< ciso
brief />
Tag Banner

All news with #privilege escalation tag

352 articles · page 2 of 18

Zyxel and Veeam Flaws Under Active Exploitation

🛡️ CISA added a now-patched Zyxel GS1900 series switch vulnerability (CVE-2026-7273, CVSS 8.8) to its Known Exploited Vulnerabilities list after evidence of active exploitation. The stack-based buffer overflow in the device CGI could permit unauthenticated LAN attackers to execute OS commands; multiple GS1900 firmware versions have fixes. Simultaneously, Arctic Wolf reported active exploitation of a local privilege escalation in Veeam Agent for Windows (CVE-2026-32996, CVSS 7.3) allowing local users to attain SYSTEM privileges via a cached elevated session UID.
read more →

Public exploit code released for four Linux kernel flaws

🛡️ A researcher published working exploits for four Linux kernel local privilege-escalation flaws called DirtyAH6, TUNderflow, PPPoEject, and DiagSpill. Kernel maintainers have released fixes in recent stable kernels, so up-to-date systems are not vulnerable, but unpatched machines should be updated promptly. Three flaws require unprivileged user namespaces to reach, while DiagSpill needs only SCTP support. The exploits are tuned to specific builds, may crash systems, and so far show no evidence of in-the-wild use.
read more →

Microsoft patches CVSS 10.0 flaw in Azure AI Foundry

🔒 Microsoft has released a fix for a maximum-severity privilege escalation flaw in Azure AI Foundry (CVE-2026-85889, CVSS 10.0). The company says the issue, discovered by Rémy Marot, allowed missing authentication for a critical function but has been fully mitigated and requires no customer action. Microsoft also patched several other high-severity Azure and Windows vulnerabilities in recent updates.
read more →

Critical Docker Sandboxes Escape Flaw Fixed in 0.42.0

🛡️ Docker warned on September 15 that a critical flaw, CVE-2026-77179, in Docker Sandboxes for macOS allowed code running inside a VM to escape the shared project directory and read or modify files on the host as the VMM user; the issue was fixed in 0.42.0 released September 7. A second high-severity issue, CVE-2026-79994, let guests trick a relay into connecting to AF_UNIX sockets outside the workspace. Docker recommends upgrading to 0.42.0+ or using clone mode and avoiding read-write host mounts until patched.
read more →

Parallels Desktop local privilege escalation flaw

🔒 JFrog disclosed a local privilege escalation in Parallels Desktop for Mac that allows a non‑admin local account to execute code as root by abusing the prl_disp_service socket and an unsafe InstallAppliance extract template. The issue, tracked as CVE-2026-90894 and rated 7.8 by JFrog, was demonstrated on Parallels Desktop 26.4.0 on Apple silicon. JFrog says the fix appears in the 27.x line, which is only installable on Apple silicon Macs, leaving Intel users on the 26.x line without the described repair.
read more →

Google patches Pixel modem flaw amid active exploitation

🔐 Google disclosed a high-severity privilege escalation flaw in its Pixel Cellular Modem, tracked as CVE-2026-58704 (CVSS 8.0), which may be under limited targeted exploitation. The NIST description notes a logic error enabling permission bypass and remote (proximal/adjacent) escalation without user interaction. September Pixel updates include fixes for this issue plus 109 other vulnerabilities; users should apply security patches dated 2026-09-05 or later via Settings > Security & privacy.
read more →

Acronis Patch Urged After cPanel Plugin Exploit

🔒 Acronis has disclosed a high-severity local privilege escalation flaw in its Backup plugin for cPanel and WHM, tracked as CVE-2026-87886 (CVSS 7.8), and confirmed it has been exploited in the wild. The issue stems from insecure file permissions and affects older builds of the cPanel & WHM (Linux) plugin and the Plesk extension; fixes are included in 1.9.3 HF3 for cPanel and in updated Plesk builds. Acronis urges immediate installation of the update; limited targeted attacks have been observed, though attribution and detailed attack objectives remain unknown.
read more →

Google issues September 2026 Pixel security updates

🔒 Google released September 2026 security patches for Pixel devices addressing 110 vulnerabilities, including one zero-day actively exploited in targeted attacks. The high-severity issue, CVE-2026-58704, is a modem component authorization flaw that can allow adjacent-network attackers with basic privileges to escalate privileges without user interaction. Pixel users should install the update via Settings and restart devices to complete the patch.
read more →

Acronis warns of exploited cPanel backup flaw

🔒 Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. The flaw, designated CVE-2026-87886 with a 7.8 severity score, allows a low-privileged attacker to elevate permissions on affected Linux servers. Acronis reports limited, targeted exploitation and urges administrators to apply patches that fix affected builds of the plugin and extension.
read more →

LiteSpeed Enterprise flaw risks root on shared hosts

⚠️ cPanel warned on September 14 of a critical vulnerability in LiteSpeed Web Server Enterprise affecting versions before 6.3.7 that could allow a low-privilege hosting account to escalate to root on shared servers. Administrators are urged to install 6.3.7, released by LiteSpeed on September 11, using the provided manual update command. The advisory notes the flaw can bypass account isolation controls such as CageFS, but neither vendor has published technical details, a CVE, or evidence of exploitation.
read more →

cPanel SQL injection in EmailTrack allows root takeover

🛡️ cPanel has patched an SQL injection flaw, tracked as CVE-2026-67401, that allows an authenticated hosting account with mail-related privileges to create files via EmailTrack and escalate to root. The advisory, published September 8, affects every supported cPanel & WHM release line and lists fixed builds for 11.110, 11.134, 11.136, 11.138 and WP Squared. cPanel provides update instructions but offers no interim mitigations, exploit details, or guidance for post-compromise verification.
read more →

