        {
          "name": "CVE-2026-68312",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68312"
        },
        {
          "name": "CVE-2026-80529",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-80529"
        },
        {
          "name": "CVE-2026-68262",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68262"
        },
        {
          "name": "CVE-2026-68194",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68194"
        },
        {
          "name": "CVE-2026-64131",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64131"
        },
        {
          "name": "CVE-2026-64048",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64048"
        },
        {
          "name": "CVE-2026-31759",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31759"
        },
        {
          "name": "CVE-2026-68127",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68127"
        },
        {
          "name": "CVE-2026-72341",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72341"
        },
        {
          "name": "CVE-2026-68112",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68112"
        },
        {
          "name": "CVE-2026-64306",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64306"
        },
        {
          "name": "CVE-2026-64313",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64313"
        },
        {
          "name": "CVE-2026-52994",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52994"
        },
        {
          "name": "CVE-2026-64112",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64112"
        },
        {
          "name": "CVE-2026-64442",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64442"
        },
        {
          "name": "CVE-2026-64554",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64554"
        },
        {
          "name": "CVE-2026-64477",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64477"
        },
        {
          "name": "CVE-2026-64463",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64463"
        },
        {
          "name": "CVE-2026-64401",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64401"
        },
        {
          "name": "CVE-2026-68159",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68159"
        },
        {
          "name": "CVE-2026-74694",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74694"
        },
        {
          "name": "CVE-2026-64018",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64018"
        },
        {
          "name": "CVE-2026-64541",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64541"
        },
        {
          "name": "CVE-2026-64332",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64332"
        },
        {
          "name": "CVE-2026-63920",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63920"
        },
        {
          "name": "CVE-2026-68202",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68202"
        },
        {
          "name": "CVE-2026-72389",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72389"
        },
        {
          "name": "CVE-2026-72498",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72498"
        },
        {
          "name": "CVE-2026-53096",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53096"
        },
        {
          "name": "CVE-2026-72499",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72499"
        },
        {
          "name": "CVE-2026-43077",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43077"
        },
        {
          "name": "CVE-2026-64127",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64127"
        },
        {
          "name": "CVE-2026-68104",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68104"
        },
        {
          "name": "CVE-2026-64378",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64378"
        },
        {
          "name": "CVE-2026-53076",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53076"
        },
        {
          "name": "CVE-2026-64549",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64549"
        },
        {
          "name": "CVE-2026-68137",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68137"
        },
        {
          "name": "CVE-2026-68143",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68143"
        },
        {
          "name": "CVE-2026-53182",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53182"
        },
        {
          "name": "CVE-2026-64055",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64055"
        },
        {
          "name": "CVE-2026-46070",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46070"
        },
        {
          "name": "CVE-2026-53207",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53207"
        },
        {
          "name": "CVE-2026-68349",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68349"
        },
        {
          "name": "CVE-2026-64244",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64244"
        },
        {
          "name": "CVE-2025-40199",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-40199"
        },
        {
          "name": "CVE-2026-74496",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74496"
        },
        {
          "name": "CVE-2026-46150",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46150"
        },
        {
          "name": "CVE-2026-68257",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68257"
        },
        {
          "name": "CVE-2026-53126",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53126"
        },
        {
          "name": "CVE-2026-68252",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68252"
        },
        {
          "name": "CVE-2026-63970",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63970"
        },
        {
          "name": "CVE-2026-72502",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72502"
        },
        {
          "name": "CVE-2026-68351",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68351"
        },
        {
          "name": "CVE-2026-68289",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68289"
        },
        {
          "name": "CVE-2026-43271",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43271"
        },
        {
          "name": "CVE-2026-68402",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68402"
        },
        {
          "name": "CVE-2026-72463",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72463"
        },
        {
          "name": "CVE-2026-64224",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64224"
        },
        {
          "name": "CVE-2026-68117",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68117"
        },
        {
          "name": "CVE-2026-64559",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64559"
        },
        {
          "name": "CVE-2026-68333",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68333"
        },
        {
          "name": "CVE-2026-64544",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64544"
        },
        {
          "name": "CVE-2026-68386",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68386"
        },
        {
          "name": "CVE-2025-71104",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-71104"
        },
        {
          "name": "CVE-2026-68111",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68111"
        },
        {
          "name": "CVE-2026-64577",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64577"
        },
        {
          "name": "CVE-2026-64115",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64115"
        },
        {
          "name": "CVE-2026-52946",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52946"
        },
        {
          "name": "CVE-2026-53059",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53059"
        },
        {
          "name": "CVE-2026-72308",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72308"
        },
        {
          "name": "CVE-2026-53133",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53133"
        },
        {
          "name": "CVE-2026-74334",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74334"
        },
        {
          "name": "CVE-2026-68142",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68142"
        },
        {
          "name": "CVE-2026-64427",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64427"
        },
        {
          "name": "CVE-2026-68243",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68243"
        },
        {
          "name": "CVE-2026-64164",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64164"
        },
        {
          "name": "CVE-2026-64346",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64346"
        },
        {
          "name": "CVE-2026-68209",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68209"
        },
        {
          "name": "CVE-2026-68306",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68306"
        },
        {
          "name": "CVE-2026-53263",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53263"
        },
        {
          "name": "CVE-2026-63891",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63891"
        },
        {
          "name": "CVE-2026-68207",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68207"
        },
        {
          "name": "CVE-2026-64342",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64342"
        },
        {
          "name": "CVE-2026-68373",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68373"
        },
        {
          "name": "CVE-2026-63985",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63985"
        },
        {
          "name": "CVE-2026-64478",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64478"
        },
        {
          "name": "CVE-2026-68206",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68206"
        },
        {
          "name": "CVE-2026-68110",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68110"
        },
        {
          "name": "CVE-2026-74577",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74577"
        },
        {
          "name": "CVE-2026-64472",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64472"
        },
        {
          "name": "CVE-2026-74516",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74516"
        },
        {
          "name": "CVE-2026-64581",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64581"
        },
        {
          "name": "CVE-2026-64585",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64585"
        },
        {
          "name": "CVE-2026-72132",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72132"
        },
        {
          "name": "CVE-2026-64335",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64335"
        },
        {
          "name": "CVE-2026-68391",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68391"
        },
        {
          "name": "CVE-2026-53228",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53228"
        },
        {
          "name": "CVE-2026-64315",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64315"
        },
        {
          "name": "CVE-2026-68227",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68227"
        },
        {
          "name": "CVE-2026-68348",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68348"
        },
        {
          "name": "CVE-2026-64273",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64273"
        },
        {
          "name": "CVE-2026-63828",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63828"
        },
        {
          "name": "CVE-2026-68331",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68331"
        },
        {
          "name": "CVE-2026-74567",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74567"
        },
        {
          "name": "CVE-2026-68238",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68238"
        },
        {
          "name": "CVE-2026-53336",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53336"
        },
        {
          "name": "CVE-2026-74582",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74582"
        },
        {
          "name": "CVE-2026-68432",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68432"
        },
        {
          "name": "CVE-2026-64084",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64084"
        },
        {
          "name": "CVE-2026-64014",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64014"
        },
        {
          "name": "CVE-2026-74548",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74548"
        },
        {
          "name": "CVE-2026-64001",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64001"
        },
        {
          "name": "CVE-2026-64545",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64545"
        },
        {
          "name": "CVE-2026-74518",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74518"
        },
        {
          "name": "CVE-2026-53388",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53388"
        },
        {
          "name": "CVE-2026-63937",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63937"
        },
        {
          "name": "CVE-2026-45897",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45897"
        },
        {
          "name": "CVE-2026-64305",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64305"
        },
        {
          "name": "CVE-2026-80590",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-80590"
        },
        {
          "name": "CVE-2026-43015",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43015"
        },
        {
          "name": "CVE-2026-68398",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68398"
        },
        {
          "name": "CVE-2026-68322",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68322"
        },
        {
          "name": "CVE-2026-64381",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64381"
        },
        {
          "name": "CVE-2026-64604",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64604"
        },
        {
          "name": "CVE-2026-53337",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53337"
        },
        {
          "name": "CVE-2026-68429",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68429"
        },
        {
          "name": "CVE-2026-64597",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64597"
        },
        {
          "name": "CVE-2026-63887",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63887"
        },
        {
          "name": "CVE-2026-68136",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68136"
        },
        {
          "name": "CVE-2026-64496",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64496"
        },
        {
          "name": "CVE-2025-39964",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-39964"
        },
        {
          "name": "CVE-2026-64113",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64113"
        },
        {
          "name": "CVE-2026-64387",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64387"
        },
        {
          "name": "CVE-2026-68263",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68263"
        },
        {
          "name": "CVE-2026-68299",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68299"
        },
        {
          "name": "CVE-2026-63972",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63972"
        },
        {
          "name": "CVE-2026-68082",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68082"
        },
        {
          "name": "CVE-2026-68366",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68366"
        },
        {
          "name": "CVE-2026-46274",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46274"
        },
        {
          "name": "CVE-2026-64408",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64408"
        },
        {
          "name": "CVE-2026-68156",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68156"
        },
        {
          "name": "CVE-2026-74695",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74695"
        },
        {
          "name": "CVE-2026-64136",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64136"
        },
        {
          "name": "CVE-2026-68121",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68121"
        },
        {
          "name": "CVE-2026-68231",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68231"
        },
        {
          "name": "CVE-2026-68182",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68182"
        },
        {
          "name": "CVE-2026-74717",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74717"
        },
        {
          "name": "CVE-2026-64481",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64481"
        },
        {
          "name": "CVE-2026-64316",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64316"
        },
        {
          "name": "CVE-2026-72036",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72036"
        },
        {
          "name": "CVE-2026-68422",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68422"
        },
        {
          "name": "CVE-2026-64000",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64000"
        },
        {
          "name": "CVE-2026-68327",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68327"
        },
        {
          "name": "CVE-2026-64582",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64582"
        },
        {
          "name": "CVE-2026-53223",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53223"
        },
        {
          "name": "CVE-2026-64423",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64423"
        },
        {
          "name": "CVE-2026-64034",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64034"
        },
        {
          "name": "CVE-2026-74610",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74610"
        },
        {
          "name": "CVE-2026-64443",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64443"
        },
        {
          "name": "CVE-2026-68433",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68433"
        },
        {
          "name": "CVE-2026-68195",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68195"
        },
        {
          "name": "CVE-2026-31557",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31557"
        },
        {
          "name": "CVE-2026-63868",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63868"
        },
        {
          "name": "CVE-2026-72123",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72123"
        },
        {
          "name": "CVE-2026-64269",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64269"
        },
        {
          "name": "CVE-2026-45968",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45968"
        },
        {
          "name": "CVE-2026-64540",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64540"
        },
        {
          "name": "CVE-2026-72296",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72296"
        },
        {
          "name": "CVE-2024-44981",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-44981"
        },
        {
          "name": "CVE-2026-64482",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64482"
        },
        {
          "name": "CVE-2026-64218",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64218"
        },
        {
          "name": "CVE-2026-64495",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64495"
        },
        {
          "name": "CVE-2026-72072",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72072"
        },
        {
          "name": "CVE-2026-68279",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68279"
        },
        {
          "name": "CVE-2026-68205",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68205"
        },
        {
          "name": "CVE-2026-68234",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68234"
        },
        {
          "name": "CVE-2026-52920",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52920"
        },
        {
          "name": "CVE-2026-53001",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53001"
        },
        {
          "name": "CVE-2026-43206",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43206"
        },
        {
          "name": "CVE-2026-43273",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43273"
        },
        {
          "name": "CVE-2026-74510",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74510"
        },
        {
          "name": "CVE-2026-68256",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68256"
        },
        {
          "name": "CVE-2026-68303",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68303"
        },
        {
          "name": "CVE-2026-53269",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53269"
        },
        {
          "name": "CVE-2026-68445",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68445"
        },
        {
          "name": "CVE-2026-64479",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64479"
        },
        {
          "name": "CVE-2026-74512",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74512"
        },
        {
          "name": "CVE-2026-64329",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64329"
        },
        {
          "name": "CVE-2026-64434",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64434"
        },
        {
          "name": "CVE-2026-46115",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46115"
        },
        {
          "name": "CVE-2026-63997",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63997"
        },
        {
          "name": "CVE-2026-64219",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64219"
        },
        {
          "name": "CVE-2026-64277",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64277"
        },
        {
          "name": "CVE-2026-64126",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64126"
        },
        {
          "name": "CVE-2026-64503",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64503"
        },
        {
          "name": "CVE-2026-64562",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64562"
        },
        {
          "name": "CVE-2026-68434",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68434"
        },
        {
          "name": "CVE-2026-64168",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64168"
        },
        {
          "name": "CVE-2026-68105",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68105"
        },
        {
