Tag: priv-esc
All entries tagged priv-esc.
- CVE-2026-66804, Windows Cross Device Service: a dangling COM registration reaches SYSTEM privilege escalation, and Google Project Zero publishes a general method to hunt for others
- CISA KEV adds three unrelated Linux kernel flaws in one day, kTLS receive-path logic error, AF_ALG race condition, netfilter ebtables SNAT out-of-bounds write
- CVE-2026-87886, Acronis Backup plugin for cPanel/WHM and extension for Plesk: local privilege escalation via insecure default permissions, CISA KEV-listed (CVSS 7.8)
- CVE-2026-58704, Google Pixel: zero-click privilege escalation out of the cellular modem sandbox, exploited in limited, targeted attacks
- CVE-2026-42016 + CVE-2026-42018, JFrog Artifactory: chaining two previously-patched token flaws turns an unauthenticated request into full administrative control in two API calls, confirmed exploited since mid-August
- Ivanti September 2026 Security Update, ten CVEs across Neurons for ITSM, Sentry and EPMM, two unauthenticated CVSS 9.8 deserialization RCEs
- September 2026 Patch Tuesday: two actively exploited Windows privilege-escalation zero-days (CVE-2026-81963 Update Stack, CVE-2026-85880 ALPC)
- Chaotic Eclipse turns its zero-day drops on third-party security products: local privilege escalation in CrowdStrike Falcon and Avast, with working proof-of-concept code public; all three vendors have since remediated
- Dell Secure Connect Gateway DSA-2026-382: an unauthenticated request replayed indefinitely mints ADMIN tokens, and Dell ships no workaround for any of the 105 flaws
- Linux kernel IPv6 UDP fraggap accounting bug (CVE-2026-53362) added to CISA KEV, an unprivileged local heap overflow via MSG_SPLICE_PAGES, no exploitation narrative published
- Unisoc T612 modem (and other devices on shared Unisoc modem firmware): a single answered video call can escalate from modem-level RCE to full Android kernel access via an ARM Memory Protection Unit isolation bypass; no CVE, no patch, vendor unresponsive
- isolated-vm sandbox escape (GHSA-864f-rcv7-6rh4): a TOCTOU type-confusion in ExternalCopy's transferList marshaling breaks the V8 Isolate guest/host boundary, the sandbox underneath a wide range of AI-agent and low-code automation platforms
- SPECTRE unlinks EDR's kernel callbacks one at a time using a two-driver BYOVD toolkit and an offset table for thirteen Windows builds, and its Linux half hides through ftrace rather than the syscall table
- Windows Defender ships its own kernel write primitive: BTR.sys, the signed boot-time remediation driver, takes an encrypted job list from an alternate data stream and will delete or create any file or registry value asked of it
- CVE-2026-71362, Adobe Commerce and Magento Open Source: an unauthenticated attacker switches a customer session to another customer's account (CVSS 9.1), and a WAF vendor reports it is already blocking attempts
- ShieldBreak, a public proof-of-concept defeats Microsoft's July fix for the RoguePlanet Defender flaw, claims 100% reliability where the original was a coin flip, and now covers Windows Server 2025
- Lazarus burned a Windows AFD.sys zero-day (CVE-2026-68820) on European defence targets, FudModule v3.1 blinds the endpoint, and the C2 is other people's Roundcube and WordPress servers
- Linux kernel bridge STP timer use-after-free, a control-flow hijack primitive with a published exploit, no CVE, and no confirmed stable backport
- Wazuh 4.14.6, two cluster-protocol paths to root that bypass the CVE-2026-25770 fix, a DAPI deserialization RCE, and a pre-auth stack overflow on the enrollment port
- Cisco IOS XE August 2026 hardening release, seven CVEs that each stand for a whole class of internally found bugs, no workarounds, and frontier AI models among the discovery tools
- CVE-2026-16443, Keycloak: importing SAML metadata without key-usage attributes silently disables response signature validation, so an unauthenticated attacker forges a login as any known user
- Adobe Campaign Classic APSB26-120, three more unauthenticated CVSS 10.0 code-execution flaws, and last week's build 9398 is the version they affect
- CVE-2026-58048, cPanel & WHM: renaming a database drops the SQL mode that contains a tenant, handing any hosting customer database-root (CVSS 9.4)
- CVE-2026-14512 / CVE-2026-14446, IBM WebSphere Application Server: two pre-auth CVSS 9.8 flaws with no workaround and no fix pack until 3Q2026 (interim APARs only)
- LegacyHive: a public Windows technique that redirects a profile's Local AppData into the NT Object Manager namespace via offline hive edits, reproduced on fully patched systems
- CVE-2026-61425, Balbooa Gridbox for Joomla: a client-supplied cookie is accepted as proof of identity, giving anonymous Super User access
- CVE-2026-54121, Windows Server AD CS 'Certighost': low-priv domain user forges a DC certificate to DCSync, full PoC public (CVSS 8.8)
- SolarWinds Serv-U 2026.3, 15 critical IDOR flaws let authenticated users escalate to root RCE on the file-transfer server (CVSS 9.1)
