Security Digest: February 1, 2026 - 1 Critical Vulnerability
Today, a critical vulnerability, CVE-2025-67601, has been identified in Rancher Manager, potentially allowing attackers to bypass TLS security controls.
· 2 min read
Critical Security Alert: Immediate Actions Needed
Executive Summary
Today, a critical vulnerability, CVE-2025-67601, has been identified in Rancher Manager, potentially allowing attackers to bypass TLS security controls. Immediate action is required to mitigate risks associated with this vulnerability.
Critical Vulnerabilities
CVE-2025-67601: Misconfigured TLS Handshake in Rancher Manager
- Impact: Attackers with network-level access can manipulate the TLS handshake, potentially circumventing security controls and accessing sensitive information.
- Affected Systems: Rancher Manager versions prior to v2.13.2, v2.12.6, v2.11.10, and v2.10.11.
- Immediate Action: Upgrade to the latest patched versions immediately:
v2.13.2,v2.12.6,v2.11.10, orv2.10.11. - Mitigation: If upgrading is not possible, ensure CA certificates are always explicitly passed with the
--cacertflag when using the login command.
What to Do Now
- Upgrade all affected Rancher Manager instances to the latest patched versions:
v2.13.2,v2.12.6,v2.11.10,v2.10.11. - Ensure all developers and users are aware of the requirement to use the
--cacertflag. - Regularly monitor systems for unusual network traffic and potential Man-in-the-Middle attack indicators.
Related Resources
- SUSE Rancher Security Team for inquiries.
- Rancher Installation Instructions for upgrading guidance.
- MITRE ATT&CK - Man-in-the-Middle for technique details.