          "name": "CVE-2026-68444",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68444"
        },
        {
          "name": "CVE-2026-72035",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72035"
        },
        {
          "name": "CVE-2025-68214",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-68214"
        },
        {
          "name": "CVE-2026-68153",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68153"
        },
        {
          "name": "CVE-2026-64558",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64558"
        },
        {
          "name": "CVE-2026-63881",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63881"
        },
        {
          "name": "CVE-2026-64571",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64571"
        },
        {
          "name": "CVE-2026-72496",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72496"
        },
        {
          "name": "CVE-2026-63969",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63969"
        },
        {
          "name": "CVE-2026-53089",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53089"
        },
        {
          "name": "CVE-2026-68188",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68188"
        },
        {
          "name": "CVE-2026-68161",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68161"
        },
        {
          "name": "CVE-2026-64436",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64436"
        },
        {
          "name": "CVE-2026-64403",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64403"
        },
        {
          "name": "CVE-2026-64222",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64222"
        },
        {
          "name": "CVE-2026-64121",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64121"
        },
        {
          "name": "CVE-2026-68259",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68259"
        },
        {
          "name": "CVE-2026-68235",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68235"
        },
        {
          "name": "CVE-2026-68223",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68223"
        },
        {
          "name": "CVE-2026-64412",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64412"
        },
        {
          "name": "CVE-2026-74556",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74556"
        },
        {
          "name": "CVE-2026-64188",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64188"
        },
        {
          "name": "CVE-2026-64144",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64144"
        },
        {
          "name": "CVE-2026-64487",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64487"
        },
        {
          "name": "CVE-2026-64303",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64303"
        },
        {
          "name": "CVE-2026-74296",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74296"
        },
        {
          "name": "CVE-2026-64086",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64086"
        },
        {
          "name": "CVE-2026-68414",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68414"
        },
        {
          "name": "CVE-2026-64429",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64429"
        },
        {
          "name": "CVE-2026-64344",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64344"
        },
        {
          "name": "CVE-2026-64286",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64286"
        },
        {
          "name": "CVE-2026-68214",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68214"
        },
        {
          "name": "CVE-2026-64029",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64029"
        },
        {
          "name": "CVE-2026-68217",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68217"
        },
        {
          "name": "CVE-2026-68222",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68222"
        },
        {
          "name": "CVE-2026-74692",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74692"
        },
        {
          "name": "CVE-2026-68124",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68124"
        },
        {
          "name": "CVE-2026-53077",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53077"
        },
        {
          "name": "CVE-2026-64350",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64350"
        },
        {
          "name": "CVE-2026-68250",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68250"
        },
        {
          "name": "CVE-2026-72473",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72473"
        },
        {
          "name": "CVE-2026-43110",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43110"
        },
        {
          "name": "CVE-2026-68397",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68397"
        },
        {
          "name": "CVE-2026-64572",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64572"
        },
        {
          "name": "CVE-2026-64411",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64411"
        },
        {
          "name": "CVE-2026-68126",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68126"
        },
        {
          "name": "CVE-2026-74321",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74321"
        },
        {
          "name": "CVE-2026-63998",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63998"
        },
        {
          "name": "CVE-2026-64137",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64137"
        },
        {
          "name": "CVE-2026-23449",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-23449"
        },
        {
          "name": "CVE-2026-43386",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43386"
        },
        {
          "name": "CVE-2026-64537",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64537"
        },
        {
          "name": "CVE-2026-64334",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64334"
        },
        {
          "name": "CVE-2026-74495",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74495"
        },
        {
          "name": "CVE-2026-64448",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64448"
        },
        {
          "name": "CVE-2026-72497",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72497"
        },
        {
          "name": "CVE-2026-68125",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68125"
        },
        {
          "name": "CVE-2026-68135",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68135"
        },
        {
          "name": "CVE-2026-53033",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53033"
        },
        {
          "name": "CVE-2026-72032",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72032"
        },
        {
          "name": "CVE-2026-72221",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72221"
        },
        {
          "name": "CVE-2026-72289",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72289"
        },
        {
          "name": "CVE-2026-72251",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72251"
        },
        {
          "name": "CVE-2026-64134",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64134"
        },
        {
          "name": "CVE-2026-68254",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68254"
        },
        {
          "name": "CVE-2026-64005",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64005"
        },
        {
          "name": "CVE-2026-68360",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68360"
        },
        {
          "name": "CVE-2026-46107",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46107"
        },
        {
          "name": "CVE-2026-64524",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64524"
        },
        {
          "name": "CVE-2026-80654",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-80654"
        },
        {
          "name": "CVE-2025-38469",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-38469"
        },
        {
          "name": "CVE-2026-68244",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68244"
        },
        {
          "name": "CVE-2026-64382",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64382"
        },
        {
          "name": "CVE-2026-68249",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68249"
        },
        {
          "name": "CVE-2026-68107",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68107"
        },
        {
          "name": "CVE-2026-68392",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68392"
        },
        {
          "name": "CVE-2026-68300",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68300"
        },
        {
          "name": "CVE-2026-64444",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64444"
        },
        {
          "name": "CVE-2026-68260",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68260"
        },
        {
          "name": "CVE-2026-68229",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68229"
        },
        {
          "name": "CVE-2026-64225",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64225"
        },
        {
          "name": "CVE-2026-64331",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64331"
        },
        {
          "name": "CVE-2026-64511",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64511"
        },
        {
          "name": "CVE-2026-68284",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68284"
        },
        {
          "name": "CVE-2026-53264",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53264"
        },
        {
          "name": "CVE-2026-63999",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63999"
        },
        {
          "name": "CVE-2026-43109",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43109"
        },
        {
          "name": "CVE-2026-53142",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53142"
        },
        {
          "name": "CVE-2026-68152",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68152"
        },
        {
          "name": "CVE-2026-68353",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68353"
        },
        {
          "name": "CVE-2026-63944",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63944"
        },
        {
          "name": "CVE-2026-53273",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53273"
        },
        {
          "name": "CVE-2026-64547",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64547"
        },
        {
          "name": "CVE-2026-64056",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64056"
        },
        {
          "name": "CVE-2026-63860",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63860"
        },
        {
          "name": "CVE-2026-64494",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64494"
        },
        {
          "name": "CVE-2026-68108",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68108"
        },
        {
          "name": "CVE-2026-64033",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64033"
        },
        {
          "name": "CVE-2026-64565",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64565"
        },
        {
          "name": "CVE-2026-68158",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68158"
        },
        {
          "name": "CVE-2026-64543",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64543"
        },
        {
          "name": "CVE-2026-64573",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64573"
        },
        {
          "name": "CVE-2026-53246",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53246"
        },
        {
          "name": "CVE-2026-64245",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64245"
        },
        {
          "name": "CVE-2026-43278",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43278"
        },
        {
          "name": "CVE-2026-63823",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63823"
        },
        {
          "name": "CVE-2026-68325",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68325"
        },
        {
          "name": "CVE-2026-68253",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68253"
        },
        {
          "name": "CVE-2026-72501",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72501"
        },
        {
          "name": "CVE-2026-68355",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68355"
        },
        {
          "name": "CVE-2026-64530",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64530"
        },
        {
          "name": "CVE-2026-64015",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64015"
        },
        {
          "name": "CVE-2026-64294",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64294"
        },
        {
          "name": "CVE-2026-43125",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43125"
        },
        {
          "name": "CVE-2026-68470",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68470"
        },
        {
          "name": "CVE-2026-63808",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63808"
        },
        {
          "name": "CVE-2026-72343",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72343"
        },
        {
          "name": "CVE-2026-63973",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63973"
        },
        {
          "name": "CVE-2026-68180",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68180"
        },
        {
          "name": "CVE-2026-68247",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68247"
        },
        {
          "name": "CVE-2026-74722",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74722"
        },
        {
          "name": "CVE-2026-68407",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68407"
        },
        {
          "name": "CVE-2026-64247",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64247"
        },
        {
          "name": "CVE-2026-68123",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68123"
        },
        {
          "name": "CVE-2026-64420",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64420"
        },
        {
          "name": "CVE-2026-53180",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53180"
        },
        {
          "name": "CVE-2026-53238",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53238"
        },
        {
          "name": "CVE-2026-43416",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43416"
        },
        {
          "name": "CVE-2026-64548",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64548"
        },
        {
          "name": "CVE-2026-64118",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64118"
        },
        {
          "name": "CVE-2026-68162",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68162"
        },
        {
          "name": "CVE-2026-68220",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68220"
        },
        {
          "name": "CVE-2026-64384",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64384"
        },
        {
          "name": "CVE-2026-64406",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64406"
        },
        {
          "name": "CVE-2026-68354",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68354"
        },
        {
          "name": "CVE-2026-64600",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64600"
        },
        {
          "name": "CVE-2026-68149",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68149"
        },
        {
          "name": "CVE-2026-64312",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64312"
        },
        {
          "name": "CVE-2026-72469",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72469"
        },
        {
          "name": "CVE-2026-63889",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63889"
        },
        {
          "name": "CVE-2026-68375",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68375"
        },
        {
          "name": "CVE-2026-64505",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64505"
        },
        {
          "name": "CVE-2026-53366",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53366"
        },
        {
          "name": "CVE-2026-52923",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52923"
        },
        {
          "name": "CVE-2026-64087",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64087"
        },
        {
          "name": "CVE-2026-68251",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68251"
        },
        {
          "name": "CVE-2026-74584",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74584"
        },
        {
          "name": "CVE-2026-53154",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53154"
        },
        {
          "name": "CVE-2026-64358",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64358"
        },
        {
          "name": "CVE-2026-64355",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64355"
        },
        {
          "name": "CVE-2026-64515",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64515"
        },
        {
          "name": "CVE-2026-72069",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72069"
        },
        {
          "name": "CVE-2026-68359",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68359"
        },
        {
          "name": "CVE-2026-64185",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64185"
        },
        {
          "name": "CVE-2026-72020",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72020"
        },
        {
          "name": "CVE-2026-68370",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68370"
        },
        {
          "name": "CVE-2026-43116",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43116"
        },
        {
          "name": "CVE-2026-64340",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64340"
        },
        {
          "name": "CVE-2026-64007",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64007"
        },
        {
          "name": "CVE-2026-64567",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64567"
        },
        {
          "name": "CVE-2026-64450",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64450"
        },
        {
          "name": "CVE-2026-64484",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64484"
        },
        {
          "name": "CVE-2026-52990",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52990"
        },
        {
          "name": "CVE-2026-64114",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64114"
        },
        {
          "name": "CVE-2026-64266",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64266"
        },
        {
          "name": "CVE-2025-40022",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-40022"
        },
        {
          "name": "CVE-2026-43363",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43363"
        },
        {
          "name": "CVE-2026-68236",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68236"
        },
        {
          "name": "CVE-2026-64088",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64088"
        },
        {
          "name": "CVE-2026-64073",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64073"
        },
        {
          "name": "CVE-2026-64576",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64576"
        },
        {
          "name": "CVE-2026-68192",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68192"
        },
        {
          "name": "CVE-2026-74712",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74712"
        },
        {
          "name": "CVE-2026-74550",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74550"
        },
        {
          "name": "CVE-2026-74269",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74269"
        },
        {
          "name": "CVE-2026-74509",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74509"
        },
        {
          "name": "CVE-2026-64002",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64002"
        },
        {
          "name": "CVE-2026-72288",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72288"
        },
        {
          "name": "CVE-2026-68272",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68272"
        },
        {
          "name": "CVE-2026-64135",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64135"
        },
        {
          "name": "CVE-2026-64440",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64440"
        },
        {
          "name": "CVE-2026-52977",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52977"
        },
        {
          "name": "CVE-2026-64564",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64564"
        },
        {
          "name": "CVE-2026-52972",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52972"
        },
        {
          "name": "CVE-2026-74527",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74527"
        },
        {
          "name": "CVE-2026-72046",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72046"
        },
        {
          "name": "CVE-2026-68406",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68406"
        },
        {
          "name": "CVE-2026-31629",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31629"
        },
        {
          "name": "CVE-2026-64011",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64011"
        },
        {
          "name": "CVE-2026-64317",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64317"
        },
        {
          "name": "CVE-2026-68336",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68336"
        },
        {
          "name": "CVE-2026-64569",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64569"
        },
        {
          "name": "CVE-2026-46078",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46078"
        },
        {
          "name": "CVE-2026-68154",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68154"
        }
      ],
      "initial_release_date": "2026-09-18T00:00:00",
      "last_revision_date": "2026-09-18T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-1202",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-09-18T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Ex\u00e9cution de code arbitraire"
        },
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        },
        {
          "description": "D\u00e9ni de service"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans le noyau Linux de SUSE. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire, une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es et une atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans le noyau Linux de SUSE",
