# Red Hat and SUSE security vulnerability disclosures

> Live situation record from CLSTR: https://clstr.news/situations/red-hat-and-suse-security-vulnerability-disclosures
> Updated: 2026-08-16T01:25:04.000Z. Sources: 8. Developments: 2.

Red Hat and SUSE have disclosed several critical security vulnerabilities affecting enterprise software and virtualization components.

Red Hat reported a high-severity privilege escalation flaw (CVE-2026-10090) in its Advanced Cluster Management for Kubernetes. The vulnerability, which carries a CVSS score of 9.9, allows users with limited permissions to potentially gain full cluster-admin status. Simultaneously, SUSE released patches for various vulnerabilities across its Linux and openSUSE distributions, addressing risks such as remote code execution and denial of service in components like the Linux kernel and OpenSSH.

Following these disclosures, SUSE identified a specific critical vulnerability (CVE-2026-25727) in the virtiofsd virtualization component. This flaw, rated with a CVSS score of 8.7, involves an error in the daemon’s date parser that can lead to stack exhaustion. The issue affects multiple operating systems, including openSUSE Leap 15.6 and several SUSE Linux Enterprise Server versions, necessitating updates to maintain the stability of virtualized infrastructures.

## Timeline

### 2026-08-16: SUSE addresses critical CVE-2026-25727 vulnerability in virtiofsd

A high-risk vulnerability (CVE-2026-25727) in the virtiofsd component affects SUSE and openSUSE systems, potentially causing stack exhaustion in virtualized environments.

6 sources. https://clstr.news/cluster/suse-addresses-critical-cve-2026-25727-vulnerability-in-virtiofsd

### 2026-08-10: Red Hat and SUSE disclose critical security vulnerabilities and patches

Red Hat disclosed a critical 9.9 CVSS privilege escalation flaw in its ACM for Kubernetes, while SUSE released security patches for the Linux kernel, Python, and other core components.

2 sources. https://clstr.news/cluster/red-hat-and-suse-disclose-critical-security-vulnerabilities-and-patches

---
Cite as: Red Hat and SUSE security vulnerability disclosures. CLSTR, https://clstr.news/situations/red-hat-and-suse-security-vulnerability-disclosures
