Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
SUSE

SUSE Vendor Cyber Rating & Cyber Score

suse.com

SUSE is a global leader in innovative, reliable and secure enterprise open source solutions, including SUSEⓇ Linux Suite, SUSEⓇ Rancher Suite, SUSEⓇ Edge Suite and SUSEⓇ AI Suite. More than 60% of the Fortune 500 rely on SUSE to power their mission-critical workloads, enabling them to innovate everywhere – from the data center to the cloud, to the edge and beyond. SUSE puts the “open” back in open source, collaborating with partners and communities to give customers the agility to tackle innovation challenges today and the freedom to evolve their strategy and solutions tomorrow. For more information, visit www.suse.com.


SUSE A.I CyberSecurity Scoring

SUSE
Company Information
Website:http://www.suse.com
Employees number:2,708
Number of followers:186,294
NAICS:5112
Industry Type:Software Development
Homepage:suse.com
SUSE Risk Score (AI oriented)
Between 750 and 799
logo
SUSESoftware Development
Updated:
08/05/2026
757/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
SUSE Global Score (TPRM)
xxxx
logo
SUSESoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

SUSE
SUSEFair
Current Score
757Baa (FAIR)
01000
6 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
758Before Incident
MAY 2026
762Before Incident
Vulnerability
08 May 2026SUSE
SUSE: Critical Vulnerability in Rancher Fleet Enables Full Cluster-Admin Privileges

Critical Rancher Fleet Vulnerability (CVE-2026-41050) Exposes Kubernetes Clusters to Privilege Escalation

757After Incident
CRITICAL-5
SUS1778235983
Critical Rancher Fleet Vulnerability (CVE-2026-41050) Exposes Kubernetes Clusters to Privilege Escalation The SUSE Rancher Security team has disclosed a critical vulnerability, CVE-2026-41050, affecting Rancher Fleet, a widely used GitOps tool for managing Kubernetes clusters. The flaw completely breaks multi-tenant isolation, allowing attackers to bypass security boundaries and extract sensitive data, including admin credentials. ### Vulnerability Details The issue stems from Fleet’s Helm deployer failing to enforce ServiceAccount impersonation, enabling two attack vectors: 1. Helm Lookup Exploitation – Malicious Helm charts using the `lookup` function execute with fleet-agent privileges instead of restricted tenant permissions, allowing attackers to harvest secrets from any namespace. 2. FleetFleet.yaml Misconfiguration – The `valuesFrom` directive in configuration files reads secrets with cluster-admin privileges, making unauthorized access appear as legitimate operations. Attackers with basic git push access to a monitored repository can deploy malicious charts to extract admin tokens, enabling full cluster-admin access or lateral movement into corporate infrastructure (e.g., AWS IAM roles). ### Affected Versions - Rancher Fleet: Versions before 0.11.13, 0.12.14, 0.13.10, and 0.14.5. - Rancher: - 2.10.11 and older (requires manual Fleet upgrade). - 2.11.x, 2.12.x, 2.13.x (patched in 2.11.13, 2.12.9, 2.13.5). - 2.14.0 (patched in 2.14.1). ### Impact & Mitigation The vulnerability poses a severe risk to shared DevOps and Kubernetes-as-a-Service environments. While patching is the definitive fix, security teams are advised to: - Disable Fleet-monitored repositories for untrusted tenants. - Audit Git repositories for malicious Helm charts using `lookup` or cross-namespace `valuesFrom`. - Rotate exposed secrets (e.g., `kube-system` namespace) if unauthorized access is detected. - Enable strict Kubernetes API audit logging to monitor future secret reads. The flaw was analyzed by Lyrie Threat Intelligence, which warned that the Helm deployer could effectively function as a secret-harvesting tool in compromised environments.
INCIDENT DETAILS -
TYPE
Privilege Escalation
IMPACT
Data Compromised: Admin credentials, sensitive secrets (e.g., kube-system namespace)Systems Affected: Kubernetes clusters managed by Rancher FleetOperational Impact: Full cluster-admin access, lateral movement into corporate infrastructure (e.g., AWS IAM roles)Identity Theft Risk: High (exposure of admin credentials and PII)
DATA BREACH
Type Of Data Compromised: Admin credentials, sensitive secretsSensitivity Of Data: High (admin tokens, PII, corporate infrastructure access)Data Exfiltration: Possible via malicious Helm chartsPersonally Identifiable Information: Possible (admin credentials, secrets)
APRIL 2026
762Before Incident
MARCH 2026
766Before Incident
Vulnerability
18 Mar 2026SUSE
GNU: Critical Telnetd Vulnerability Enables Remote Code Execution Attacks