      "vendor_advisories": [
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23540-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623540-1"
        },
        {
          "published_at": "2026-09-17",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:4256-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20264256-1"
        },
        {
          "published_at": "2026-09-12",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23686-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623686-1"
        },
        {
          "published_at": "2026-09-12",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23681-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623681-1"
        },
        {
          "published_at": "2026-09-14",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:4172-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20264172-1"
        },
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23536-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623536-1"
        },
        {
          "published_at": "2026-09-12",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23674-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623674-1"
        },
        {
          "published_at": "2026-09-12",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23678-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623678-1"
        },
        {
          "published_at": "2026-09-12",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23685-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623685-1"
        },
        {
          "published_at": "2026-09-14",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:4170-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20264170-1"
        },
        {
          "published_at": "2026-09-13",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23687-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623687-1"
        },
        {
          "published_at": "2026-09-12",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23676-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623676-1"
        },
        {
          "published_at": "2026-09-12",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23680-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623680-1"
        },
        {
          "published_at": "2026-09-17",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:4224-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20264224-1"
        },
        {
          "published_at": "2026-09-15",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:4190-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20264190-1"
        },
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23537-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623537-1"
        },
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23528-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623528-1"
        },
        {
          "published_at": "2026-09-12",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23682-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623682-1"
        },
        {
          "published_at": "2026-09-17",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:4231-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20264231-1"
        },
        {
          "published_at": "2026-09-17",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:4244-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20264244-1"
        },
        {
          "published_at": "2026-09-15",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:4185-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20264185-1"
        },
        {
          "published_at": "2026-09-17",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:4254-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20264254-1"
        },
        {
          "published_at": "2026-09-14",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:4162-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20264162-1"
        },
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23510-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623510-1"
        },
        {
          "published_at": "2026-09-12",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23679-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623679-1"
        },
        {
          "published_at": "2026-09-12",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23684-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623684-1"
        },
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23535-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623535-1"
        },
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23531-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623531-1"
        },
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23529-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623529-1"
        },
        {
          "published_at": "2026-09-12",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23672-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623672-1"
        },
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23541-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623541-1"
        },
        {
          "published_at": "2026-09-12",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23673-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623673-1"
        },
        {
          "published_at": "2026-09-15",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:4193-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20264193-1"
        },
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23533-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623533-1"
        },
        {
          "published_at": "2026-09-12",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23683-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623683-1"
        },
        {
          "published_at": "2026-09-16",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:4215-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20264215-1"
        },
        {
          "published_at": "2026-09-14",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:4168-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20264168-1"
        },
        {
          "published_at": "2026-09-12",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23677-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623677-1"
        },
        {
          "published_at": "2026-09-17",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:4243-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20264243-1"
        },
        {
          "published_at": "2026-09-15",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:4183-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20264183-1"
        },
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23532-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623532-1"
        },
        {
          "published_at": "2026-09-15",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:4192-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20264192-1"
        },
        {
          "published_at": "2026-09-12",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23675-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623675-1"
        },
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23534-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623534-1"
        },
        {
          "published_at": "2026-09-17",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:4255-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20264255-1"
        }
      ]
    }

    CERTFR-2026-AVI-1164

    Vulnerability from certfr_avis - Published: 2026-09-11 - Updated: 2026-09-11

    De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et un déni de service à distance.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    SUSE SUSE Linux Enterprise Real Time SUSE Linux Enterprise Real Time 15 SP7
    SUSE SUSE Linux Enterprise Live Patching SUSE Linux Enterprise Live Patching 15-SP7
    SUSE SUSE Linux Enterprise Server SUSE Linux Enterprise Server for SAP Applications 15 SP7
    SUSE SUSE Linux Micro SUSE Linux Micro 6.1
    SUSE SUSE Linux Micro SUSE Linux Micro 6.0
    SUSE SUSE Linux Enterprise Server SUSE Linux Enterprise Server 15 SP7
    SUSE SUSE Real Time Module SUSE Real Time Module 15-SP7
    SUSE SUSE Linux Micro Extras SUSE Linux Micro Extras 6.0

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "SUSE Linux Enterprise Real Time 15 SP7",
          "product": {
            "name": "SUSE Linux Enterprise Real Time",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Live Patching 15-SP7",
          "product": {
            "name": "SUSE Linux Enterprise Live Patching",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Server for SAP Applications 15 SP7",
          "product": {
            "name": "SUSE Linux Enterprise Server",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Micro 6.1",
          "product": {
            "name": "SUSE Linux Micro",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Micro 6.0",
          "product": {
            "name": "SUSE Linux Micro",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Server 15 SP7",
          "product": {
            "name": "SUSE Linux Enterprise Server",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Real Time Module 15-SP7",
          "product": {
            "name": "SUSE Real Time Module",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Micro Extras 6.0",
          "product": {
            "name": "SUSE Linux Micro Extras",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-68116",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68116"
        },
        {
          "name": "CVE-2025-71075",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-71075"
        },
        {
          "name": "CVE-2026-64214",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64214"
        },
        {
          "name": "CVE-2026-53091",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53091"
        },
        {
          "name": "CVE-2026-64376",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64376"
        },
        {
          "name": "CVE-2026-74395",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74395"
        },
        {
          "name": "CVE-2026-68343",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68343"
        },
        {
          "name": "CVE-2026-64552",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64552"
        },
        {
          "name": "CVE-2026-64287",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64287"
        },
        {
          "name": "CVE-2026-53381",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53381"
        },
        {
          "name": "CVE-2026-64275",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64275"
        },
        {
          "name": "CVE-2026-64274",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64274"
        },
        {
          "name": "CVE-2026-64538",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64538"
        },
        {
          "name": "CVE-2026-74394",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74394"
        },
        {
          "name": "CVE-2026-68450",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68450"
        },
        {
          "name": "CVE-2026-68480",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68480"
        },
        {
          "name": "CVE-2026-68271",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68271"
        },
        {
          "name": "CVE-2026-74297",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74297"
        },
        {
          "name": "CVE-2026-64133",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64133"
        },
        {
          "name": "CVE-2026-31658",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31658"
        },
        {
          "name": "CVE-2026-64047",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64047"
        },
        {
          "name": "CVE-2026-74481",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74481"
        },
        {
          "name": "CVE-2026-68138",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68138"
        },
        {
          "name": "CVE-2026-64192",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64192"
        },
        {
          "name": "CVE-2026-68193",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68193"
        },
        {
          "name": "CVE-2026-68204",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68204"
        },
        {
          "name": "CVE-2026-52925",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52925"
        },
        {
          "name": "CVE-2026-74669",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74669"
        },
        {
          "name": "CVE-2026-68302",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68302"
        },
        {
          "name": "CVE-2026-64452",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64452"
        },
        {
          "name": "CVE-2026-52929",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52929"
        },
        {
          "name": "CVE-2026-68081",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68081"
        },
        {
          "name": "CVE-2026-64483",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64483"
        },
        {
          "name": "CVE-2026-63980",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63980"
        },
        {
          "name": "CVE-2026-74482",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74482"
        },
        {
          "name": "CVE-2026-64322",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64322"
        },
        {
          "name": "CVE-2026-43448",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43448"
        },
        {
          "name": "CVE-2026-64470",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64470"
        },
        {
          "name": "CVE-2026-63923",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63923"
        },
        {
          "name": "CVE-2026-68339",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68339"
        },
        {
          "name": "CVE-2026-64513",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64513"
        },
        {
          "name": "CVE-2026-68218",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68218"
        },
        {
          "name": "CVE-2026-68088",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68088"
        },
        {
          "name": "CVE-2026-64388",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64388"
        },
        {
          "name": "CVE-2026-64512",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64512"
        },
        {
          "name": "CVE-2026-64409",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64409"
        },
        {
          "name": "CVE-2026-68129",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68129"
        },
        {
          "name": "CVE-2026-74571",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74571"
        },
        {
          "name": "CVE-2026-68245",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68245"
        },
        {
          "name": "CVE-2026-64268",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64268"
        },
        {
          "name": "CVE-2026-68428",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68428"
        },
        {
          "name": "CVE-2026-64099",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64099"
        },
        {
          "name": "CVE-2026-64489",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64489"
        },
        {
          "name": "CVE-2026-74581",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74581"
        },
        {
          "name": "CVE-2026-64480",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64480"
        },
        {
          "name": "CVE-2026-72494",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72494"
        },
        {
          "name": "CVE-2026-64257",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64257"
        },
        {
          "name": "CVE-2026-64006",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64006"
        },
        {
          "name": "CVE-2026-68313",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68313"
        },
        {
          "name": "CVE-2026-64385",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64385"
        },
        {
          "name": "CVE-2026-74537",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74537"
        },
        {
          "name": "CVE-2026-63995",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63995"
        },
        {
          "name": "CVE-2026-64217",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64217"
        },
        {
          "name": "CVE-2026-46319",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46319"
        },
        {
          "name": "CVE-2026-68326",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68326"
        },
        {
          "name": "CVE-2026-68184",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68184"
        },
        {
          "name": "CVE-2026-64454",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64454"
        },
        {
          "name": "CVE-2026-64407",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64407"
        },
        {
          "name": "CVE-2026-68417",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68417"
        },
        {
          "name": "CVE-2026-64527",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64527"
        },
        {
          "name": "CVE-2026-23227",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-23227"
        },
        {
          "name": "CVE-2026-74563",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74563"
        },
        {
          "name": "CVE-2026-23454",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-23454"
        },
        {
          "name": "CVE-2026-68248",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68248"
        },
        {
          "name": "CVE-2026-63886",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63886"
        },
        {
          "name": "CVE-2026-64365",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64365"
        },
        {
          "name": "CVE-2026-53260",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53260"
        },
        {
          "name": "CVE-2026-64128",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64128"
        },
        {
          "name": "CVE-2026-68277",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68277"
        },
        {
          "name": "CVE-2026-68288",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68288"
        },
        {
          "name": "CVE-2026-68410",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68410"
        },
        {
          "name": "CVE-2026-68437",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68437"
        },
        {
          "name": "CVE-2026-68261",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68261"
        },
        {
          "name": "CVE-2026-74345",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74345"
        },
        {
          "name": "CVE-2025-40204",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-40204"
        },
        {
          "name": "CVE-2026-72083",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72083"
        },
        {
          "name": "CVE-2026-64333",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64333"
        },
        {
          "name": "CVE-2026-68304",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68304"
        },
        {
          "name": "CVE-2026-68155",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68155"
        },
        {
          "name": "CVE-2026-63928",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63928"
        },
        {
          "name": "CVE-2026-68132",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68132"
        },
        {
          "name": "CVE-2026-64574",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64574"
        },
        {
          "name": "CVE-2026-63879",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63879"
        },
        {
          "name": "CVE-2026-68102",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68102"
        },
        {
          "name": "CVE-2026-74488",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74488"
        },
        {
          "name": "CVE-2026-68086",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68086"
        },
        {
          "name": "CVE-2025-39939",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-39939"
        },
        {
          "name": "CVE-2026-53220",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53220"
        },
        {
          "name": "CVE-2026-64246",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64246"
        },
        {
          "name": "CVE-2026-68085",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68085"
        },
        {
          "name": "CVE-2026-68446",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68446"
        },
        {
          "name": "CVE-2026-68408",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68408"
        },
        {
          "name": "CVE-2026-64386",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64386"
        },
        {
          "name": "CVE-2026-43163",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43163"
        },
        {
          "name": "CVE-2026-68226",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68226"
        },
        {
          "name": "CVE-2026-53365",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53365"
        },
        {
          "name": "CVE-2026-68350",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68350"
        },
        {
          "name": "CVE-2026-23210",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-23210"
        },
        {
          "name": "CVE-2026-68419",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68419"
        },
        {
          "name": "CVE-2026-68091",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68091"
        },
        {
          "name": "CVE-2026-68297",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68297"
        },
        {
          "name": "CVE-2026-53224",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53224"
        },
        {
          "name": "CVE-2026-68199",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68199"
        },
        {
          "name": "CVE-2026-64383",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64383"
        },
        {
          "name": "CVE-2026-68425",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68425"
