Home/ Blog/ Topics/ Privilege escalation
Topic

Privilege escalation

Flaws that let an attacker gain admin, root, or kernel-level control from a lesser foothold.

Security news

A public exploit turns Kaspersky's endpoint agent into a privilege-escalation tool on fully patched Windows 11

A public exploit, HardBreacher, coerces Kaspersky Endpoint Security into a privileged write on fully patched Windows 11. Vendor says fixed, no CVE yet.

Security news

Linux kernel IPv6 flaw (CVE-2026-53362) lets a container break out to host root, now exploited

CVE-2026-53362 is an actively exploited Linux kernel IPv6 flaw that lets a low-privilege user escape a container to host root.

Security news

CISA says a 2022 Linux kernel flaw lets a local user become root, and it's now being exploited (CVE-2022-0995)

CISA added Linux kernel flaw CVE-2022-0995 to its actively-exploited list. A local user can escalate to root.

Security news

cPanel flaw CVE-2026-65643 lets any hosting account gain root on the whole server. Patch now.

cPanel and WHM flaw CVE-2026-65643 lets any authenticated hosting account write files as root and take full control of a shared server. Patched builds are out.

Security news

Unisoc modem flaw lets an answered video call take over the Android kernel, and there is no patch

A two-stage exploit turns a VoLTE video call into full Android kernel access on phones with Unisoc modems. No patch exists; only the chipset maker can fix it.

Security news

Windows Task Host flaw CVE-2025-60710 gives a local user SYSTEM, and ransomware gangs now exploit it

CISA confirms ransomware crews are exploiting CVE-2025-60710, a Windows Task Host flaw that elevates a local user to SYSTEM on Windows 11 and Server 2025.

Security news

North Korea's Lazarus used fake job offers and a Windows zero-day to hijack defense firms' PCs

North Korea's Lazarus group used fake job offers and a Windows zero-day (CVE-2026-68820) to seize SYSTEM control of defense and aerospace PCs. Patch now.

Security news

A Linux kernel SCTP flaw (CVE-2026-64564) escalates to root and breaks out of default-seccomp containers

SCTPhantom (CVE-2026-64564) is a use-after-free in Linux SCTP that reaches host root and escaped default-seccomp containers in 6 of 8 tests.

Security news

A second dracut flaw (CVE-2026-15816) lets a rogue DHCP server run code as root on network-booted Linux

CVE-2026-15816 is a second dracut flaw: a rogue DHCP server can run code as root during boot on network-booted Linux. June's CVE-2026-6893 fix missed it.

Security news

OVSwrap (CVE-2026-64531): a 13-year-old Open vSwitch kernel bug now hands local users root on default Linux

OVSwrap (CVE-2026-64531, CVSS 7.8) lets an ordinary local user reach root through the Linux Open vSwitch datapath on most default distros.

Security news

Critical cPanel flaw lets a hosting account reach database root

cPanel CVE-2026-58048 (CVSS 9.4) lets an authenticated hosting customer run SQL as database root, risking full server compromise. Patch to the fixed build now.

Security news

Attackers ran an AI agent unattended to do the hands-on hacking inside Thailand's finance ministry

An attacker ran an unattended AI agent to hack Thailand's finance ministry. It used no new exploit, and defenders catch it by watching host actions.

Security news

RefluXFS: a Linux XFS flaw gives any local user root access

RefluXFS (CVE-2026-64600) lets any local user get root on default RHEL, Rocky, Alma and Amazon Linux via an XFS race. No workaround: patch and reboot.

Security news

A Jackson library flaw lets low-privilege users write fields meant only for admins

CVE-2026-59889 lets a low-privilege user bypass jackson-databind's @JsonView write guard and set admin-only fields. Patched in 2.18.9, 2.21.5, 3.1.5.

Security news

Fully patched Windows, no fix: a new local privilege zero-day

LegacyHive is a Windows User Profile Service privilege-escalation zero-day that works on fully patched systems, with no CVE and no fix yet.

Security news

A booby-trapped Linux app can escape its sandbox through the audio server and run on your system

CVE-2026-5674 lets a sandboxed Linux app abuse PipeWire's PulseAudio layer to load a malicious library and run code outside the sandbox.

Security news

Two Microsoft zero-days were exploited before the fix shipped

Microsoft's July 2026 Patch Tuesday fixes two zero-days already exploited in the wild: an ADFS and a SharePoint Server privilege bug.

Security news

A logged-in user can hijack the Linux graphics server, and on many systems that means root

X.Org patched two memory-corruption bugs in the X server and XWayland. A local client can reach root where Xorg runs as root. Update to 21.1.24 and 24.1.13.

Security news

A default in Red Hat's Linux login system lets one directory account seize root on every server

CVE-2026-14474: when SSSD's LDAP sudo provider has no explicit search base, one directory account can plant a rule that grants root on every enrolled Linux

Security news

A Linux kernel bug called Bad Epoll turns a sandboxed process into root, and the exploit is now public

Bad Epoll (CVE-2026-46242) lets a sandboxed or unprivileged process reach root on Linux 6.4+ and Android. Fixed in April; a public 99% exploit now exists.

Security news

Linux's newest root exploits rewrite /bin/su in memory and leave the file clean

DirtyClone and pedit COW are the latest in a family of Linux kernel root bugs that rewrite binaries in memory, invisible to file-integrity monitoring.

Security news

A free GitHub account can push code as a trusted maintainer. Upgrading actions/checkout won't fix it.

Cordyceps lets anyone with a free GitHub account run code as a maintainer on 300+ repos. Why upgrading actions/checkout closes one door, not the others.

Security news

One rigged account-sync update can poison your whole app and forge an admin

CVE-2026-48170 lets one SCIM PATCH request poison Object.prototype across a Node.js app using scim-patch, risking admin forgery. Update to 0.9.1 now.

Security news

PaperCut's Windows print client can be tricked into giving a local attacker total control

CVE-2026-6645 lets a local attacker plant a file that PaperCut's Print Deploy client runs with full system rights on Windows. Update to version 1.10.4178.

Security news

EaseUS Partition Master left a Windows driver that lets any user seize the whole PC

A signed driver in EaseUS Partition Master (CVE-2026-12781) lets any standard Windows user read and overwrite the whole disk to reach SYSTEM.

Security news

Branda fixed this WordPress account takeover in January. It is back, and a public exploit is circulating.

CVE-2026-11551 is a CVSS 9.8 unauthenticated account takeover in the Branda WordPress plugin (versions up to 3.4.29). A public exploit is out.

Security news

Cisco called this SD-WAN flaw medium. Attackers used it to take root on your WAN.

CVE-2026-20262 is an actively exploited Cisco SD-WAN Manager flaw that escalates a low-privilege login to root.

Security news

RoguePlanet turns Microsoft Defender into a SYSTEM shell, and switching it off won't save you

RoguePlanet (CVE-2026-50656) is a public-exploit privilege escalation in Microsoft Defender's engine.

Security news

LiteSpeed's cPanel plugin gave shared-hosting tenants root twice in 2026. CageFS didn't help.

CVE-2026-54420 and CVE-2026-48172 let shared-hosting tenants reach root through the LiteSpeed cPanel plugin. Why CageFS isolation failed and what to patch now.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.