Critical Telnetd Vulnerability (CVE-2026-32746) Exposes Legacy Systems to Remote Code Execution

761After Incident
CRITICAL-5
GNU1773836738
Critical Telnetd Vulnerability (CVE-2026-32746) Exposes Legacy Systems to Remote Code Execution A severe buffer overflow vulnerability (CVE-2026-32746) has been identified in the GNU InetUtils telnetd daemon, allowing unauthenticated attackers to execute arbitrary code with root privileges. The flaw, rated 9.8 (CVSS 3.1), was discovered by Dream Security Labs and affects all versions of the software up to 2.7. The vulnerability stems from improper handling of LINEMODE SLC (Set Local Characters) option negotiation during the initial connection handshake. By sending a maliciously crafted message with an excessive triplet count over TCP port 23, attackers can trigger a buffer overflow before authentication occurs meaning no credentials or user interaction are required. Since telnetd typically runs with root privileges, successful exploitation grants full system compromise, enabling backdoor deployment, data exfiltration, or lateral movement within a network. While modern IT environments have largely replaced Telnet with SSH, the protocol persists in legacy Industrial Control Systems (ICS), operational technology (OT), and government networks, including PLCs, SCADA systems, and embedded devices where upgrades are costly or operationally disruptive. This makes the flaw particularly dangerous for critical infrastructure, such as power grids, water treatment facilities, and manufacturing plants, where security modernization is slow and exposed systems remain common. Mitigation efforts include disabling telnetd where possible, blocking port 23 at the network perimeter, restricting access to trusted IPs, and running the daemon without root privileges. Detection requires network-level monitoring, as standard logs won’t capture the attack. Security teams should configure firewalls to log all port 23 connections and deploy IDS/IPS solutions (e.g., Suricata, Snort) to flag LINEMODE SLC payloads exceeding 90 bytes. No active exploitation has been confirmed, but the flaw’s severity demands immediate action.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Systems Affected: Legacy Industrial Control Systems (ICS), operational technology (OT), government networks, PLCs, SCADA systems, embedded devicesOperational Impact: Full system compromise, backdoor deployment, data exfiltration, lateral movement
DATA BREACH
Data Exfiltration: Possible (if exploited)
FEBRUARY 2026
766Before Incident
JANUARY 2026
766Before Incident
DECEMBER 2025
766Before Incident
NOVEMBER 2025
766Before Incident
OCTOBER 2025
765Before Incident
SEPTEMBER 2025
765Before Incident
AUGUST 2025
765Before Incident
JULY 2025
765Before Incident
JUNE 2025
769Before Incident
Vulnerability
16 Jun 2025SUSE
SUSE

Critical Vulnerability in SUSE Manager (CVE-2025-46811)

765After Incident
CRITICAL-4
SUS629073125
A critical security vulnerability in SUSE Manager allows unauthenticated attackers to execute arbitrary commands with root privileges. This flaw, tracked as CVE-2025-46811, has a CVSS 4.0 score of 9.3 and affects multiple versions of SUSE Manager across various platforms. The vulnerability stems from a Missing Authentication for Critical Function weakness, which targets a specific websocket endpoint. Organizations are at risk of widespread compromise, requiring immediate updates to mitigate the threat. The impact is significant as it could lead to complete system compromise, affecting enterprise infrastructure.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Container suse/manager/5.0/x86_64/server:5.0.5.7.30.1SLES15-SP4-Manager-Server-4-3-BYOS (all variants)SLES15-SP4-Manager-Server-4-3-BYOS-AzureSLES15-SP4-Manager-Server-4-3-BYOS-EC2SLES15-SP4-Manager-Server-4-3-BYOS-GCESUSE Manager Server Module 4.3
AUGUST 2017
762Before Incident
Vulnerability
01 Aug 2017SUSE
SUSE: New Linux 'Copy Fail' Vulnerability Enables Root Access on Major Distributions