        },
        {
          "name": "CVE-2026-64337",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64337"
        },
        {
          "name": "CVE-2026-63888",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63888"
        },
        {
          "name": "CVE-2026-52956",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52956"
        },
        {
          "name": "CVE-2026-80534",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-80534"
        },
        {
          "name": "CVE-2026-72466",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72466"
        },
        {
          "name": "CVE-2026-64178",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64178"
        },
        {
          "name": "CVE-2026-64497",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64497"
        },
        {
          "name": "CVE-2026-53163",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53163"
        },
        {
          "name": "CVE-2026-46195",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46195"
        },
        {
          "name": "CVE-2026-64599",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64599"
        },
        {
          "name": "CVE-2026-68293",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68293"
        },
        {
          "name": "CVE-2026-68365",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68365"
        },
        {
          "name": "CVE-2026-72254",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72254"
        },
        {
          "name": "CVE-2026-64598",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64598"
        },
        {
          "name": "CVE-2026-68320",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68320"
        },
        {
          "name": "CVE-2026-63810",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63810"
        },
        {
          "name": "CVE-2026-31531",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31531"
        },
        {
          "name": "CVE-2026-64098",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64098"
        },
        {
          "name": "CVE-2026-63801",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63801"
        },
        {
          "name": "CVE-2026-63827",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63827"
        },
        {
          "name": "CVE-2026-64304",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64304"
        },
        {
          "name": "CVE-2026-43014",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43014"
        },
        {
          "name": "CVE-2026-68280",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68280"
        },
        {
          "name": "CVE-2026-68362",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68362"
        },
        {
          "name": "CVE-2025-68179",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-68179"
        },
        {
          "name": "CVE-2026-63842",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63842"
        },
        {
          "name": "CVE-2026-68430",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68430"
        },
        {
          "name": "CVE-2026-68427",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68427"
        },
        {
          "name": "CVE-2026-43319",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43319"
        },
        {
          "name": "CVE-2026-64146",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64146"
        },
        {
          "name": "CVE-2026-72500",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72500"
        },
        {
          "name": "CVE-2026-53309",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53309"
        },
        {
          "name": "CVE-2026-68324",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68324"
        },
        {
          "name": "CVE-2026-68308",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68308"
        },
        {
          "name": "CVE-2026-64276",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64276"
        },
        {
          "name": "CVE-2026-64190",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64190"
        },
        {
          "name": "CVE-2026-68210",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68210"
        },
        {
          "name": "CVE-2026-64237",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64237"
        },
        {
          "name": "CVE-2026-64323",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64323"
        },
        {
          "name": "CVE-2026-68267",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68267"
        },
        {
          "name": "CVE-2026-68309",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68309"
        },
        {
          "name": "CVE-2026-68403",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68403"
        },
        {
          "name": "CVE-2026-68139",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68139"
        },
        {
          "name": "CVE-2026-64271",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64271"
        },
        {
          "name": "CVE-2026-74566",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74566"
        },
        {
          "name": "CVE-2026-52939",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52939"
        },
        {
          "name": "CVE-2026-63925",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63925"
        },
        {
          "name": "CVE-2026-68093",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68093"
        },
        {
          "name": "CVE-2026-72262",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72262"
        },
        {
          "name": "CVE-2026-68166",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68166"
        },
        {
          "name": "CVE-2026-63990",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63990"
        },
        {
          "name": "CVE-2026-64455",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64455"
        },
        {
          "name": "CVE-2026-72467",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72467"
        },
        {
          "name": "CVE-2026-64421",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64421"
        },
        {
          "name": "CVE-2026-64584",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64584"
        },
        {
          "name": "CVE-2026-64445",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64445"
        },
        {
          "name": "CVE-2026-52935",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52935"
        },
        {
          "name": "CVE-2026-68310",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68310"
        },
        {
          "name": "CVE-2026-64433",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64433"
        },
        {
          "name": "CVE-2026-68115",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68115"
        },
        {
          "name": "CVE-2026-68133",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68133"
        },
        {
          "name": "CVE-2026-68246",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68246"
        },
        {
          "name": "CVE-2026-64563",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64563"
        },
        {
          "name": "CVE-2026-68405",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68405"
        },
        {
          "name": "CVE-2026-68219",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68219"
        },
        {
          "name": "CVE-2026-68216",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68216"
        },
        {
          "name": "CVE-2026-64500",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64500"
        },
        {
          "name": "CVE-2026-53094",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53094"
        },
        {
          "name": "CVE-2026-64097",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64097"
        },
        {
          "name": "CVE-2026-68328",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68328"
        },
        {
          "name": "CVE-2026-68394",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68394"
        },
        {
          "name": "CVE-2026-53330",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53330"
        },
        {
          "name": "CVE-2025-23137",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-23137"
        },
        {
          "name": "CVE-2026-64348",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64348"
        },
        {
          "name": "CVE-2026-68196",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68196"
        },
        {
          "name": "CVE-2026-64362",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64362"
        },
        {
          "name": "CVE-2026-72464",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72464"
        },
        {
          "name": "CVE-2026-68269",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68269"
        },
        {
          "name": "CVE-2026-68255",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68255"
        },
        {
          "name": "CVE-2026-64102",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64102"
        },
        {
          "name": "CVE-2026-68363",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68363"
        },
        {
          "name": "CVE-2026-46091",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46091"
        },
        {
          "name": "CVE-2026-68213",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68213"
        },
        {
          "name": "CVE-2026-68278",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68278"
        },
        {
          "name": "CVE-2026-64486",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64486"
        },
        {
          "name": "CVE-2026-68145",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68145"
        },
        {
          "name": "CVE-2026-64517",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64517"
        },
        {
          "name": "CVE-2026-74454",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74454"
        },
        {
          "name": "CVE-2026-64341",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64341"
        },
        {
          "name": "CVE-2026-72342",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72342"
        },
        {
          "name": "CVE-2026-64338",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64338"
        },
        {
          "name": "CVE-2026-68361",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68361"
        },
        {
          "name": "CVE-2026-64083",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64083"
        },
        {
          "name": "CVE-2026-68181",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68181"
        },
        {
          "name": "CVE-2026-46037",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46037"
        },
        {
          "name": "CVE-2026-64249",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64249"
        },
        {
          "name": "CVE-2026-72222",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72222"
        },
        {
          "name": "CVE-2026-64536",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64536"
        },
        {
          "name": "CVE-2026-43213",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43213"
        },
        {
          "name": "CVE-2026-64570",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64570"
        },
        {
          "name": "CVE-2026-63850",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63850"
        },
        {
          "name": "CVE-2026-31663",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31663"
        },
        {
          "name": "CVE-2026-68113",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68113"
        },
        {
          "name": "CVE-2026-68286",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68286"
        },
        {
          "name": "CVE-2026-64010",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64010"
        },
        {
          "name": "CVE-2026-64243",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64243"
        },
        {
          "name": "CVE-2026-52975",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52975"
        },
        {
          "name": "CVE-2026-68160",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68160"
        },
        {
          "name": "CVE-2026-46127",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46127"
        },
        {
          "name": "CVE-2026-64553",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64553"
        },
        {
          "name": "CVE-2026-68157",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68157"
        },
        {
          "name": "CVE-2026-64351",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64351"
        },
        {
          "name": "CVE-2026-64051",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64051"
        },
        {
          "name": "CVE-2026-23230",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-23230"
        },
        {
          "name": "CVE-2026-64039",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64039"
        },
        {
          "name": "CVE-2026-68368",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68368"
        },
        {
          "name": "CVE-2026-68281",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68281"
        },
        {
          "name": "CVE-2026-74474",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74474"
        },
        {
          "name": "CVE-2026-68335",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68335"
        },
        {
          "name": "CVE-2026-53353",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53353"
        },
        {
          "name": "CVE-2026-68426",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68426"
        },
        {
          "name": "CVE-2026-68329",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68329"
        },
        {
          "name": "CVE-2026-68189",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68189"
        },
        {
          "name": "CVE-2026-64375",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64375"
        },
        {
          "name": "CVE-2026-64296",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64296"
        },
        {
          "name": "CVE-2026-72307",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72307"
        },
        {
          "name": "CVE-2026-64546",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64546"
        },
        {
          "name": "CVE-2026-63926",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63926"
        },
        {
          "name": "CVE-2026-68212",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68212"
        },
        {
          "name": "CVE-2026-53110",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53110"
        },
        {
          "name": "CVE-2026-64593",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64593"
        },
        {
          "name": "CVE-2026-23240",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-23240"
        },
        {
          "name": "CVE-2026-64568",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64568"
        },
        {
          "name": "CVE-2026-63865",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63865"
        },
        {
          "name": "CVE-2026-64052",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64052"
        },
        {
          "name": "CVE-2026-68389",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68389"
        },
        {
          "name": "CVE-2026-64603",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64603"
        },
        {
          "name": "CVE-2026-53219",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53219"
        },
        {
          "name": "CVE-2026-68215",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68215"
        },
        {
          "name": "CVE-2026-64109",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64109"
        },
        {
          "name": "CVE-2026-64085",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64085"
        },
        {
          "name": "CVE-2026-64166",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64166"
        },
        {
          "name": "CVE-2026-31418",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31418"
        },
        {
          "name": "CVE-2026-64504",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64504"
        },
        {
          "name": "CVE-2026-68369",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68369"
        },
        {
          "name": "CVE-2026-63898",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63898"
        },
        {
          "name": "CVE-2026-64148",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64148"
        },
        {
          "name": "CVE-2026-72495",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72495"
        },
        {
          "name": "CVE-2026-64004",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64004"
        },
        {
          "name": "CVE-2026-31392",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31392"
        },
        {
          "name": "CVE-2026-63992",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63992"
        },
        {
          "name": "CVE-2026-64155",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64155"
        },
        {
          "name": "CVE-2026-72084",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72084"
        },
        {
          "name": "CVE-2026-68340",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68340"
        },
        {
          "name": "CVE-2026-72317",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72317"
        },
        {
          "name": "CVE-2026-68352",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68352"
        },
        {
          "name": "CVE-2026-68106",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68106"
        },
        {
          "name": "CVE-2026-46242",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46242"
        },
        {
          "name": "CVE-2026-63996",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63996"
        },
        {
          "name": "CVE-2026-68197",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68197"
        },
        {
          "name": "CVE-2026-64343",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64343"
        },
        {
          "name": "CVE-2026-64021",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64021"
        },
        {
          "name": "CVE-2026-68315",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68315"
        },
        {
          "name": "CVE-2026-68346",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68346"
        },
        {
          "name": "CVE-2026-68377",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68377"
        },
        {
          "name": "CVE-2026-68413",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68413"
        },
        {
          "name": "CVE-2026-68372",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68372"
        },
        {
          "name": "CVE-2026-64471",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64471"
        },
        {
          "name": "CVE-2026-64180",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64180"
        },
        {
          "name": "CVE-2026-68357",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68357"
        },
        {
          "name": "CVE-2026-53034",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53034"
        },
        {
          "name": "CVE-2024-57841",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-57841"
        },
        {
          "name": "CVE-2026-74318",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74318"
        },
        {
          "name": "CVE-2026-68399",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68399"
        },
        {
          "name": "CVE-2026-64539",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64539"
        },
        {
          "name": "CVE-2026-64602",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64602"
        },
        {
          "name": "CVE-2026-64583",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64583"
        },
        {
          "name": "CVE-2026-64125",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64125"
        },
        {
          "name": "CVE-2026-68418",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68418"
        },
        {
          "name": "CVE-2026-64551",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64551"
        },
        {
          "name": "CVE-2026-53111",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53111"
        },
        {
          "name": "CVE-2026-68312",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68312"
        },
        {
          "name": "CVE-2026-80529",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-80529"
        },
        {
          "name": "CVE-2026-68262",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68262"
        },
        {
          "name": "CVE-2026-68194",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68194"
        },
        {
          "name": "CVE-2026-64131",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64131"
        },
        {
          "name": "CVE-2026-64048",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64048"
        },
        {
          "name": "CVE-2026-31759",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31759"
        },
        {
          "name": "CVE-2026-68127",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68127"
        },
        {
          "name": "CVE-2026-72341",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72341"
        },
        {
          "name": "CVE-2026-68112",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68112"
        },
        {
          "name": "CVE-2026-64306",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64306"
        },
        {
          "name": "CVE-2026-64313",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64313"
        },
        {
          "name": "CVE-2026-52994",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52994"
        },
        {
          "name": "CVE-2026-64112",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64112"
        },
        {
          "name": "CVE-2026-64442",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64442"
        },
        {
          "name": "CVE-2026-64554",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64554"
        },
        {
          "name": "CVE-2026-64477",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64477"
        },
        {
          "name": "CVE-2026-64463",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64463"
