Public Exploits for Four Critical Linux Kernel Flaws Released
Article Content
- •Four critical Linux kernel vulnerabilities allow local privilege escalation to root.
- •Public exploit code was released on September 18, 2026, increasing risk for unpatched systems.
- •Affected vulnerabilities include CVE-2026-80844, CVE-2026-81000, CVE-2026-68121, and CVE-2026-74469.
Four vulnerabilities in the Linux kernel, named DirtyAH6, TUNderflow, PPPoEject, and DiagSpill, have been publicly disclosed, allowing local users to escalate privileges to root. These flaws, tracked as CVE-2026-80844, CVE-2026-81000, CVE-2026-68121, and CVE-2026-74469, were discovered by researcher Asim Manizada and reported to the Linux kernel security team in mid-July 2026. Working proof-of-concept exploits were published on September 18, 2026, following a coordinated disclosure process. While kernel maintainers have patched these vulnerabilities, systems running outdated kernels remain at risk. The vulnerabilities primarily affect Linux networking components and could potentially allow attackers to escape containers or execute code remotely under specific conditions. Security teams are urged to apply patches immediately to mitigate risks. No real-world exploitation has been reported yet, but the availability of exploit code increases the threat landscape significantly.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-68121 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CISA Flags Active Exploitation of Linux Kernel Vulnerabilities The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including CVE-2025-39964, which allows local attackers to exploit a race condition in AF_ALG sockets. This vulnerability, along with CVE-2025-39682 and…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…