- CVE-2026-16232, Check Point SmartConsole: authentication bypass to full admin, exploited in the wild (CVSS 9.1)
- Hugging Face: a fully autonomous AI agent breached production, ran 17,000+ actions before detection
- WP2Shell: pre-auth RCE chain in stock WordPress core (CVE-2026-63030 + CVE-2026-60137), out-of-band 7.0.2 patch, exploitation expected short-term
- CVE-2025-40948/-40947/-40949, Siemens RUGGEDCOM ROX II: Unit 42 chains three OT-switch flaws to persistent root
- CISA ICS batch (14 Jul): Rockwell 1715-AENTR unauthenticated debug-port takeover (CVE-2026-10577, CVSS 10.0, fixed in firmware 3.011) and a Swiss-vendor ABB T-MAC Plus auth chain (CVSS 9.9)
- Microsoft July 2026 Patch Tuesday ships two actively-exploited zero-days, AD FS local EoP (CVE-2026-56155) and unauthenticated SharePoint EoP (CVE-2026-56164)
- Siemens SICAM 8 (A8000/EGS/S8000) grid RTUs: firmware-signature-validation bypass + OPC-UA-off-by-default among four CVEs (SSA-229470)
- CVE-2026-50656, Microsoft Defender engine 'RoguePlanet' local privilege escalation now patched; NCSC-CH tracks the ongoing 'Nightmare Eclipse' zero-day series
- CVE-2026-53359, Linux KVM/x86 "Januscape": shadow-MMU use-after-free enables guest-to-host VM escape on Intel and AMD
- CVE-2026-48614, Plesk XML API code injection: authenticated low-privilege user to root (CVSS 9.9)
- GhostLock (CVE-2026-43499), Linux kernel rtmutex use-after-free with a public, 97%-reliable root and container-escape exploit
- CVE-2026-58053, Gitea act_runner Docker backend: container-hardening bypass to host escape (CVSS 9.4, public PoC)
- CVE-2026-46331, Linux kernel "pedit COW": out-of-bounds write in the tc act_pedit module (public weaponised PoC)
- CVE-2026-43503, Linux kernel "DirtyClone": page-cache corruption via XFRM/IPsec skb cloning (working PoC)
- Cisco Catalyst SD-WAN Manager CVE-2026-20245
- Cisco ISE CVE-2026-20181 + CVE-2026-20190: an unauthenticated credential-harvest primitive feeding authenticated root code execution on the identity plane
- Nightmare/Chaotic Eclipse zero-day wave; the Defender LPE now carries a CVE, a public PoC, and Microsoft's "Exploitation More Likely" rating, with no patch
- CVE-2026-20181 / CVE-2026-20190, Cisco Identity Services Engine: unauthenticated credential read chaining to authenticated root command execution
- BSI flags 13 vulnerabilities patched in Zammad 7.1, admin privilege escalation in a DACH public-sector helpdesk platform
- Obsidian Security: a three-CVE chain turns any LiteLLM user into root on the AI gateway
- CVE-2026-54420, LiteSpeed cPanel/WHM plugin: symlink-following on shared hosting, exploited in the wild (CISA KEV)
- "RoguePlanet" Microsoft Defender zero-day: TOCTOU race in the scan engine yields a SYSTEM shell, no CVE, no patch
- CVE-2026-47344 et al. TYPO3 core June release: 13 CVEs across every supported branch (10.4 ELTS → 14.3 LTS)
- Exodus Intelligence publishes working exploit for a one-character Linux kernel nf_tables use-after-free (CVE-2026-23111)
- Keycloak 26.6.3: privilege escalation via OAuth token-exchange and SSRF in the EU public sector's reference identity platform
- CVE-2026-20245, Cisco Catalyst SD-WAN Manager: actively-exploited command-injection to root (no patch)
- CVE-2026-20230, Cisco Unified Communications Manager: unauthenticated SSRF to OS-root file write
- CVE-2026-8206 + CVE-2026-8181, Kirki and Burst Statistics WordPress plugins: unauthenticated account takeover under active mass-exploitation
- Linux cgroups v1 release_agent container escape (CVE-2022-0492) re-enters active exploitation
- CVE-2025-48595, Android Framework: actively-exploited integer-overflow privilege escalation
- CVE-2026-44848 & CVE-2026-44849, Portainer CE: Docker plugin endpoints unguarded; Swarm-service security checks bypassed (CVSS 9.4)
- CVE-2026-44939 (+ CVE-2026-41052, CVE-2026-41053), SUSE Rancher: command injection on cluster import, PSA label privilege-escalation, GitHub-App over-inclusive team membership
- Atos TRC: "hardware-gated" Windows drivers can be made BYOVD-exploitable in software
- CVE-2026-48172, LiteSpeed User-End cPanel plugin: authenticated cPanel user to root via lsws.redisAble, actively exploited
- CVE-2026-46333 ssh-keysign-pwn: a 9-year ptrace race in the Linux kernel reaching root and SSH host keys
- CVE-2026-42822, Microsoft Azure Local Disconnected Operations (ALDO): CVSS 10.0 unauthenticated network elevation-of-privilege, "Exploitation More Likely"
- CVE-2026-31635 ("DirtyDecrypt"), Linux kernel RxGK page-cache write, public PoC; Fedora, Arch, openSUSE Tumbleweed affected
- CVE-2026-41091, Microsoft Defender Engine link-following EoP, actively exploited
- CVE-2026-41225, F5 BIG-IP / BIG-IQ: iControl REST Manager-role authenticated RCE (CVSS 4.0 score 8.6 / CVSS 3.1 score 9.1) leading the May 2026 Quarterly Notification
- CVE-2026-44112 / CVE-2026-44113 / CVE-2026-44115 / CVE-2026-44118, OpenClaw "Claw Chain": four chainable flaws in autonomous-agent platform enable sandbox escape → credential leak → privilege escalation → file disclosure