Linuxsecurity Critical Libvirt Vulnerabilities in Ubuntu 26.04 LTS Exploited
Article Content
- •CISA confirmed active exploitation of libvirt vulnerabilities in Ubuntu 26.04 LTS.
- •Key vulnerabilities include CVE-2026-18917 and CVE-2026-77159, allowing privilege escalation.
- •Immediate system updates and reboots are necessary to mitigate these security risks.
Multiple security vulnerabilities have been identified in the libvirt virtualization toolkit affecting Ubuntu 26.04 LTS. Key issues include a local privilege escalation vulnerability (CVE-2026-18917) and a symlink-following vulnerability (CVE-2026-77159), which could allow attackers to execute arbitrary code or change file ownership. CISA has confirmed exploitation of these vulnerabilities in the wild. Administrators are urged to apply patches immediately to mitigate risks. The vulnerabilities impact systems running libvirt versions 12.0.0-1ubuntu5.5. Users are advised to update their systems and reboot to ensure all changes take effect. The vulnerabilities were disclosed in August and September 2026, with the most recent patch released on September 11, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-18917 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
SUSE libvirt Vulnerabilities Prompt Urgent Security Updates SUSE has issued security advisories for multiple vulnerabilities in libvirt, affecting Linux systems. Notable vulnerabilities include CVE-2026-18917, an integer overflow leading to a heap buffer overflow, and CVE-2026-63622, which allows privilege escalation via symlink following. Other issues involve potential…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…