        },
        {
          "name": "CVE-2026-64401",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64401"
        },
        {
          "name": "CVE-2026-68159",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68159"
        },
        {
          "name": "CVE-2026-74694",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74694"
        },
        {
          "name": "CVE-2026-64018",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64018"
        },
        {
          "name": "CVE-2026-64541",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64541"
        },
        {
          "name": "CVE-2026-64332",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64332"
        },
        {
          "name": "CVE-2026-63920",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63920"
        },
        {
          "name": "CVE-2026-68202",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68202"
        },
        {
          "name": "CVE-2026-72389",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72389"
        },
        {
          "name": "CVE-2026-72498",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72498"
        },
        {
          "name": "CVE-2026-53096",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53096"
        },
        {
          "name": "CVE-2026-72499",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72499"
        },
        {
          "name": "CVE-2026-43077",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43077"
        },
        {
          "name": "CVE-2026-64127",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64127"
        },
        {
          "name": "CVE-2026-68104",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68104"
        },
        {
          "name": "CVE-2026-64378",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64378"
        },
        {
          "name": "CVE-2026-53076",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53076"
        },
        {
          "name": "CVE-2026-64549",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64549"
        },
        {
          "name": "CVE-2026-68137",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68137"
        },
        {
          "name": "CVE-2026-68143",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68143"
        },
        {
          "name": "CVE-2026-53182",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53182"
        },
        {
          "name": "CVE-2026-64055",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64055"
        },
        {
          "name": "CVE-2026-46070",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46070"
        },
        {
          "name": "CVE-2026-53207",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53207"
        },
        {
          "name": "CVE-2026-68349",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68349"
        },
        {
          "name": "CVE-2026-64244",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64244"
        },
        {
          "name": "CVE-2025-40199",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-40199"
        },
        {
          "name": "CVE-2026-74496",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74496"
        },
        {
          "name": "CVE-2026-68257",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68257"
        },
        {
          "name": "CVE-2026-53126",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53126"
        },
        {
          "name": "CVE-2026-68252",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68252"
        },
        {
          "name": "CVE-2026-63970",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63970"
        },
        {
          "name": "CVE-2026-72502",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72502"
        },
        {
          "name": "CVE-2026-68351",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68351"
        },
        {
          "name": "CVE-2026-68289",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68289"
        },
        {
          "name": "CVE-2026-43271",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43271"
        },
        {
          "name": "CVE-2026-68402",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68402"
        },
        {
          "name": "CVE-2026-72463",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72463"
        },
        {
          "name": "CVE-2026-64224",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64224"
        },
        {
          "name": "CVE-2026-68117",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68117"
        },
        {
          "name": "CVE-2026-64559",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64559"
        },
        {
          "name": "CVE-2026-68333",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68333"
        },
        {
          "name": "CVE-2026-64544",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64544"
        },
        {
          "name": "CVE-2026-68386",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68386"
        },
        {
          "name": "CVE-2025-71104",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-71104"
        },
        {
          "name": "CVE-2026-68111",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68111"
        },
        {
          "name": "CVE-2026-64577",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64577"
        },
        {
          "name": "CVE-2026-64115",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64115"
        },
        {
          "name": "CVE-2026-52946",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52946"
        },
        {
          "name": "CVE-2026-53059",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53059"
        },
        {
          "name": "CVE-2026-72308",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72308"
        },
        {
          "name": "CVE-2026-53133",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53133"
        },
        {
          "name": "CVE-2026-74334",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74334"
        },
        {
          "name": "CVE-2026-68142",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68142"
        },
        {
          "name": "CVE-2026-64427",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64427"
        },
        {
          "name": "CVE-2026-68243",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68243"
        },
        {
          "name": "CVE-2026-64164",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64164"
        },
        {
          "name": "CVE-2026-64346",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64346"
        },
        {
          "name": "CVE-2026-68209",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68209"
        },
        {
          "name": "CVE-2026-68306",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68306"
        },
        {
          "name": "CVE-2026-53263",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53263"
        },
        {
          "name": "CVE-2026-63891",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63891"
        },
        {
          "name": "CVE-2026-68207",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68207"
        },
        {
          "name": "CVE-2026-64342",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64342"
        },
        {
          "name": "CVE-2026-68373",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68373"
        },
        {
          "name": "CVE-2026-63985",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63985"
        },
        {
          "name": "CVE-2026-64478",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64478"
        },
        {
          "name": "CVE-2026-68206",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68206"
        },
        {
          "name": "CVE-2026-68110",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68110"
        },
        {
          "name": "CVE-2026-74577",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74577"
        },
        {
          "name": "CVE-2026-64472",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64472"
        },
        {
          "name": "CVE-2026-74516",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74516"
        },
        {
          "name": "CVE-2026-64581",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64581"
        },
        {
          "name": "CVE-2026-64585",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64585"
        },
        {
          "name": "CVE-2026-72132",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72132"
        },
        {
          "name": "CVE-2026-64335",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64335"
        },
        {
          "name": "CVE-2026-68391",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68391"
        },
        {
          "name": "CVE-2026-53228",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53228"
        },
        {
          "name": "CVE-2026-64315",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64315"
        },
        {
          "name": "CVE-2026-68227",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68227"
        },
        {
          "name": "CVE-2026-68348",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68348"
        },
        {
          "name": "CVE-2026-64273",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64273"
        },
        {
          "name": "CVE-2026-63828",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63828"
        },
        {
          "name": "CVE-2026-68331",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68331"
        },
        {
          "name": "CVE-2026-74567",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74567"
        },
        {
          "name": "CVE-2026-68238",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68238"
        },
        {
          "name": "CVE-2026-53336",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53336"
        },
        {
          "name": "CVE-2026-74582",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74582"
        },
        {
          "name": "CVE-2026-68432",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68432"
        },
        {
          "name": "CVE-2026-64084",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64084"
        },
        {
          "name": "CVE-2026-64014",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64014"
        },
        {
          "name": "CVE-2026-74548",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74548"
        },
        {
          "name": "CVE-2026-64001",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64001"
        },
        {
          "name": "CVE-2026-64545",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64545"
        },
        {
          "name": "CVE-2026-74518",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74518"
        },
        {
          "name": "CVE-2026-53388",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53388"
        },
        {
          "name": "CVE-2026-63937",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63937"
        },
        {
          "name": "CVE-2026-45897",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45897"
        },
        {
          "name": "CVE-2026-64305",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64305"
        },
        {
          "name": "CVE-2026-80590",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-80590"
        },
        {
          "name": "CVE-2026-43015",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43015"
        },
        {
          "name": "CVE-2026-68398",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68398"
        },
        {
          "name": "CVE-2026-68322",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68322"
        },
        {
          "name": "CVE-2026-64381",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64381"
        },
        {
          "name": "CVE-2026-64604",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64604"
        },
        {
          "name": "CVE-2026-53337",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53337"
        },
        {
          "name": "CVE-2026-68429",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68429"
        },
        {
          "name": "CVE-2026-64597",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64597"
        },
        {
          "name": "CVE-2026-63887",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63887"
        },
        {
          "name": "CVE-2026-68136",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68136"
        },
        {
          "name": "CVE-2026-64496",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64496"
        },
        {
          "name": "CVE-2025-39964",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-39964"
        },
        {
          "name": "CVE-2026-64113",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64113"
        },
        {
          "name": "CVE-2026-64387",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64387"
        },
        {
          "name": "CVE-2026-68263",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68263"
        },
        {
          "name": "CVE-2026-68299",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68299"
        },
        {
          "name": "CVE-2026-63972",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63972"
        },
        {
          "name": "CVE-2026-68082",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68082"
        },
        {
          "name": "CVE-2026-68366",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68366"
        },
        {
          "name": "CVE-2026-46274",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46274"
        },
        {
          "name": "CVE-2026-64408",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64408"
        },
        {
          "name": "CVE-2026-68156",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68156"
        },
        {
          "name": "CVE-2026-74695",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74695"
        },
        {
          "name": "CVE-2026-64136",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64136"
        },
        {
          "name": "CVE-2026-68121",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68121"
        },
        {
          "name": "CVE-2026-68231",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68231"
        },
        {
          "name": "CVE-2026-68182",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68182"
        },
        {
          "name": "CVE-2026-74717",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74717"
        },
        {
          "name": "CVE-2026-64481",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64481"
        },
        {
          "name": "CVE-2026-64316",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64316"
        },
        {
          "name": "CVE-2026-72036",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72036"
        },
        {
          "name": "CVE-2026-68422",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68422"
        },
        {
          "name": "CVE-2026-64000",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64000"
        },
        {
          "name": "CVE-2026-68327",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68327"
        },
        {
          "name": "CVE-2026-64582",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64582"
        },
        {
          "name": "CVE-2026-53223",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53223"
        },
        {
          "name": "CVE-2026-64423",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64423"
        },
        {
          "name": "CVE-2026-64034",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64034"
        },
        {
          "name": "CVE-2026-74610",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74610"
        },
        {
          "name": "CVE-2026-64443",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64443"
        },
        {
          "name": "CVE-2026-68433",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68433"
        },
        {
          "name": "CVE-2026-68195",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68195"
        },
        {
          "name": "CVE-2026-31557",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31557"
        },
        {
          "name": "CVE-2026-63868",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63868"
        },
        {
          "name": "CVE-2026-72123",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72123"
        },
        {
          "name": "CVE-2026-64269",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64269"
        },
        {
          "name": "CVE-2026-45968",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45968"
        },
        {
          "name": "CVE-2026-64540",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64540"
        },
        {
          "name": "CVE-2026-72296",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72296"
        },
        {
          "name": "CVE-2024-44981",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-44981"
        },
        {
          "name": "CVE-2026-64482",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64482"
        },
        {
          "name": "CVE-2026-64218",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64218"
        },
        {
          "name": "CVE-2026-64495",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64495"
        },
        {
          "name": "CVE-2026-72072",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72072"
        },
        {
          "name": "CVE-2026-68279",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68279"
        },
        {
          "name": "CVE-2026-68205",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68205"
        },
        {
          "name": "CVE-2026-68234",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68234"
        },
        {
          "name": "CVE-2026-52920",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52920"
        },
        {
          "name": "CVE-2026-53001",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53001"
        },
        {
          "name": "CVE-2026-43206",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43206"
        },
        {
          "name": "CVE-2026-43273",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43273"
        },
        {
          "name": "CVE-2026-74510",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74510"
        },
        {
          "name": "CVE-2026-68256",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68256"
        },
        {
          "name": "CVE-2026-68303",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68303"
        },
        {
          "name": "CVE-2026-53269",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53269"
        },
        {
          "name": "CVE-2026-68445",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68445"
        },
        {
          "name": "CVE-2026-64479",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64479"
        },
        {
          "name": "CVE-2026-74512",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74512"
        },
        {
          "name": "CVE-2026-64329",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64329"
        },
        {
          "name": "CVE-2026-64434",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64434"
        },
        {
          "name": "CVE-2026-46115",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46115"
        },
        {
          "name": "CVE-2026-63997",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63997"
        },
        {
          "name": "CVE-2026-64219",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64219"
        },
        {
          "name": "CVE-2026-64277",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64277"
        },
        {
          "name": "CVE-2026-64126",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64126"
        },
        {
          "name": "CVE-2026-64503",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64503"
        },
        {
          "name": "CVE-2026-64562",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64562"
        },
        {
          "name": "CVE-2026-68434",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68434"
        },
        {
          "name": "CVE-2026-64168",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64168"
        },
        {
          "name": "CVE-2026-68105",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68105"
        },
        {
          "name": "CVE-2026-68444",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68444"
        },
        {
          "name": "CVE-2026-72035",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72035"
        },
        {
          "name": "CVE-2025-68214",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-68214"
        },
        {
          "name": "CVE-2026-68153",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68153"
        },
        {
          "name": "CVE-2026-64558",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64558"
        },
        {
          "name": "CVE-2026-63881",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63881"
        },
        {
          "name": "CVE-2026-64571",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64571"
        },
        {
          "name": "CVE-2026-72496",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72496"
        },
        {
          "name": "CVE-2026-63969",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63969"
        },
        {
          "name": "CVE-2026-53089",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53089"
        },
        {
          "name": "CVE-2026-68188",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68188"
        },
        {
          "name": "CVE-2026-68161",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68161"
        },
        {
          "name": "CVE-2026-64436",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64436"
        },
        {
          "name": "CVE-2026-64403",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64403"
        },
        {
          "name": "CVE-2026-64222",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64222"
        },
        {
          "name": "CVE-2026-64121",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64121"
        },
        {
          "name": "CVE-2026-68259",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68259"
        },
        {
          "name": "CVE-2026-68235",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68235"
        },
        {
          "name": "CVE-2026-68223",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68223"
