{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/neuvector--5.4.11--5.5.4--5.6.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["NeuVector (\u003c 5.4.11, \u003c 5.5.4, \u003c 5.6.2)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","kubernetes","cloud-native"],"_cs_type":"advisory","_cs_vendors":["SUSE"],"content_html":"\u003cp\u003eSUSE has identified a critical vulnerability in the NeuVector container security platform affecting specific versions of the product. The issue lies within the packet-capture (sniffer) filter functionality, which fails to properly sanitize inputs, resulting in an OS command injection flaw. An attacker capable of interacting with the packet-capture configuration can leverage this vulnerability to execute arbitrary commands with the privileges of the NeuVector service. Because NeuVector components typically operate with elevated permissions to monitor network traffic within a Kubernetes cluster, successful exploitation grants the attacker Remote Code Execution (RCE) on the underlying Kubernetes nodes hosting the vulnerable containers. This poses a significant risk to cluster integrity and container isolation. Affected versions include those prior to 5.4.11, 5.5.4, and 5.6.2. Administrators should prioritize updating NeuVector deployments to the patched versions to mitigate potential cluster-wide compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an attacker to achieve full code execution on the underlying host nodes in a Kubernetes environment. This level of access typically results in complete container escape, persistent access to the cluster, potential exfiltration of sensitive secrets and service tokens stored in the cluster, and disruption of critical business services. No specific incident count or sector targeting was provided in the advisory, but all organizations leveraging NeuVector within Kubernetes environments are at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize upgrading all NeuVector instances to versions 5.4.11, 5.5.4, 5.6.2, or later to eliminate the command injection vector. Audit Kubernetes cluster role and container security policy logs for anomalous process execution patterns originating from NeuVector pods.\u003c/p\u003e\n","date_modified":"2026-09-28T22:19:35Z","date_published":"2026-09-28T22:19:35Z","id":"https://feed.craftedsignal.io/briefs/2026-09-suse-neuvector-rce/","summary":"An OS command injection vulnerability in the packet-capture filter component of SUSE NeuVector allows for unauthenticated remote code execution on affected Kubernetes nodes.","title":"Remote Code Execution Vulnerability in SUSE NeuVector","url":"https://feed.craftedsignal.io/briefs/2026-09-suse-neuvector-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - NeuVector (\u003c 5.4.11, \u003c 5.5.4, \u003c 5.6.2)","version":"https://jsonfeed.org/version/1.1"}