Linux
CVE-2026-86708: ManageEngine Shipped a Live GCP Service-Account Key Inside Its Public Installer
CVE-2026-86708 (CVSS 10.0): Zoho's ManageEngine Applications Manager Linux installer shipped a hard-coded, over-privileged Google Cloud service-account key that anyone who downloaded the installer could extract and use to impersonate the account.
CISA Adds Three Linux Kernel Flaws to KEV: TLS Receive Path, ebtables SNAT, and AF_ALG Race Condition Under Active Exploitation
CISA added three Linux kernel CVEs to its Known Exploited Vulnerabilities catalog on evidence of in-the-wild exploitation — a CVSS 9.8 TLS receive-path flaw, an 8.8 ebtables SNAT out-of-bounds write, and a 7.8 AF_ALG race condition — with FCEB remediation due September 21.
CVE-2026-87886: Acronis Backup Plugin for cPanel and Plesk Exploited for Root on Shared Hosting
CVE-2026-87886 (CVSS 7.8) lets a low-privileged local user escalate to root on cPanel, WHM, Plesk, and DirectAdmin hosts via world-writable files left behind by Acronis's backup plugin — already exploited in targeted attacks and added to CISA KEV with a September 19 federal deadline.
PostGREShell (CVE-2026-6471): A 12-Year-Old PostgreSQL Flaw Turns Replication Access Into Root RCE
A missing-authorization bug in PostgreSQL logical decoding, present since version 9.4 in 2014, lets any account with REPLICATION privilege load an arbitrary library and execute code as the database server's OS user.
Fire Ant Expands From VMware Hypervisors to Cisco IOS XR Routers and TACACS Servers
China-nexus actor Fire Ant has moved beyond VMware ESXi hosts to implant Cisco IOS XR routers and TACACS+ authentication servers, using purpose-built tooling to hijack GRE tunnels, hide commands from admins, and intercept credentials at the network's control plane.
GPUThor: First Rowhammer Attack to Defeat ECC on NVIDIA Workstation GPUs
University of Toronto researchers show GPUThor beats NVIDIA's ECC mitigation for GDDR6 Rowhammer, closing the gap the GPUBreach disclosure left open for host root access.
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Fourteen npm packages disguised as calendar and streak utilities smuggle in RedC2 4.0, a commercial Linux implant whose LLM-driven operator console turns plain-English prompts into post-exploitation commands.
Evooo1Bot: New Mirai-Derived Linux Botnet Chains Eight CVEs Spanning 2007–2025 Against Routers and Edge Devices
Evooo1Bot, a modular Mirai-derived Linux botnet tracked by FortiGuard Labs, exploits eight known CVEs dating back to 2007 across routers, firewalls, and industrial gateways to build a SOCKS5 proxy and DDoS network.
CopyEscape (CVE-2026-17106): A Malicious Container Can Overwrite Files on the Docker Host via `docker cp`
CVE-2026-17106 ('CopyEscape'), found by Imperva's Red Team, lets a malicious or compromised container hijack docker cp to overwrite arbitrary files on the host — and, when the copy runs with elevated privileges, replace runc to get root. Docker has shipped fixes across Engine, Desktop, and Sandboxes.
SCTPhantom (CVE-2026-64564): An 18-Year-Old Linux Kernel SCTP Bug Gives Local Root and Escapes Containers
A use-after-free in the Linux kernel's SCTP ASCONF transport handling, present since 2008, lets a local attacker with SCTP reachability escalate to root and, on affected configurations, escape containers.
OVSwrap (CVE-2026-64531): 13-Year-Old Linux Kernel Bug in Open vSwitch Gives Any Local User Root
A 16-bit integer wraparound in the Linux kernel's Open vSwitch action parser (CVE-2026-64531, 'OVSwrap') lets any unprivileged local user become root — no OVS configuration, no CAP_NET_ADMIN, no container privileges required. A public PoC ships precomputed offsets for ~800 kernel builds.
Cisco Ships Two CVSS 9.8+ 'Hardening Releases' for IOS XE and Catalyst SD-WAN in One Day
Cisco's August 5 disclosure batch bundles seven CWE-grouped IOS XE flaws (CVSS 9.8) and five Catalyst SD-WAN flaws (CVSS 9.9) into umbrella CVEs — the first big test of its new AI-driven, twice-monthly hardening-release disclosure model.
Rails CVE-2026-66066: Unauthenticated File Read via Active Storage Image Uploads
A critical 9.5 CVSS flaw in Rails Active Storage lets unauthenticated attackers read arbitrary files — secrets, credentials, master keys — from any app that processes untrusted image uploads with libvips. Patch to 7.2.3.2, 8.0.5.1, or 8.1.3.1.
7-Zip CVE-2026-14266: Heap Overflow in XZ Decoder Lets Crafted Archives Run Code on Extraction
A heap-based buffer overflow in 7-Zip's XZ chunk decoder (CVE-2026-14266) lets a crafted .xz or .7z archive corrupt memory during extraction. Patched in 26.02; no in-the-wild exploitation reported yet, but the affected code path sits in build agents and CI unpacking steps everywhere.
AI Agents Find Two New Redis RCE Chains in Under 90 Minutes
Kimi K3 agents surfaced a stream shared-NACK double-free and a RedisBloom TDigest heap overflow across Redis 6.2 through 8.8, both yielding authenticated remote code execution. Patches are out; no in-the-wild exploitation reported yet.
RefluXFS (CVE-2026-64600): A Nine-Year-Old XFS Race Condition Roots 16.4 Million Linux Systems
A race condition in the XFS copy-on-write path lets any local user overwrite protected files and gain root — no SELinux bypass needed, no workaround available. Patch and reboot is the only fix.
HollowByte: An 11-Byte TLS Handshake Payload That Bloats OpenSSL Server Memory
A memory-allocation flaw in OpenSSL's TLS handshake parsing, dubbed HollowByte, lets an unauthenticated attacker exhaust server memory with an 11-byte payload per connection. No CVE was assigned; patched in 4.0.1 and backported across the 3.x line.
Six U-Boot Flaws Let Malicious Firmware Images Execute Code Before Signature Verification Ever Runs
Binarly found six bugs in U-Boot's FIT image parser — two lead to code execution, four to denial of service — and all six trigger while the bootloader is still reading an untrusted image, before it checks the signature that's supposed to protect it.
GhostLock (CVE-2026-43499): A 15-Year-Old Futex Bug Gives Any Local User Root — and Breaks Out of Containers
A use-after-free in the Linux kernel's futex requeue-PI code, present since 2011, lets any unprivileged local user gain root with a public, 97%-reliable exploit that also escapes Docker and Kubernetes containers.
Januscape (CVE-2026-53359): A 16-Year-Old KVM Bug Lets Guests Escape to the Host
A use-after-free in KVM's shadow MMU, present since 2010, lets a guest VM with nested virtualization corrupt host kernel memory and potentially execute code on the hypervisor — patched July 4 across Intel and AMD x86.