Critical CVE-2026-93337 in NetworkManager-l2tp Allows Root Code Execution
Article Content
- •CVE-2026-93337 allows local users to escalate privileges to root via NetworkManager-l2tp.
- •The vulnerability affects Linux systems where users can create VPN connections.
- •A proof-of-concept for the exploit has been developed, indicating high risk.
A vulnerability identified as CVE-2026-93337 in NetworkManager-l2tp permits local users to exploit improper input validation of VPN properties, specifically mru and mtu. This flaw enables attackers to inject arbitrary pppd directives, leading to arbitrary code execution with root privileges. The issue affects Linux endpoints and servers where non-administrative users can create VPN connections. The vulnerability has been confirmed on Debian 13 and is considered a high-risk local privilege escalation. A proof-of-concept demonstrating the exploit has been developed, indicating reliable exploitation potential. Administrators are urged to apply patches promptly and restrict VPN connection creation to trusted users until a fix is implemented. Monitoring for unusual changes in PPP options files is also recommended. The vulnerability was published on September 17, 2026, and is currently not confirmed to be actively exploited in the wild.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-93337 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…