privilege-escalation 52
- CISA Warns of Critical Command Injection and Auth Bypass Flaws in Xiiaozet LK100W
- GPUThor Rowhammer Attack Defeats ECC on NVIDIA RTX A6000, Enables Root Access
- N-able Ships Second N-central Hotfix as Attackers Persist on Managed Systems
- New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
- VMware Patches Three Critical Flaws Allowing Auth Bypass, VM Escapes
- Toptech Systems RCU II+/Multiload II+ Missing Authentication Flaw Rated 8.8
- SilverFox Targets Japanese Manufacturer With 3-Driver BYOVD Chain and ValleyRAT
- Check Point Patches Exploited SmartConsole Zero-Day (CVE-2026-16232)
- Fourth SharePoint Vulnerability Exploited to Steal Machine Keys
- SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
- Inc Ransomware Chains SonicWall SMA Zero-Days for Root Access
- CISA Confirms Active Ransomware Exploitation of Windows BlueHammer Flaw
- CISA Confirms Ransomware Gangs Exploiting Microsoft Defender 'BlueHammer' Flaw (CVE-2026-33825)
- Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited
- Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild
- In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw
- CISA Adds Four Actively Exploited Vulnerabilities to KEV Catalog
- Microsoft Working on Patch for 'RoguePlanet' Zero-Day
- LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers
- GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files
- Veeam Backup & Replication Critical RCE CVE-2026-44963 (CVSS 9.4)
- Cisco Catalyst SD-WAN Manager Zero-Day CVE-2026-20245 Actively Exploited, No Patch Available
- Google Patches Android Zero-Day CVE-2025-48595 Exploited in Targeted Attacks
- FortiClient EMS Auth Bypass CVE-2026-35616 Actively Exploited to Deploy EKZ Credential Stealer
- LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root
- LiteSpeed cPanel Plugin CVE-2026-48172 Actively Exploited for Root Privilege Escalation
- Iranian APT Screening Serpens Uses AppDomainManager Hijacking in 2026 Espionage Campaigns
- BYOVD: Exploiting Vulnerable Windows Kernel Drivers Without Their Target Hardware
- Cisco Patches Maximum-Severity Auth Bypass in Secure Workload
- Drupal Patches Unauthenticated RCE Flaw CVE-2026-9082
- Microsoft Defender Vulnerabilities Actively Exploited in the Wild
- DirtyDecrypt PoC Published for Patched Linux Kernel LPE CVE-2026-31635
- MiniPlasma Windows Zero-Day Grants SYSTEM Privileges on Fully Patched Systems
- DirtyDecrypt: Public PoC Released for Linux Kernel Root Escalation Flaw
- Four OpenClaw Vulnerabilities Chain to Enable Data Theft, Privilege Escalation, and Backdoor Planting
- Researcher Drops YellowKey BitLocker Bypass and GreenPlasma Windows EoP Zero-Days
- Fragnesia Linux Kernel LPE (CVE-2026-46300) Grants Root via Page Cache Corruption
- May 2026 Patch Tuesday: 138 CVEs Including Critical Zero-Click Outlook Flaw CVE-2026-40361
- Unit 42 Unpacks AD CS Escalation: Template Misconfigs, Shadow Credentials, and Detection Guidance
- cPanel and WHM Patch Three Vulnerabilities Including RCE and Privilege Escalation
- Dirty Frag Linux Zero-Day Gives Root on All Major Distributions
- CloudZ RAT Abuses Windows Phone Link to Steal Credentials and Bypass 2FA
- 'Copy Fail' Linux Flaw Hits CISA KEV as Active Exploitation Begins
- Critical cPanel and WHM Auth Bypass CVE-2026-41940 Exploited as Zero-Day Since February
- Linux 'Copy Fail' CVE-2026-31431 Enables Root on All Major Distros Since 2017
- Microsoft Patches Entra ID AI Agent Role That Enabled Service Principal Takeover
- 15-Year-Old OpenSSH Flaw Allowed Full Root Shell Access via Certificate Principal Parsing Bug
- Microsoft Defender Zero-Day Exploited to Dump NTLM Hashes and Gain SYSTEM Privileges
- Microsoft Issues Emergency Out-of-Band Patches for Critical ASP.NET Core Privilege Escalation
- Windows Zero-Days Leaked, Now Actively Exploited for SYSTEM Privileges
- Palo Alto Networks and SonicWall Patch High-Severity Privilege Escalation Bugs
- AWS Bedrock AgentCore Flaw Enables "Agent God Mode" via IAM Privilege Escalation