
CVE-2026-44941: Path traversal in libzypp, the core package manager of SUSE Linux and openSUSE. Run zypper refresh with a malicious repo. Write arbitrary files as root. Full RCE. Millions of servers affected. Found by Trung Nguyễn from CyStack. Details at https://cystack.net/disclosures #CyStack #CyberSecurity #Vulnerability #RCE #OpenSUSE #SUSE #openSUSE #Linux #SupplyChain #InfoSec
Post summary
CVE‑2026‑44941 is a path traversal flaw in libzypp that allows an attacker to gain root RCE and has reportedly affected millions of SUSE/OpenSUSE servers; details are available from the CyStack disclosure.