Linux Kernel Flaw (CVE-2026-31431) Enables Local Privilege Escalation to Root

758After Incident
CRITICAL-4
SUS1777552033
Linux Kernel Flaw (CVE-2026-31431) Enables Local Privilege Escalation to Root Cybersecurity researchers from Xint.io and Theori have disclosed a high-severity Linux local privilege escalation (LPE) vulnerability, tracked as CVE-2026-31431 (CVSS 7.8), which allows an unprivileged local user to gain root access. Dubbed "Copy Fail", the flaw stems from a logic error in the Linux kernel’s cryptographic subsystem, specifically within the algif_aead module, introduced in a 2017 code commit. Exploitation requires only a 732-byte Python script, which manipulates the kernel’s page cache to modify a setuid binary (e.g., `/usr/bin/su`), enabling arbitrary code execution as root. The attack involves four key steps: 1. Opening an AF_ALG socket bound to `authenc(hmac(sha256),cbc(aes))`. 2. Crafting a shellcode payload. 3. Triggering a write operation to the kernel’s cached copy of a privileged binary. 4. Executing the binary to run the injected code with root privileges. The vulnerability affects all major Linux distributions released since 2017, including Amazon Linux, RHEL, SUSE, and Ubuntu. While not remotely exploitable, it poses a significant risk in multi-user or containerized environments, as the page cache is shared system-wide, allowing cross-container impacts. Security experts note that Copy Fail shares similarities with Dirty Pipe (CVE-2022-0847), another LPE flaw that enabled unauthorized writes to read-only files. However, Copy Fail is distinguished by its portability, small exploit size, stealth, and cross-container capabilities, making it particularly dangerous. Unlike many kernel exploits, it does not rely on race conditions or kernel offsets, ensuring reliable exploitation across distributions. In response to the disclosure, affected Linux vendors have released security advisories to address the flaw. The vulnerability underscores the ongoing risks of kernel-level logic errors in widely deployed systems.
INCIDENT DETAILS -
TYPE
Local Privilege Escalation (LPE)
IMPACT
Systems Affected: All major Linux distributions released since 2017Operational Impact: Arbitrary code execution as root, cross-container impacts
JANUARY 2017
767Before Incident
Vulnerability
01 Jan 2017SUSE
Debian, SUSE, Ubuntu and Sudo: ‘CrackArmor’ Vulnerability in AppArmor Impacts 12.6M Linux Systems

Critical AppArmor Vulnerabilities Expose Millions of Linux Systems to Attack

760After Incident
CRITICAL-7
SUSDEBSUDCAN1773426242
Critical AppArmor Vulnerabilities Expose Millions of Linux Systems to Attack Cybersecurity firm Qualys has uncovered nine severe vulnerabilities in AppArmor, the default security enforcement tool for major Linux distributions, including Ubuntu, Debian, and SUSE. These flaws, present since 2017 (version v4.11), affect an estimated 12.6 million enterprise systems worldwide, leaving them vulnerable to privilege escalation and container escapes. The vulnerabilities stem from a "confused deputy" attack, where a low-privileged user manipulates trusted system tools (such as Sudo or Postfix) to bypass security restrictions. By exploiting hidden pseudo-files, attackers can gain root access, disable protections, or even break out of isolated containers often without detection. The risks include denial-of-service (DoS) attacks, unauthorized system modifications, and the removal of critical security policies. The impact extends to banking, healthcare, and telecommunications, with CISA and DHS issuing emergency alerts for energy, water, and defense sectors, citing potential alignment with state-sponsored hacking tactics. Qualys CTO Dilip Bachwani emphasized that these flaws demonstrate how even default security mechanisms can be compromised without admin credentials. While no CVE identifiers have been assigned, vendors including Ubuntu, Debian, SUSE, and Sudo have collaborated with Qualys to release patches. Administrators are advised to apply the latest kernel updates immediately to mitigate exposure.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
MOTIVATION
State-sponsored hackingUnauthorized system access
IMPACT
Systems Affected: 12.6 million enterprise systemsDenial-of-service (DoS) attacksUnauthorized system modificationsRemoval of critical security policies
Vulnerability
01 Jan 2017SUSE
SUSE and Linux: 9-Year-Old Linux Kernel Vulnerability “Copy Fail” Enables Full Root Access