        },
        {
          "name": "CVE-2026-64412",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64412"
        },
        {
          "name": "CVE-2026-74556",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74556"
        },
        {
          "name": "CVE-2026-64188",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64188"
        },
        {
          "name": "CVE-2026-64144",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64144"
        },
        {
          "name": "CVE-2026-64487",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64487"
        },
        {
          "name": "CVE-2026-64303",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64303"
        },
        {
          "name": "CVE-2026-74296",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74296"
        },
        {
          "name": "CVE-2026-64086",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64086"
        },
        {
          "name": "CVE-2026-68414",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68414"
        },
        {
          "name": "CVE-2026-64429",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64429"
        },
        {
          "name": "CVE-2026-64344",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64344"
        },
        {
          "name": "CVE-2026-64286",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64286"
        },
        {
          "name": "CVE-2026-68214",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68214"
        },
        {
          "name": "CVE-2026-64029",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64029"
        },
        {
          "name": "CVE-2026-68217",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68217"
        },
        {
          "name": "CVE-2026-68222",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68222"
        },
        {
          "name": "CVE-2026-74692",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74692"
        },
        {
          "name": "CVE-2026-68124",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68124"
        },
        {
          "name": "CVE-2026-53077",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53077"
        },
        {
          "name": "CVE-2026-64350",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64350"
        },
        {
          "name": "CVE-2026-68250",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68250"
        },
        {
          "name": "CVE-2026-72473",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72473"
        },
        {
          "name": "CVE-2026-43110",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43110"
        },
        {
          "name": "CVE-2026-68397",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68397"
        },
        {
          "name": "CVE-2026-64572",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64572"
        },
        {
          "name": "CVE-2026-64411",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64411"
        },
        {
          "name": "CVE-2026-68126",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68126"
        },
        {
          "name": "CVE-2026-74321",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74321"
        },
        {
          "name": "CVE-2026-63998",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63998"
        },
        {
          "name": "CVE-2026-64137",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64137"
        },
        {
          "name": "CVE-2026-23449",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-23449"
        },
        {
          "name": "CVE-2026-43386",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43386"
        },
        {
          "name": "CVE-2026-64537",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64537"
        },
        {
          "name": "CVE-2026-64334",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64334"
        },
        {
          "name": "CVE-2026-74495",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74495"
        },
        {
          "name": "CVE-2026-64448",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64448"
        },
        {
          "name": "CVE-2026-72497",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72497"
        },
        {
          "name": "CVE-2026-68125",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68125"
        },
        {
          "name": "CVE-2026-68135",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68135"
        },
        {
          "name": "CVE-2026-53033",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53033"
        },
        {
          "name": "CVE-2026-72032",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72032"
        },
        {
          "name": "CVE-2026-72221",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72221"
        },
        {
          "name": "CVE-2026-72289",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72289"
        },
        {
          "name": "CVE-2026-72251",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72251"
        },
        {
          "name": "CVE-2026-64134",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64134"
        },
        {
          "name": "CVE-2026-68254",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68254"
        },
        {
          "name": "CVE-2026-64005",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64005"
        },
        {
          "name": "CVE-2026-68360",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68360"
        },
        {
          "name": "CVE-2026-46107",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46107"
        },
        {
          "name": "CVE-2026-64524",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64524"
        },
        {
          "name": "CVE-2026-80654",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-80654"
        },
        {
          "name": "CVE-2025-38469",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-38469"
        },
        {
          "name": "CVE-2026-68244",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68244"
        },
        {
          "name": "CVE-2026-64382",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64382"
        },
        {
          "name": "CVE-2026-68249",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68249"
        },
        {
          "name": "CVE-2026-68107",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68107"
        },
        {
          "name": "CVE-2026-68392",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68392"
        },
        {
          "name": "CVE-2026-68300",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68300"
        },
        {
          "name": "CVE-2026-64444",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64444"
        },
        {
          "name": "CVE-2026-68260",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68260"
        },
        {
          "name": "CVE-2026-68229",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68229"
        },
        {
          "name": "CVE-2026-64225",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64225"
        },
        {
          "name": "CVE-2026-64331",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64331"
        },
        {
          "name": "CVE-2026-64511",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64511"
        },
        {
          "name": "CVE-2026-68284",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68284"
        },
        {
          "name": "CVE-2026-53264",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53264"
        },
        {
          "name": "CVE-2026-63999",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63999"
        },
        {
          "name": "CVE-2026-43109",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43109"
        },
        {
          "name": "CVE-2026-53142",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53142"
        },
        {
          "name": "CVE-2026-68152",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68152"
        },
        {
          "name": "CVE-2026-68353",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68353"
        },
        {
          "name": "CVE-2026-63944",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63944"
        },
        {
          "name": "CVE-2026-53273",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53273"
        },
        {
          "name": "CVE-2026-64547",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64547"
        },
        {
          "name": "CVE-2026-64056",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64056"
        },
        {
          "name": "CVE-2026-63860",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63860"
        },
        {
          "name": "CVE-2026-64494",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64494"
        },
        {
          "name": "CVE-2026-68108",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68108"
        },
        {
          "name": "CVE-2026-64033",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64033"
        },
        {
          "name": "CVE-2026-64565",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64565"
        },
        {
          "name": "CVE-2026-68158",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68158"
        },
        {
          "name": "CVE-2026-64543",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64543"
        },
        {
          "name": "CVE-2026-64573",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64573"
        },
        {
          "name": "CVE-2026-53246",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53246"
        },
        {
          "name": "CVE-2026-64245",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64245"
        },
        {
          "name": "CVE-2026-43278",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43278"
        },
        {
          "name": "CVE-2026-63823",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63823"
        },
        {
          "name": "CVE-2026-68325",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68325"
        },
        {
          "name": "CVE-2026-68253",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68253"
        },
        {
          "name": "CVE-2026-72501",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72501"
        },
        {
          "name": "CVE-2026-68355",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68355"
        },
        {
          "name": "CVE-2026-64530",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64530"
        },
        {
          "name": "CVE-2026-64015",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64015"
        },
        {
          "name": "CVE-2026-64294",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64294"
        },
        {
          "name": "CVE-2026-43125",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43125"
        },
        {
          "name": "CVE-2026-68470",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68470"
        },
        {
          "name": "CVE-2026-63808",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63808"
        },
        {
          "name": "CVE-2026-72343",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72343"
        },
        {
          "name": "CVE-2026-63973",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63973"
        },
        {
          "name": "CVE-2026-68180",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68180"
        },
        {
          "name": "CVE-2026-68247",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68247"
        },
        {
          "name": "CVE-2026-74722",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74722"
        },
        {
          "name": "CVE-2026-68407",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68407"
        },
        {
          "name": "CVE-2026-64247",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64247"
        },
        {
          "name": "CVE-2026-68123",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68123"
        },
        {
          "name": "CVE-2026-64420",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64420"
        },
        {
          "name": "CVE-2026-53180",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53180"
        },
        {
          "name": "CVE-2026-53238",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53238"
        },
        {
          "name": "CVE-2026-43416",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43416"
        },
        {
          "name": "CVE-2026-64548",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64548"
        },
        {
          "name": "CVE-2026-64118",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64118"
        },
        {
          "name": "CVE-2026-68162",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68162"
        },
        {
          "name": "CVE-2026-68220",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68220"
        },
        {
          "name": "CVE-2026-64384",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64384"
        },
        {
          "name": "CVE-2026-64406",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64406"
        },
        {
          "name": "CVE-2026-68354",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68354"
        },
        {
          "name": "CVE-2026-64600",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64600"
        },
        {
          "name": "CVE-2026-68149",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68149"
        },
        {
          "name": "CVE-2026-64312",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64312"
        },
        {
          "name": "CVE-2026-72469",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72469"
        },
        {
          "name": "CVE-2026-63889",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63889"
        },
        {
          "name": "CVE-2026-68375",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68375"
        },
        {
          "name": "CVE-2026-64505",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64505"
        },
        {
          "name": "CVE-2026-53366",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53366"
        },
        {
          "name": "CVE-2026-52923",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52923"
        },
        {
          "name": "CVE-2026-64087",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64087"
        },
        {
          "name": "CVE-2026-68251",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68251"
        },
        {
          "name": "CVE-2026-74584",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74584"
        },
        {
          "name": "CVE-2026-53154",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53154"
        },
        {
          "name": "CVE-2026-64358",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64358"
        },
        {
          "name": "CVE-2026-64355",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64355"
        },
        {
          "name": "CVE-2026-64515",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64515"
        },
        {
          "name": "CVE-2026-72069",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72069"
        },
        {
          "name": "CVE-2026-68359",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68359"
        },
        {
          "name": "CVE-2026-64185",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64185"
        },
        {
          "name": "CVE-2026-72020",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72020"
        },
        {
          "name": "CVE-2026-68370",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68370"
        },
        {
          "name": "CVE-2026-43116",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43116"
        },
        {
          "name": "CVE-2026-64340",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64340"
        },
        {
          "name": "CVE-2026-64007",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64007"
        },
        {
          "name": "CVE-2026-64567",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64567"
        },
        {
          "name": "CVE-2026-64450",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64450"
        },
        {
          "name": "CVE-2026-64484",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64484"
        },
        {
          "name": "CVE-2026-52990",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52990"
        },
        {
          "name": "CVE-2026-64114",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64114"
        },
        {
          "name": "CVE-2026-64266",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64266"
        },
        {
          "name": "CVE-2025-40022",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-40022"
        },
        {
          "name": "CVE-2026-43363",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43363"
        },
        {
          "name": "CVE-2026-68236",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68236"
        },
        {
          "name": "CVE-2026-64088",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64088"
        },
        {
          "name": "CVE-2026-64073",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64073"
        },
        {
          "name": "CVE-2026-64576",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64576"
        },
        {
          "name": "CVE-2026-68192",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68192"
        },
        {
          "name": "CVE-2026-74712",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74712"
        },
        {
          "name": "CVE-2026-74550",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74550"
        },
        {
          "name": "CVE-2026-74269",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74269"
        },
        {
          "name": "CVE-2026-74509",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74509"
        },
        {
          "name": "CVE-2026-64002",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64002"
        },
        {
          "name": "CVE-2026-72288",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72288"
        },
        {
          "name": "CVE-2026-68272",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68272"
        },
        {
          "name": "CVE-2026-64135",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64135"
        },
        {
          "name": "CVE-2026-64440",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64440"
        },
        {
          "name": "CVE-2026-52977",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52977"
        },
        {
          "name": "CVE-2026-52972",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52972"
        },
        {
          "name": "CVE-2026-74527",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74527"
        },
        {
          "name": "CVE-2026-72046",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72046"
        },
        {
          "name": "CVE-2026-68406",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68406"
        },
        {
          "name": "CVE-2026-31629",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31629"
        },
        {
          "name": "CVE-2026-64011",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64011"
        },
        {
          "name": "CVE-2026-64317",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64317"
        },
        {
          "name": "CVE-2026-68336",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68336"
        },
        {
          "name": "CVE-2026-64569",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64569"
        },
        {
          "name": "CVE-2026-46078",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46078"
        },
        {
          "name": "CVE-2026-68154",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68154"
        }
      ],
      "initial_release_date": "2026-09-11T00:00:00",
      "last_revision_date": "2026-09-11T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-1164",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-09-11T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Ex\u00e9cution de code arbitraire"
        },
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        },
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans le noyau Linux de SUSE. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire, une \u00e9l\u00e9vation de privil\u00e8ges et un d\u00e9ni de service \u00e0 distance.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans le noyau Linux de SUSE",
      "vendor_advisories": [
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23490-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623490-1"
        },
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23485-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623485-1"
        },
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23479-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623479-1"
        },
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23486-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623486-1"
        },
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23477-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623477-1"
        },
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23484-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623484-1"
        },
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23487-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623487-1"
        },
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23488-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623488-1"
        },
        {
          "published_at": "2026-09-10",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:4120-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20264120-1"
        },
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23439-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623439-1"
        },
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23440-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623440-1"
        },
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23482-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623482-1"
        },
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23481-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623481-1"
        },
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23483-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623483-1"
        },
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23489-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623489-1"
        },
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23491-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623491-1"
        },
