Linuxsecurity Critical dracut Command Injection Vulnerability in Ubuntu
Article Content
- •CVE-2026-15816 allows command injection as root during boot failures.
- •Affected systems include Ubuntu 26.04 LTS with specific dracut versions.
- •Immediate updates are required to mitigate this critical vulnerability.
A vulnerability (CVE-2026-15816) was discovered in dracut, an initramfs image generation tool, affecting Ubuntu 26.04 LTS. The flaw allows an attacker on an adjacent network with control over a rogue DHCP server to inject commands that execute as root during boot-failure handling. This vulnerability arises from improper shell quoting of messages written by the die() function to the emergency hook directory. Affected systems include Ubuntu 26.04 LTS with specific dracut package versions. Users are advised to update their systems to mitigate this risk. The vulnerability was published on August 7, 2026, and is considered critical due to its potential for exploitation. Immediate action is recommended to prevent unauthorized access and control. The issue can be resolved by updating to the specified package versions and rebooting the system.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Ubuntu and CVE-2026-15816 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…