Skip to content
Multiple Critical Vulnerabilities Discovered in Samba Affecting Unix Systems

Multiple Critical Vulnerabilities Discovered in Samba Affecting Unix Systems

First seen 28 Jul 2026, 15:16 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 29, 2026 at 13:48 UTC

A series of vulnerabilities have been identified in Samba, impacting Unix systems and allowing local and remote attackers to exploit them. Key issues include improper handling of directory ownership by the pam_winbind module (CVE-2026-15779), which can lead to denial of service by changing ownership of critical directories. Additionally, flaws in TSIG packet handling (CVE-2026-6949) can cause crashes in the internal DNS server, while malformed ASN.1 kpasswd packets (CVE-2026-58216) can also result in denial of service. These vulnerabilities affect various distributions, including Ubuntu and openSUSE, prompting urgent patch releases. The vulnerabilities were confirmed by multiple security advisories and pose significant risks to system integrity and availability. System administrators are advised to apply the latest patches immediately to mitigate these risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 45d ago How this analysis works

Timeline

2024-05-30
CVE-2024-36898 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-01-31
CVE-2025-71185 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-02-04
CVE-2026-23057 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-02-14
CVE-2026-23118 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-24
CVE-2026-31649 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-01
CVE-2026-31773 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-01
CVE-2026-31720 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-01
CVE-2026-31781 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-08
CVE-2026-43414 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-27
CVE-2026-46073 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (15)

Following this threat?

Track Ubuntu and CVE-2024-54661 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed