CVE-2025-71261: Suse Harvester

High severity, CVSS 8.6. EPSS: 0.2% chance of exploitation in the next 30 days.

An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the TLS handshake and abuse it to bypass TLS as a security control.

Affected products

  • Suse Harvester: before 1.8 (fixed in 1.8)

Published 2026-06-16. Last modified 2026-10-07.