Canadian Cyber Centre advisories flag SUSE NeuVector RCE and multiple Rancher flaws; updates urged
Canada's Cyber Centre issued two SUSE advisories: AV26-968 on a NeuVector sniffer command-injection flaw enabling remote code execution on Kubernetes nodes, and AV26-974 detailing Rancher flaws including stored XSS, session non-revocation, and cross-tenant…
The Canadian Centre for Cyber Security issued advisory AV26-968 on September 28, 2026, covering SUSE NeuVector versions prior to 5.4.11, 5.5.4, and 5.6.2. The flaw is an OS command injection in the packet-capture (sniffer) filter that can lead to remote code execution on Kubernetes nodes; users and administrators are encouraged to review the linked SUSE update advisories and apply patches. On September 29, 2026, the Centre issued advisory AV26-974 for SUSE Rancher vulnerabilities affecting numerous versions across release lines up to 2.15.2. The Rancher flaws comprise: an unauthenticated update of public UI settings leading to stored cross-site scripting; sessions not being revoked server-side on logout; the Fleet agent copying downstream resources with cluster-admin privileges, allowing cross-namespace writes; and cross-tenant BundleDeployment and Secret disclosure via spoofed cluster labels during agent-initiated registration. For both advisories, users and administrators are urged to apply updates as they become available. Neither report provides CVE identifiers. The two sources do not conflict: they cover different SUSE products and advisory numbers.
- Advisory AV26-968, issued 2026-09-28, covers SUSE NeuVector versions prior to 5.4.11, 5.5.4, and 5.6.2
- NeuVector flaw is an OS command injection in the packet-capture (sniffer) filter that can lead to remote code execution on Kubernetes nodes
- Advisory AV26-974, issued 2026-09-29, covers SUSE Rancher vulnerabilities affecting numerous versions across release lines up to 2.15.2
- Rancher: unauthenticated update of public UI settings enables stored cross-site scripting
- Rancher: sessions are not revoked server-side on logout
- Rancher: Fleet agent copies downstream resources with cluster-admin privileges, allowing cross-namespace writes
- Rancher: cross-tenant BundleDeployment and Secret disclosure via spoofed cluster labels during agent-initiated registration
- Neither advisory lists CVE identifiers; the Cyber Centre urges applying SUSE updates as they become available
Coverage timelineoldest first · each row is one article
- · 1d agoSUSE Linux security advisory (AV26-968)
Canadian Centre for Cyber Security· 48
Canadian Cyber Centre warns SUSE NeuVector packet-capture filter command injection enables remote code execution on Kubernetes nodes; update advised.
- · 14h agoSUSE Linux security advisory (AV26-974)
Canadian Centre for Cyber Security· 28
Canadian Cyber Centre relayed SUSE advisory AV26-974 covering Rancher flaws including stored XSS, session issues, and cross-tenant secret disclosure; patches advised.