logo

Warning: A critical vulnerability in SUSE Multi Linux Manager allows attackers to execute any command as root. Patch Immediately!

ID: 53c22b53-5e06-576d-b70c-8db64ca2e41f

STIX ID: report--53c22b53-5e06-576d-b70c-8db64ca2e41f

Feed Name: Centre for Cybersecurity Belgium Advisories Feed

Threat Score
85/100

Date Published: 2025-07-31

Date Updated: 2026-07-24

...
...

SUSE disclosed CVE-2025-46811, a critical (CVSS 9.8) missing-authentication vulnerability in SUSE Multi Linux Manager that permits any remote unauthenticated actor connected to port 443 to access the /rhn/websocket/minion/remote-commands endpoint and execute arbitrary commands as root on clients, enabling full takeover; vendors and CCB recommend immediate patching, increased monitoring, and reviewing published IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.