Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > privilege escalation
#privilege escalation

Steam Windows Zero-Day Turns Local Access Into Full SYSTEM Control

19 September 2026  |  dark6  |  Vulnerability

A newly disclosed weakness in the Steam Client Service reportedly lets a standard Windows user execute code with SYSTEM privileges. With no confirmed vendor fix at publication time,...

>> read more

Plesk Backup Restore Race Opens a Path From Customer Access to Linux Root

13 September 2026  |  dark6  |  Vulnerability

A race condition in Plesk Obsidian’s Backup Manager can let a low-privileged hosting customer cross tenant boundaries and ultimately obtain root access on Linux servers. Administrators should install...

>> read more

Critical Ivanti Flaws Expose ITSM and Mobile Management Systems to RCE and Admin Takeover

9 September 2026  |  dark6  |  Vulnerability

Ivanti has disclosed ten vulnerabilities across EPMM, Neurons for ITSM and Sentry, including unauthenticated remote-code-execution flaws rated 9.8. Cloud instances have been patched, while on-premises customers and Sentry...

>> read more

Ivanti Patches Nine Critical Flaws Across EPMM, Neurons for ITSM, and Sentry

9 September 2026  |  dark6  |  Vulnerability

Ivanti has disclosed a cluster of vulnerabilities spanning Endpoint Manager Mobile, Neurons for ITSM, and Sentry, several rated up to 9.9 in severity and capable of unauthenticated remote...

>> read more

High-Severity Cleo Harmony Bug Lets Attackers Forge Their Way to Admin Access

3 September 2026  |  dark6  |  Vulnerability

A high-severity flaw in Cleo Harmony's JWT refresh-token handling, tracked as CVE-2026-84115, lets remote attackers escalate privileges to admin level with a working exploit already public. Cleo has...

>> read more

Public HardBreacher Code Claims Kaspersky Privilege Escalation, but Evidence Remains Unverified

1 September 2026  |  dark6  |  Vulnerability

A public proof of concept called HardBreacher claims a local privilege-escalation weakness in Kaspersky Endpoint Security on Windows 11. The report remains unconfirmed, has no CVE, and is...

>> read more

Critical cPanel Domain-Parking Flaw Lets Basic Users Seize Root Control

28 August 2026  |  dark6  |  Vulnerability

CVE-2026-65643 allows a low-privileged cPanel user with domain-parking rights to create arbitrary files and ultimately execute code as root. Hosting providers should verify patched builds immediately and restrict...

>> read more

Five New TP-Link Flaws Let Attackers Hijack ISP-Managed Routers and Mesh Systems

15 August 2026  |  dark6  |  Vulnerability

TP-Link has disclosed five vulnerabilities affecting its carrier-supplied Aginet router, mesh, and modem lineup, the worst of which lets an attacker on the network bypass authentication entirely. Because...

>> read more