❌

Normal view

Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root

18 September 2026 at 18:02
A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine. Kernel maintainers have fixed all four over the past few weeks, so a system running an up-to-date kernel is not affected. But the exploit code is now public, and any machine still running an older kernel should be updated. The flaws

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

18 September 2026 at 16:56
WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install. The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain Click2Shell. On its own the flaw only

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

18 September 2026 at 11:01
A flaw in four widely used AI coding agents lets someone who controls a plugin's code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firmΒ Air Security said on Thursday. The firm said Anthropic has patched the flaw in Claude Code 2.1.179 and OpenAI in Codex 0.146.0, that GitHub Copilot has no

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

17 September 2026 at 18:08
A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Management Server is the system that controls firewall policy and administrator access. Check Point has released a fix through its LivePatch update channel and says it has no indication that the flaw

Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

17 September 2026 at 15:37
Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in aΒ security announcementΒ on September 15. The escape runs with the rights of the host account that runs the virtual machine. The flaw,Β CVE-2026-77179, is rated Critical, affects versions

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

17 September 2026 at 12:30
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in anΒ advisoryΒ on Wednesday. An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution. Unbound 1.26.1, released the same day, fixes the bug, tracked asΒ CVE-2026-81642, along with

❌