Security Digest: February 1, 2026 - 1 Critical Vulnerability

Today, a critical vulnerability, CVE-2025-67601, has been identified in Rancher Manager, potentially allowing attackers to bypass TLS security controls.

· 2 min read

Critical Security Alert: Immediate Actions Needed

Executive Summary

Today, a critical vulnerability, CVE-2025-67601, has been identified in Rancher Manager, potentially allowing attackers to bypass TLS security controls. Immediate action is required to mitigate risks associated with this vulnerability.

Critical Vulnerabilities

CVE-2025-67601: Misconfigured TLS Handshake in Rancher Manager

  • Impact: Attackers with network-level access can manipulate the TLS handshake, potentially circumventing security controls and accessing sensitive information.
  • Affected Systems: Rancher Manager versions prior to v2.13.2, v2.12.6, v2.11.10, and v2.10.11.
  • Immediate Action: Upgrade to the latest patched versions immediately: v2.13.2, v2.12.6, v2.11.10, or v2.10.11.
  • Mitigation: If upgrading is not possible, ensure CA certificates are always explicitly passed with the --cacert flag when using the login command.

What to Do Now

  1. Upgrade all affected Rancher Manager instances to the latest patched versions: v2.13.2, v2.12.6, v2.11.10, v2.10.11.
  2. Ensure all developers and users are aware of the requirement to use the --cacert flag.
  3. Regularly monitor systems for unusual network traffic and potential Man-in-the-Middle attack indicators.

Related Resources

Keep reading