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23480-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623480-1"
        }
      ]
    }

    CERTFR-2026-AVI-1120

    Vulnerability from certfr_avis - Published: 2026-09-04 - Updated: 2026-09-04

    De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Elles permettent à un attaquant de provoquer une atteinte à l'intégrité des données, un contournement de la politique de sécurité et un problème de sécurité non spécifié par l'éditeur.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    SUSE SUSE Linux Enterprise Server SUSE Linux Enterprise Server 16.0
    SUSE SUSE Linux Enterprise Server SUSE Linux Enterprise Server for SAP applications 16.0
    SUSE SUSE Linux Micro SUSE Linux Micro 6.2
    SUSE SUSE Linux Micro SUSE Linux Micro 6.0
    References
    Bulletin de sécurité SUSE SUSE-SU-2026:23279-1 2026-08-26 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23367-1 2026-08-31 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23387-1 2026-08-31 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23281-1 2026-08-26 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23293-1 2026-08-26 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23372-1 2026-08-31 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23373-1 2026-08-31 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23280-1 2026-08-26 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23378-1 2026-08-31 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23382-1 2026-08-31 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23292-1 2026-08-26 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23295-1 2026-08-26 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23286-1 2026-08-26 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23370-1 2026-08-31 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23287-1 2026-08-26 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23374-1 2026-08-31 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23342-1 2026-08-26 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23383-1 2026-08-31 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23336-1 2026-08-26 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23375-1 2026-08-31 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23377-1 2026-08-31 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23389-1 2026-08-31 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23369-1 2026-08-31 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23290-1 2026-08-26 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23341-1 2026-08-26 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23284-1 2026-08-26 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23337-1 2026-08-26 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23379-1 2026-08-31 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23386-1 2026-08-31 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23291-1 2026-08-26 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23366-1 2026-08-31 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23390-1 2026-08-31 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23371-1 2026-08-31 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23288-1 2026-08-26 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23343-1 2026-08-26 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23388-1 2026-08-31 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23296-1 2026-08-26 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23380-1 2026-08-31 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23384-1 2026-08-31 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23339-1 2026-08-26 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23368-1 2026-08-31 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23381-1 2026-08-31 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23385-1 2026-08-31 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23340-1 2026-08-26 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23338-1 2026-08-26 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23285-1 2026-08-26 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23282-1 2026-08-26 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23283-1 2026-08-26 vendor-advisory
    Bulletin de sécurité SUSE SUSE-SU-2026:23376-1 2026-08-31 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "SUSE Linux Enterprise Server 16.0",
          "product": {
            "name": "SUSE Linux Enterprise Server",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Enterprise Server for SAP applications 16.0",
          "product": {
            "name": "SUSE Linux Enterprise Server",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Micro 6.2",
          "product": {
            "name": "SUSE Linux Micro",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        },
        {
          "description": "SUSE Linux Micro 6.0",
          "product": {
            "name": "SUSE Linux Micro",
            "vendor": {
              "name": "SUSE",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-46319",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46319"
        },
        {
          "name": "CVE-2025-40204",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-40204"
        },
        {
          "name": "CVE-2026-53224",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53224"
        },
        {
          "name": "CVE-2026-52956",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52956"
        },
        {
          "name": "CVE-2026-53205",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53205"
        },
        {
          "name": "CVE-2026-46037",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46037"
        },
        {
          "name": "CVE-2026-53233",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53233"
        },
        {
          "name": "CVE-2026-23240",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-23240"
        },
        {
          "name": "CVE-2026-46242",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46242"
        },
        {
          "name": "CVE-2026-31759",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31759"
        },
        {
          "name": "CVE-2026-43077",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43077"
        },
        {
          "name": "CVE-2026-53182",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53182"
        },
        {
          "name": "CVE-2026-53133",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53133"
        },
        {
          "name": "CVE-2026-46274",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46274"
        },
        {
          "name": "CVE-2026-43206",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43206"
        },
        {
          "name": "CVE-2026-43110",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43110"
        },
        {
          "name": "CVE-2026-23449",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-23449"
        },
        {
          "name": "CVE-2026-43109",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43109"
        },
        {
          "name": "CVE-2026-53246",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53246"
        },
        {
          "name": "CVE-2026-64530",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64530"
        },
        {
          "name": "CVE-2026-23161",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-23161"
        },
        {
          "name": "CVE-2026-64600",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64600"
        },
        {
          "name": "CVE-2026-53366",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53366"
        },
        {
          "name": "CVE-2026-52923",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52923"
        },
        {
          "name": "CVE-2026-52972",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52972"
        },
        {
          "name": "CVE-2026-31629",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31629"
        }
      ],
      "initial_release_date": "2026-09-04T00:00:00",
      "last_revision_date": "2026-09-04T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-1120",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-09-04T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans le noyau Linux de SUSE. Elles permettent \u00e0 un attaquant de provoquer une atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es, un contournement de la politique de s\u00e9curit\u00e9 et un probl\u00e8me de s\u00e9curit\u00e9 non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans le noyau Linux de SUSE",
      "vendor_advisories": [
        {
          "published_at": "2026-08-26",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23279-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623279-1"
        },
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23367-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623367-1"
        },
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23387-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623387-1"
        },
        {
          "published_at": "2026-08-26",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23281-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623281-1"
        },
        {
          "published_at": "2026-08-26",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23293-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623293-1"
        },
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23372-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623372-1"
        },
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23373-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623373-1"
        },
        {
          "published_at": "2026-08-26",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23280-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623280-1"
        },
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23378-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623378-1"
        },
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23382-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623382-1"
        },
        {
          "published_at": "2026-08-26",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23292-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623292-1"
        },
        {
          "published_at": "2026-08-26",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23295-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623295-1"
        },
        {
          "published_at": "2026-08-26",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23286-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623286-1"
        },
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23370-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623370-1"
        },
        {
          "published_at": "2026-08-26",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23287-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623287-1"
        },
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23374-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623374-1"
        },
        {
          "published_at": "2026-08-26",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23342-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623342-1"
        },
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23383-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623383-1"
        },
        {
          "published_at": "2026-08-26",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23336-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623336-1"
        },
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23375-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623375-1"
        },
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23377-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623377-1"
        },
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23389-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623389-1"
        },
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23369-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623369-1"
        },
        {
          "published_at": "2026-08-26",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23290-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623290-1"
        },
        {
          "published_at": "2026-08-26",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23341-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623341-1"
        },
        {
          "published_at": "2026-08-26",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23284-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623284-1"
        },
        {
          "published_at": "2026-08-26",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23337-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623337-1"
        },
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23379-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623379-1"
        },
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23386-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623386-1"
        },
        {
          "published_at": "2026-08-26",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23291-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623291-1"
        },
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23366-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623366-1"
        },
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23390-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623390-1"
        },
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23371-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623371-1"
        },
        {
          "published_at": "2026-08-26",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23288-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623288-1"
        },
        {
          "published_at": "2026-08-26",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23343-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623343-1"
        },
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23388-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623388-1"
        },
        {
          "published_at": "2026-08-26",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23296-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623296-1"
        },
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23380-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623380-1"
        },
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23384-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623384-1"
        },
        {
          "published_at": "2026-08-26",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23339-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623339-1"
        },
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23368-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623368-1"
        },
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23381-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623381-1"
        },
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23385-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623385-1"
        },
        {
          "published_at": "2026-08-26",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23340-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623340-1"
        },
        {
          "published_at": "2026-08-26",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23338-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623338-1"
        },
        {
          "published_at": "2026-08-26",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23285-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623285-1"
        },
        {
          "published_at": "2026-08-26",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23282-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623282-1"
        },
        {
          "published_at": "2026-08-26",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23283-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623283-1"
        },
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23376-1",
          "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623376-1"
        }
      ]
    }

    CVE-2026-75036 (GCVE-0-2026-75036)

    Vulnerability from nvd – Published: 2026-09-03 15:15 – Updated: 2026-09-05 01:32
    VLAI
    Title
    Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessing
    Summary
    A security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet controller could reach network resources outside the management cluster. A user who can supply bundle content to a repository referenced by a `GitRepo` resource can cause the Fleet controller to: - Disclose cluster metadata available to the templating context. - Reveal information about hosts reachable from the controller's network position. Because the disclosure channel is name resolution, it may remain effective in environments where outbound traffic is otherwise restricted. The disclosed information is limited to values exposed to the Fleet templating context and to name resolution results. Integrity and availability of managed clusters are not affected. This issue affects Fleet: from 0.12.0 before 0.12.19, from 0.13.0 before 0.13.15, from 0.14.0 before 0.14.10, from 0.15.0 before 0.15.6, and from 0.16.0 before 0.16.1.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-05 01:32 UTC
    CWE
    • CWE-918 - Server-Side request forgery (SSRF)
    • CWE-1336 - Improper neutralization of special elements used in a template engine
    References
    Impacted products
    Vendor Product Version
    SUSE Fleet Affected: 0.12.0 , < 0.12.19 (semver)
    Affected: 0.13.0 , < 0.13.15 (semver)
    Affected: 0.14.0 , < 0.14.10 (semver)
    Affected: 0.15.0 , < 0.15.6 (semver)
    Affected: 0.16.0 , < 0.16.1 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-75036",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-05T01:32:24.237639Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-05T01:32:33.141Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Fleet",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "0.12.19",
                  "status": "affected",
                  "version": "0.12.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.13.15",
                  "status": "affected",
                  "version": "0.13.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.14.10",
                  "status": "affected",
                  "version": "0.14.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.15.6",
                  "status": "affected",
                  "version": "0.15.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.16.1",
                  "status": "affected",
                  "version": "0.16.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A security vulnerability was discovered in Fleet\u0027s Helm template preprocessing where templates evaluated by the Fleet controller could reach network resources outside the management cluster. A user who can supply bundle content to a repository referenced by a `GitRepo` resource can cause the Fleet controller to:\u003cbr\u003e- Disclose cluster metadata available to the templating context.\u003cbr\u003e- Reveal information about hosts reachable from the controller\u0027s network position.\u003cbr\u003eBecause the disclosure channel is name resolution, it may remain effective in environments where outbound traffic is otherwise restricted. The disclosed information is limited to values exposed to the Fleet templating context and to name resolution results. Integrity and availability of managed clusters are not affected.\u003cbr\u003e\u003cbr\u003eThis issue affects Fleet:\u003cbr\u003efrom 0.12.0 before 0.12.19, \u003cbr\u003efrom 0.13.0 before 0.13.15, \u003cbr\u003efrom 0.14.0 before 0.14.10, \u003cbr\u003efrom 0.15.0 before 0.15.6, and\u003cbr\u003efrom 0.16.0 before 0.16.1."
                }
              ],
              "value": "A security vulnerability was discovered in Fleet\u0027s Helm template preprocessing where templates evaluated by the Fleet controller could reach network resources outside the management cluster. A user who can supply bundle content to a repository referenced by a `GitRepo` resource can cause the Fleet controller to:\n- Disclose cluster metadata available to the templating context.\n- Reveal information about hosts reachable from the controller\u0027s network position.\nBecause the disclosure channel is name resolution, it may remain effective in environments where outbound traffic is otherwise restricted. The disclosed information is limited to values exposed to the Fleet templating context and to name resolution results. Integrity and availability of managed clusters are not affected.\n\nThis issue affects Fleet:\nfrom 0.12.0 before 0.12.19, \nfrom 0.13.0 before 0.13.15, \nfrom 0.14.0 before 0.14.10, \nfrom 0.15.0 before 0.15.6, and\nfrom 0.16.0 before 0.16.1."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-664",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-664 Server Side Request Forgery"
                }
              ]
            },
            {
              "capecId": "CAPEC-116",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-116 Excavation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "CWE-918 Server-Side request forgery (SSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-1336",
                  "description": "CWE-1336 Improper neutralization of special elements used in a template engine",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-03T15:15:25.490Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/rancher/fleet/security/advisories/GHSA-x9m6-xcjr-hpjp"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessing",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-75036",
        "datePublished": "2026-09-03T15:15:25.490Z",
        "dateReserved": "2026-08-17T15:22:54.444Z",
        "dateUpdated": "2026-09-05T01:32:33.141Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-75035 (GCVE-0-2026-75035)

    Vulnerability from nvd – Published: 2026-09-03 15:07 – Updated: 2026-09-05 01:25
    VLAI
    Title
    Rancher: ext.cattle.io/v1 Token store: cross-user token disclosure via label-selector scoping bypass
    Summary
    A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its internal owner filter instead of returning an empty result. Any authenticated user could therefore list and watch every other user's tokens, disclosing token metadata and the stored salted hash of the bearer token. This issue affects Rancher: before 2.15.1.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-05 01:25 UTC
    CWE
    • CWE-639 - Authorization bypass through User-Controlled key
    Impacted products
    Vendor Product Version
    SUSE Rancher Affected: 0 , < 2.15.1 (semver)
    Create a notification for this product.
