Linuxsecurity Critical Vulnerabilities in Cyborg API Affect Ubuntu Users
Article Content
- •Two critical vulnerabilities (CVE-2026-40213, CVE-2026-40214) impact Ubuntu 26.04 LTS and 25.10.
- •CVE-2026-40214 allows deletion of ARQs, risking cross-tenant denial of service.
- •CVE-2026-40213 permits unauthorized actions via a permissive default policy.
Two critical vulnerabilities were discovered in the Cyborg API affecting Ubuntu 26.04 LTS and 25.10. The first vulnerability (CVE-2026-40214) allows authenticated users to delete Accelerator Requests (ARQs) linked to other projects, leading to cross-tenant denial of service. The second vulnerability (CVE-2026-40213) involves a permissive default policy that permits unauthorized actions, such as reprogramming FPGA bitstreams on compute nodes, for any request with a valid authentication token. These vulnerabilities were published on May 7, 2026, and users are advised to update their systems to mitigate the risks. Ubuntu Pro offers ten-year security coverage for affected packages. Immediate action is recommended to prevent potential exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Ubuntu and CVE-2026-40213 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…