Skip to content
Critical Libvirt Vulnerabilities in Ubuntu 26.04 LTS Exploited

Critical Libvirt Vulnerabilities in Ubuntu 26.04 LTS Exploited

First seen 28 Sep 2026, 19:09 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 20:08 UTC
  • •CISA confirmed active exploitation of libvirt vulnerabilities in Ubuntu 26.04 LTS.
  • •Key vulnerabilities include CVE-2026-18917 and CVE-2026-77159, allowing privilege escalation.
  • •Immediate system updates and reboots are necessary to mitigate these security risks.

Multiple security vulnerabilities have been identified in the libvirt virtualization toolkit affecting Ubuntu 26.04 LTS. Key issues include a local privilege escalation vulnerability (CVE-2026-18917) and a symlink-following vulnerability (CVE-2026-77159), which could allow attackers to execute arbitrary code or change file ownership. CISA has confirmed exploitation of these vulnerabilities in the wild. Administrators are urged to apply patches immediately to mitigate risks. The vulnerabilities impact systems running libvirt versions 12.0.0-1ubuntu5.5. Users are advised to update their systems and reboot to ensure all changes take effect. The vulnerabilities were disclosed in August and September 2026, with the most recent patch released on September 11, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-07
CVE-2026-61477 published
A local attacker could exploit a newline character validation issue in libvirt, leading to command execution.
Linuxsecurity
2026-08-10
CVE-2026-63622 and CVE-2026-63623 published
Two additional vulnerabilities in libvirt were disclosed, increasing the risk for users.
Linuxsecurity
2026-08-20
CVE-2026-18917 published
An integer overflow vulnerability in libvirt was disclosed, allowing potential denial of service or code execution.
Linuxsecurity
2026-09-11
CVE-2026-77159 published
A symlink-following vulnerability in libvirt was disclosed, allowing file ownership changes by local attackers.
Linuxsecurity
2026-09-28
Patches released for libvirt vulnerabilities
Ubuntu released updates for libvirt to address multiple vulnerabilities, urging users to reboot after installation.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track CVE-2026-18917 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed