Linux
Curated coverage and analysis in this editorial area.

CVE-2026-23111: Single-Character Logic Error Grants Root Access on Linux
An inverted check in the nf_tables subsystem enables local privilege escalation and container breakouts. With public exploits already…

C0XMO: Gafgyt Variant Targets DD-WRT Routers with Modular Scanner and Competitor-Killing Routine
The C0XMO variant of the Gafgyt botnet exploits CVE-2021-27137 in DD-WRT firmware, utilizing a modular architecture with a standalone…

CVE-2026-8936: Docker Desktop VM Panic Triggered via grpcfuse Recursion
A low-privileged container can trigger a VM panic in Docker Desktop through uncontrolled recursion in the grpcfuse module. The vulnera…

CIFSwitch: Linux Kernel Bug Grants Root Access on CentOS and Rocky Linux
CIFSwitch enables local privilege escalation to root across multiple Linux distributions. While a public PoC is available and an upstr…

CVE-2026-46333: Nine-Year-Old Linux Kernel Flaw Enables Root Escalation
Qualys researchers have disclosed CVE-2026-46333, a Linux kernel vulnerability dormant since 2016 that enables local privilege escalat…

CVE-2025-68670: Pre-auth RCE Vulnerability Identified in xrdp Server Domain Field
A technical breakdown of CVE-2025-68670: A stack buffer overflow within xrdp's domain name processing logic enables unauthenticated re…

NGINX Rift: Critical CVE-2026-42945 Exploitation Detected In-the-Wild
The NGINX Rift vulnerability (CVE-2026-42945) has seen active exploitation since May 16, leveraging a long-dormant heap buffer overflo…

DirtyDecrypt: Linux Local Privilege Escalation Exploit Surfaces for Unpatched Systems
A proof-of-concept for 'DirtyDecrypt'—a local privilege escalation flaw in the Linux kernel's RXGK module—is now public. Organizations…

Fragnesia Flaw Enables Local Root via Linux Page Cache Corruption
CVE-2026-46300 allows local root escalation on Linux by corrupting read-only files in memory. With a public PoC available and patches…

Exim 'Dead.Letter' Vulnerability: Critical RCE Risk for GnuTLS-Based Builds
CVE-2026-45185 is a use-after-free vulnerability in the Exim SMTP BDAT parser that allows unauthenticated RCE on GnuTLS-compiled serve…

Dirty Frag LPE Chain: Deterministic Linux Root Access via Single Command
Dirty Frag exploits two Linux kernel vulnerabilities to achieve deterministic local privilege escalation to root. With a public PoC av…

Exim 'Dead.Letter' Vulnerability: Unauthenticated RCE Threatens GnuTLS-Based Mail Servers
A critical use-after-free vulnerability in Exim’s BDAT parser (CVE-2026-45185) allows for unauthenticated remote code execution on ser…