    Date Public
    2026-08-31 15:01
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-75035",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-05T01:25:28.809972Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-05T01:25:40.696Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Rancher",
              "repo": "https://github.com/rancher/rancher",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.15.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "datePublic": "2026-08-31T15:01:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eA flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its internal owner filter instead of returning an empty result. Any authenticated user could therefore list and watch every other user\u0027s tokens, disclosing token metadata and the stored salted hash of the bearer token.\u003c/p\u003e\u003cp\u003eThis issue affects Rancher: before 2.15.1.\u003c/p\u003e"
                }
              ],
              "value": "A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its internal owner filter instead of returning an empty result. Any authenticated user could therefore list and watch every other user\u0027s tokens, disclosing token metadata and the stored salted hash of the bearer token.\n\n\n\nThis issue affects Rancher: before 2.15.1."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-77",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-77 Manipulating User-Controlled Variables"
                }
              ]
            },
            {
              "capecId": "CAPEC-1",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs"
                }
              ]
            },
            {
              "capecId": "CAPEC-116",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-116 Excavation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.7,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "CWE-639 Authorization bypass through User-Controlled key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-03T15:07:11.685Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "url": "https://github.com/rancher/rancher/releases/tag/v2.15.1"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Rancher: ext.cattle.io/v1 Token store: cross-user token disclosure via label-selector scoping bypass",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-75035",
        "datePublished": "2026-09-03T15:07:11.685Z",
        "dateReserved": "2026-08-17T15:22:54.444Z",
        "dateUpdated": "2026-09-05T01:25:40.696Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-75034 (GCVE-0-2026-75034)

    Vulnerability from nvd – Published: 2026-09-03 15:01 – Updated: 2026-09-04 03:56
    VLAI
    Title
    Rancher: SAML Assertion Replay
    Summary
    A flaw was found in Rancher Manager. The SAML assertion replay protection introduced by the fix for CVE-2026-44946 recorded consumed assertion IDs in a per-process cache, so each replica only detected replays that reached the same pod. In a high-availability deployment, an attacker holding a captured assertion could replay it once against every other replica to obtain additional authenticated sessions as the victim. This issue affects Rancher: before 2.15.1.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-03 00:00 UTC
    CWE
    • CWE-294 - Authentication bypass by capture-replay
    Impacted products
    Vendor Product Version
    SUSE Rancher Affected: 0 , < 2.15.1 (semver)
    Create a notification for this product.
    Date Public
    2026-08-31 14:58
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-75034",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-03T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-04T03:56:03.896Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Rancher",
              "repo": "https://github.com/rancher/rancher",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.15.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Wade Sparks"
            }
          ],
          "datePublic": "2026-08-31T14:58:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A flaw was found in Rancher Manager. The SAML assertion replay protection introduced by the fix for CVE-2026-44946 recorded consumed assertion IDs in a per-process cache, so each replica only detected replays that reached the same pod. In a high-availability deployment, an attacker holding a captured assertion could replay it once against every other replica to obtain additional authenticated sessions as the victim.\u003cbr\u003e\u003cp\u003eThis issue affects Rancher: before 2.15.1.\u003c/p\u003e"
                }
              ],
              "value": "A flaw was found in Rancher Manager. The SAML assertion replay protection introduced by the fix for CVE-2026-44946 recorded consumed assertion IDs in a per-process cache, so each replica only detected replays that reached the same pod. In a high-availability deployment, an attacker holding a captured assertion could replay it once against every other replica to obtain additional authenticated sessions as the victim.\n\n\nThis issue affects Rancher: before 2.15.1."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-60",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-60 Reusing Session IDs (aka Session Replay)"
                }
              ]
            },
            {
              "capecId": "CAPEC-94",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-94 Adversary in the Middle (AiTM)"
                }
              ]
            },
            {
              "capecId": "CAPEC-593",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-593 Session Hijacking"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.4,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-294",
                  "description": "CWE-294 Authentication bypass by capture-replay",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-03T15:01:16.635Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "url": "https://github.com/rancher/rancher/releases/tag/v2.15.1"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Rancher: SAML Assertion Replay",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-75034",
        "datePublished": "2026-09-03T15:01:16.635Z",
        "dateReserved": "2026-08-17T15:22:54.444Z",
        "dateUpdated": "2026-09-04T03:56:03.896Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-75033 (GCVE-0-2026-75033)

    Vulnerability from nvd – Published: 2026-09-03 14:57 – Updated: 2026-09-03 15:13
    VLAI
    Title
    Rancher: Cross-Cluster Secret Leakage via Namespace projectId Annotation Spoofing
    Summary
    A flaw was found in Rancher Manager. Project Secrets were propagated into a namespace based only on its `field.cattle.io/projectId` annotation, without verifying that the referenced project belonged to the same downstream cluster. A user able to create namespaces on one cluster could set the annotation to a project ID from another cluster and have that project's secrets copied into a namespace under their control. This issue affects Rancher: before 2.15.1.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-03 15:13 UTC
    CWE
    • CWE-639 - Authorization bypass through User-Controlled key
    Impacted products
    Vendor Product Version
    SUSE Rancher Affected: 0 , < 2.15.1 (semver)
    Create a notification for this product.
    Date Public
    2026-08-31 14:52
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-75033",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-03T15:13:38.725376Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-03T15:13:54.624Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Rancher",
              "repo": "https://github.com/rancher/rancher",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.15.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Alex Seymour"
            }
          ],
          "datePublic": "2026-08-31T14:52:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A flaw was found in Rancher Manager. Project Secrets were propagated into a namespace based only on its `field.cattle.io/projectId` annotation, without verifying that the referenced project belonged to the same downstream cluster. A user able to create namespaces on one cluster could set the annotation to a project ID from another cluster and have that project\u0027s secrets copied into a namespace under their control.\u003cbr\u003e\u003cp\u003eThis issue affects Rancher: before 2.15.1.\u003c/p\u003e"
                }
              ],
              "value": "A flaw was found in Rancher Manager. Project Secrets were propagated into a namespace based only on its `field.cattle.io/projectId` annotation, without verifying that the referenced project belonged to the same downstream cluster. A user able to create namespaces on one cluster could set the annotation to a project ID from another cluster and have that project\u0027s secrets copied into a namespace under their control.\n\n\nThis issue affects Rancher: before 2.15.1."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-21",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-21 Exploitation of Trusted Identifiers"
                }
              ]
            },
            {
              "capecId": "CAPEC-116",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-116 Excavation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.7,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "CWE-639 Authorization bypass through User-Controlled key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-03T14:57:34.334Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "url": "https://github.com/rancher/rancher/releases/tag/v2.15.1"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Rancher: Cross-Cluster Secret Leakage via Namespace projectId Annotation Spoofing",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-75033",
        "datePublished": "2026-09-03T14:57:34.334Z",
        "dateReserved": "2026-08-17T15:22:54.443Z",
        "dateUpdated": "2026-09-03T15:13:54.624Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-71404 (GCVE-0-2026-71404)

    Vulnerability from nvd – Published: 2026-09-03 14:51 – Updated: 2026-09-03 15:07
    VLAI
    Title
    Rancher: Ownership-less ClusterRole overwrite via attacker-controlled cr-name annotation on GlobalRole
    Summary
    A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable `authz.management.cattle.io/cr-name` annotation and overwrote that object's rules without verifying ownership. A user with delegated GlobalRole create or update permission could point the annotation at any existing ClusterRole, such as `cluster-admin`, and revoke the permissions of every principal bound to it. The change persists after the malicious GlobalRole is deleted. This issue affects Rancher: before 2.15.1.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-03 15:06 UTC
    CWE
    • CWE-639 - Authorization bypass through User-Controlled key
    Impacted products
    Vendor Product Version
    SUSE Rancher Affected: 0 , < 2.15.1 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-71404",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-03T15:06:03.098792Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-03T15:07:12.467Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Rancher",
              "repo": "https://github.com/rancher/rancher",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.15.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "https://github.com/Pig-Tail"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable `authz.management.cattle.io/cr-name` annotation and overwrote that object\u0027s rules without verifying ownership. A user with delegated GlobalRole create or update permission could point the annotation at any existing ClusterRole, such as `cluster-admin`, and revoke the permissions of every principal bound to it. The change persists after the malicious GlobalRole is deleted.\u003cbr\u003e\u003cp\u003eThis issue affects Rancher: before 2.15.1.\u003c/p\u003e"
                }
              ],
              "value": "A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable `authz.management.cattle.io/cr-name` annotation and overwrote that object\u0027s rules without verifying ownership. A user with delegated GlobalRole create or update permission could point the annotation at any existing ClusterRole, such as `cluster-admin`, and revoke the permissions of every principal bound to it. The change persists after the malicious GlobalRole is deleted.\n\n\nThis issue affects Rancher: before 2.15.1."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-176",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-176 Configuration/Environment Manipulation"
                }
              ]
            },
            {
              "capecId": "CAPEC-77",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-77 Manipulating User-Controlled Variables"
                }
              ]
            },
            {
              "capecId": "CAPEC-240",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-240 Resource Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "CWE-639 Authorization bypass through User-Controlled key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-03T14:51:44.678Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/rancher/rancher/pull/56642"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/rancher/rancher/pull/56593"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Rancher: Ownership-less ClusterRole overwrite via attacker-controlled cr-name annotation on GlobalRole",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-71404",
        "datePublished": "2026-09-03T14:51:44.678Z",
        "dateReserved": "2026-08-06T11:38:54.896Z",
        "dateUpdated": "2026-09-03T15:07:12.467Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-71403 (GCVE-0-2026-71403)

    Vulnerability from nvd – Published: 2026-09-03 14:45 – Updated: 2026-09-04 03:55
    VLAI
    Title
    Rancher: Identity-field mutation in /v3/users allows account hijack via principal rebind
    Summary
    A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a User resource's `username` and `principalIds` fields. A user holding the `update` verb on `users.management.cattle.io` could inject a foreign identity provider principal into any account, so that the next login by the owner of that principal was bound to the victim's account and inherited its role bindings. This issue affects Rancher: before 2.15.1.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-03 00:00 UTC
    CWE
    • CWE-639 - Authorization bypass through User-Controlled key
    References
    Impacted products
    Vendor Product Version
    SUSE Rancher Affected: 0 , < 2.15.1 (semver)
    Create a notification for this product.
    Date Public
    2026-08-31 14:37
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-71403",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-03T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-04T03:55:59.443Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Manager"
              ],
              "product": "Rancher",
              "repo": "https://github.com/rancher/rancher",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.15.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Andrej Tom\u010di"
            }
          ],
          "datePublic": "2026-08-31T14:37:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a User resource\u0027s `username` and `principalIds` fields. A user holding the `update` verb on `users.management.cattle.io` could inject a foreign identity provider principal into any account, so that the next login by the owner of that principal was bound to the victim\u0027s account and inherited its role bindings.\u003cbr\u003e\u003cp\u003eThis issue affects Rancher: before 2.15.1.\u003c/p\u003e"
                }
              ],
              "value": "A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a User resource\u0027s `username` and `principalIds` fields. A user holding the `update` verb on `users.management.cattle.io` could inject a foreign identity provider principal into any account, so that the next login by the owner of that principal was bound to the victim\u0027s account and inherited its role bindings.\n\n\nThis issue affects Rancher: before 2.15.1."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-21",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-21 Exploitation of Trusted Identifiers"
                }
              ]
            },
            {
              "capecId": "CAPEC-151",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-151 Identity Spoofing"
                }
              ]
            },
            {
              "capecId": "CAPEC-593",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-593 Session Hijacking"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.1,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "CWE-639 Authorization bypass through User-Controlled key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-03T14:45:37.468Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/rancher/rancher/pull/56616"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Rancher: Identity-field mutation in /v3/users allows account hijack via principal rebind",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-71403",
        "datePublished": "2026-09-03T14:45:37.468Z",
        "dateReserved": "2026-08-06T11:38:54.896Z",
        "dateUpdated": "2026-09-04T03:55:59.443Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }