Privilege escalation
Flaws that let an attacker gain admin, root, or kernel-level control from a lesser foothold.
A public exploit turns Kaspersky's endpoint agent into a privilege-escalation tool on fully patched Windows 11
A public exploit, HardBreacher, coerces Kaspersky Endpoint Security into a privileged write on fully patched Windows 11. Vendor says fixed, no CVE yet.
Linux kernel IPv6 flaw (CVE-2026-53362) lets a container break out to host root, now exploited
CVE-2026-53362 is an actively exploited Linux kernel IPv6 flaw that lets a low-privilege user escape a container to host root.
CISA says a 2022 Linux kernel flaw lets a local user become root, and it's now being exploited (CVE-2022-0995)
CISA added Linux kernel flaw CVE-2022-0995 to its actively-exploited list. A local user can escalate to root.
cPanel flaw CVE-2026-65643 lets any hosting account gain root on the whole server. Patch now.
cPanel and WHM flaw CVE-2026-65643 lets any authenticated hosting account write files as root and take full control of a shared server. Patched builds are out.
Unisoc modem flaw lets an answered video call take over the Android kernel, and there is no patch
A two-stage exploit turns a VoLTE video call into full Android kernel access on phones with Unisoc modems. No patch exists; only the chipset maker can fix it.
Windows Task Host flaw CVE-2025-60710 gives a local user SYSTEM, and ransomware gangs now exploit it
CISA confirms ransomware crews are exploiting CVE-2025-60710, a Windows Task Host flaw that elevates a local user to SYSTEM on Windows 11 and Server 2025.
North Korea's Lazarus used fake job offers and a Windows zero-day to hijack defense firms' PCs
North Korea's Lazarus group used fake job offers and a Windows zero-day (CVE-2026-68820) to seize SYSTEM control of defense and aerospace PCs. Patch now.
A Linux kernel SCTP flaw (CVE-2026-64564) escalates to root and breaks out of default-seccomp containers
SCTPhantom (CVE-2026-64564) is a use-after-free in Linux SCTP that reaches host root and escaped default-seccomp containers in 6 of 8 tests.
A second dracut flaw (CVE-2026-15816) lets a rogue DHCP server run code as root on network-booted Linux
CVE-2026-15816 is a second dracut flaw: a rogue DHCP server can run code as root during boot on network-booted Linux. June's CVE-2026-6893 fix missed it.
OVSwrap (CVE-2026-64531): a 13-year-old Open vSwitch kernel bug now hands local users root on default Linux
OVSwrap (CVE-2026-64531, CVSS 7.8) lets an ordinary local user reach root through the Linux Open vSwitch datapath on most default distros.
Critical cPanel flaw lets a hosting account reach database root
cPanel CVE-2026-58048 (CVSS 9.4) lets an authenticated hosting customer run SQL as database root, risking full server compromise. Patch to the fixed build now.
Attackers ran an AI agent unattended to do the hands-on hacking inside Thailand's finance ministry
An attacker ran an unattended AI agent to hack Thailand's finance ministry. It used no new exploit, and defenders catch it by watching host actions.
RefluXFS: a Linux XFS flaw gives any local user root access
RefluXFS (CVE-2026-64600) lets any local user get root on default RHEL, Rocky, Alma and Amazon Linux via an XFS race. No workaround: patch and reboot.
A Jackson library flaw lets low-privilege users write fields meant only for admins
CVE-2026-59889 lets a low-privilege user bypass jackson-databind's @JsonView write guard and set admin-only fields. Patched in 2.18.9, 2.21.5, 3.1.5.
Fully patched Windows, no fix: a new local privilege zero-day
LegacyHive is a Windows User Profile Service privilege-escalation zero-day that works on fully patched systems, with no CVE and no fix yet.
A booby-trapped Linux app can escape its sandbox through the audio server and run on your system
CVE-2026-5674 lets a sandboxed Linux app abuse PipeWire's PulseAudio layer to load a malicious library and run code outside the sandbox.
Two Microsoft zero-days were exploited before the fix shipped
Microsoft's July 2026 Patch Tuesday fixes two zero-days already exploited in the wild: an ADFS and a SharePoint Server privilege bug.
A logged-in user can hijack the Linux graphics server, and on many systems that means root
X.Org patched two memory-corruption bugs in the X server and XWayland. A local client can reach root where Xorg runs as root. Update to 21.1.24 and 24.1.13.
A default in Red Hat's Linux login system lets one directory account seize root on every server
CVE-2026-14474: when SSSD's LDAP sudo provider has no explicit search base, one directory account can plant a rule that grants root on every enrolled Linux
A Linux kernel bug called Bad Epoll turns a sandboxed process into root, and the exploit is now public
Bad Epoll (CVE-2026-46242) lets a sandboxed or unprivileged process reach root on Linux 6.4+ and Android. Fixed in April; a public 99% exploit now exists.
Linux's newest root exploits rewrite /bin/su in memory and leave the file clean
DirtyClone and pedit COW are the latest in a family of Linux kernel root bugs that rewrite binaries in memory, invisible to file-integrity monitoring.
A free GitHub account can push code as a trusted maintainer. Upgrading actions/checkout won't fix it.
Cordyceps lets anyone with a free GitHub account run code as a maintainer on 300+ repos. Why upgrading actions/checkout closes one door, not the others.
One rigged account-sync update can poison your whole app and forge an admin
CVE-2026-48170 lets one SCIM PATCH request poison Object.prototype across a Node.js app using scim-patch, risking admin forgery. Update to 0.9.1 now.
PaperCut's Windows print client can be tricked into giving a local attacker total control
CVE-2026-6645 lets a local attacker plant a file that PaperCut's Print Deploy client runs with full system rights on Windows. Update to version 1.10.4178.
EaseUS Partition Master left a Windows driver that lets any user seize the whole PC
A signed driver in EaseUS Partition Master (CVE-2026-12781) lets any standard Windows user read and overwrite the whole disk to reach SYSTEM.
Branda fixed this WordPress account takeover in January. It is back, and a public exploit is circulating.
CVE-2026-11551 is a CVSS 9.8 unauthenticated account takeover in the Branda WordPress plugin (versions up to 3.4.29). A public exploit is out.
Cisco called this SD-WAN flaw medium. Attackers used it to take root on your WAN.
CVE-2026-20262 is an actively exploited Cisco SD-WAN Manager flaw that escalates a low-privilege login to root.
RoguePlanet turns Microsoft Defender into a SYSTEM shell, and switching it off won't save you
RoguePlanet (CVE-2026-50656) is a public-exploit privilege escalation in Microsoft Defender's engine.
LiteSpeed's cPanel plugin gave shared-hosting tenants root twice in 2026. CageFS didn't help.
CVE-2026-54420 and CVE-2026-48172 let shared-hosting tenants reach root through the LiteSpeed cPanel plugin. Why CageFS isolation failed and what to patch now.
Ready to meet the Guardians?
Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.