Linux Kernel Flaw 'Copy Fail' Grants Root Access via Memory Manipulation

760After Incident
CRITICAL-7
THESUS1777537860
Linux Kernel Flaw "Copy Fail" Grants Root Access via Memory Manipulation Security researchers at Theori uncovered a critical vulnerability in the Linux kernel, present since 2017, that allows unprivileged users to gain full system control. Tracked as CVE-2026-31431 (dubbed Copy Fail), the flaw was discovered using Theori’s AI-powered code auditing tool, following an initial lead by researcher Taeyang Lee. The bug resides in the algif_aead module, part of Linux’s cryptographic subsystem, which handles AEAD (Authenticated Encryption with Associated Data) operations. A miscalculation in the authencesn tool causes it to incorrectly write four bytes of data into the page cache a memory region storing frequently accessed file fragments. Due to a 2017 performance optimization, these bytes can overwrite critical system files in memory, such as /usr/bin/su, without altering the disk-based version. Attackers can exploit this with a 732-byte Python script, modifying memory-resident files to escalate privileges to root access. The flaw is highly reliable, working consistently across multiple Linux distributions, including Ubuntu 24.04 LTS, Amazon Linux 2023, Red Hat Enterprise Linux 10.1, and SUSE 16. Its in-memory nature leaves minimal forensic traces, evading traditional file integrity checks. Linux has released a patch (commit a664bf3d603d) that prevents the issue by forcing safe data copying, replacing the vulnerable in-place method. For systems unable to update immediately, disabling the algif_aead module mitigates the risk without disrupting common applications like web browsers or SSH. Security experts, including David Brumley of Bugcrowd, emphasize the flaw’s severity, noting its broker-market value and cross-distribution reliability. Brumley warned that the shared page cache in containerized environments could allow a single compromised tenant to affect the entire host, underscoring the need for urgent patching. The discovery also signals a shift in exploit discovery, as AI-driven tools lower the cost of uncovering deep logic flaws in critical systems.
INCIDENT DETAILS -
TYPE
Privilege Escalation
IMPACT
Systems Affected: Linux systems (Ubuntu 24.04 LTS, Amazon Linux 2023, Red Hat Enterprise Linux 10.1, SUSE 16)Operational Impact: Full system control (root access) by unprivileged users

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for SUSE ?
?
What was SUSE's A.I Rankiteo Cyber Score in May 2026 ?
?
What was SUSE's A.I Rankiteo Cyber Score in April 2026 ?
?
What was SUSE's A.I Rankiteo Cyber Score in March 2026 ?
?
What was SUSE's A.I Rankiteo Cyber Score in February 2026 ?
?
What was SUSE's A.I Rankiteo Cyber Score in January 2026 ?
?
What was SUSE's A.I Rankiteo Cyber Score in December 2025 ?
?
What was SUSE's A.I Rankiteo Cyber Score in November 2025 ?
?
What was SUSE's A.I Rankiteo Cyber Score in October 2025 ?
?
What was SUSE's A.I Rankiteo Cyber Score in September 2025 ?
?
What was SUSE's A.I Rankiteo Cyber Score in August 2025 ?
?
What was SUSE's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on SUSE's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with SUSE ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view SUSE's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?