SAP issues emergency patches for critical kernel flaws

🔒 SAP released urgent security updates to fix multiple critical vulnerabilities, including a maximum-severity (CVSS 10.0) memory corruption bug in EPP Processing (CVE-2026-44756, "OVERPASS") discovered by Onapsis. The flaw is remotely exploitable without authentication and can lead to OS command execution with SAP administrative privileges, risking full compromise of business data and processes. SAP also patched CVE-2026-58240 ("S4GET") in NetWeaver Message Server and two other high-severity issues affecting CAP and SAP GUI for Java.
read more →

Microsoft Patch Tuesday: September 2026 Vulnerabilities

🔒 Microsoft released its September 2026 security update covering 973 vulnerabilities across many products, including 113 marked critical. Two vulnerabilities were reported exploited in the wild: one in the Windows Update Stack (CVE-2026-81963) and one in Windows ALPC (CVE-2026-85880). The bulletin highlights numerous remote code execution and elevation-of-privilege issues, with several high CVSS scores and multiple components prioritized for remediation.
read more →

MikroTik RouterOS SSH flaws exploited in wild

🔒 Hackers are actively exploiting two recently disclosed MikroTik RouterOS vulnerabilities to hijack routers with internet-exposed SSH. The chain combines an SSH authentication bypass (CVE-2026-67276) that lets attackers log in if they know a username and the public modulus, and an SSH privilege escalation (CVE-2026-86060) that grants full administrative rights via specially crafted usernames. Poland's CERT, aided by GPT-5.5-cyber and GPT-5.6-sol, named the campaign “MikroTrick” and confirmed active exploitation; MikroTik released patches and added compromise-detection measures in recent RouterOS updates.
read more →

Zero-day Privilege Escalation Reported in CrowdStrike

🛡️ A security researcher known as “Nightmare Eclipse” published a GitHub proof-of-concept on September 3 for a zero-day privilege escalation called FalconFlank that targets CrowdStrike Falcon Sensor. The exploit abuses the Microsoft Office file malicious macro remediation feature and reportedly works on fully updated Windows 11 25H2 and Windows Server 2025 when specific CrowdStrike settings are enabled. CrowdStrike advised customers to disable the Microsoft Office File Suspicious Macro Removal policy while it investigates and referenced a customer-only tech alert. No CVE has been assigned yet, and the researcher has also published other vendor zero-days previously.
read more →

Critical VMware Workstation and Fusion Fixes Released

🔒 Broadcom has released patches for two vulnerabilities in VMware Workstation and Fusion, including a critical integer-overflow bug (CVE-2026-59346) that could allow arbitrary code execution from a privileged local VM user. A second fix addresses a stack-based buffer overflow in HGFS (CVE-2026-59347). Both flaws require the attacker to have local administrative privileges on the VM and have been fixed in VMware Workstation 26H1u1 and Fusion 26H1u1. Broadcom credited external researchers for reporting the issues and noted no current evidence of in-the-wild exploitation, though recent attacks on VMware products increase urgency.
read more →

PostgreSQL patch for long‑running logical decoding flaw

🔒 PostgreSQL released fixes for CVE-2026-6471, a vulnerability in logical decoding present since 2014 that allows accounts with the REPLICATION attribute to load arbitrary libraries and execute code as the OS user running the server. A new server parameter, output_plugin_libraries, whitelists allowed output plugins and defaults to 'pgoutput, test_decoding', causing non-default plugins like wal2json and decoderbufs to be blocked until administrators add them and reload configuration. The update affects supported branches 14–18 and is available in upstream and vendor packages; administrators are advised to identify used plugins, update, and add any required non-default plugins to the new parameter.
read more →

CrowdStrike FalconFlank zero-day grants SYSTEM access

🛡️ An anonymous researcher called "Nightmare Eclipse" released a zero-day named FalconFlank that escalates privileges on fully patched Windows 11 and Windows Server systems by abusing CrowdStrike Falcon's Office malicious macros remediation. Successful exploitation spawns a command prompt with SYSTEM privileges, and CrowdStrike is investigating while advising customers to disable the Microsoft Office File Suspicious Macro Removal policy. The advisory is available to customers via the CrowdStrike support portal only.
read more →

CloudTrail incident response: multi‑Region Bedrock attack

🔍 This post examines a multi‑stage attack that begins with a web application SSRF vulnerability on an EC2 instance, leads to IMDSv1 credential harvesting for an attached webdev role, and culminates in unauthorized access to Amazon Bedrock across Regions. It walks through four CloudTrail events—failed CreateUser, console sign‑in without MFA, ListFoundationModels in another Region, and a Converse call invoking Amazon Nova Pro—and shows which log fields reveal attribution, intent, and cross‑Region pivots. The article also provides containment, remediation, and hardening recommendations.
read more →

Decade-old PostgreSQL flaw risks backup accounts

🛡️ A decade-old vulnerability in PostgreSQL’s logical replication can let low-privilege REPLICATION accounts load and execute arbitrary code, potentially escalating to superuser and full server compromise. Cyera Research named the issue PostGREShell and reported it to the PostgreSQL Security Team; patches were issued in August for supported releases including 18.6, 17.11, 16.15, 15.19, and 14.24. Windows systems are especially exposed due to UNC/SMB loading vectors. Administrators are urged to patch, audit replication accounts, and restrict outbound SMB/NFS access.
read more →