Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
## This update for apache-ivy fixes the following issue: * CVE-2026-26032: directory traversal sequences in module coordinates can allow overwriting arbitrary files outside the configured "buildRoot" directory (bsc#1271727). Changes for apache-ivy: * Upgrade to 2.6.0: * the ivy:retrieve task failed when the retrieve pattern contained some text in parentheses before the first token, for instance: /jobs/lib (JDK 17)/[artifact].[ext] (IVY-1660) * when the ivy:deliver task is configured to replace dynamic revisions, it now replaces these revisions to the resolved revision before any conflict resolution was done, which was the original behavior before Ivy 2.3.0. This way, the delivered ivy.xml can be used to have reproducible dependency
* bsc#1271727
Cross-
* CVE-2026-26032
CVSS scores:
* CVE-2026-26032 ( SUSE ): 5.9
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-26032 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
* CVE-2026-26032 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Affected Products:
* SUSE Linux Enterprise Server 16.0
* SUSE Linux Enterprise Server for SAP applications 16.0
An update that solves one vulnerability can now be installed.
##
* https://www.suse.com/security/cve/CVE-2026-26032.html
* https://bugzilla.suse.com/show_bug.cgi?id=1271727
Get the latest Linux and open source security news straight to your inbox.