Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > privilege escalation
#privilege escalation

Red Hat Patches Kubernetes Flaw That Let Developers Seize Full Cluster-Admin Rights

11 August 2026  |  dark6  |  Vulnerability

A critical privilege escalation vulnerability in Red Hat Advanced Cluster Management, tracked as CVE-2026-10090 and rated 9.9 in severity, allowed any user with basic namespace-level edit permissions to...

>> read more

18-Year-Old Linux Kernel Bug Lets Attackers Seize Full Root and Break Out of Containers

9 August 2026  |  dark6  |  Vulnerability

A newly disclosed use-after-free vulnerability nicknamed SCTPhantom, tracked as CVE-2026-64564, traces back to Linux kernel code written in 2007 and lets a local attacker escalate to full root...

>> read more

Foxit’s Own Update Service Can Be Turned Into a SYSTEM-Level Backdoor on Windows

27 July 2026  |  dark6  |  Vulnerability

A privilege-escalation flaw in Foxit PDF Reader's updater, tracked as CVE-2026-57239, lets an attacker who already has a foothold on a Windows machine ride the update service all...

>> read more

Citrix Patches Privilege Escalation Flaw That Hands Standard Users Full SYSTEM Control

19 July 2026  |  dark6  |  Vulnerability

Cloud Software Group has disclosed two vulnerabilities in Citrix Secure Access and Endpoint Analysis clients for Windows, including a high-severity flaw (CVSS 8.5) that lets a low-privileged local...

>> read more

Unpatched LegacyHive Bug Lets Standard Windows Users Hijack Admin Accounts

18 July 2026  |  dark6  |  Vulnerability

A newly disclosed Windows zero-day called LegacyHive abuses the User Profile Service to let a low-privileged user tamper with an administrator's registry hive, opening a path to persistence...

>> read more

New “Bad Epoll” Linux Zero-Day Lets Local Users Root Servers and Android Devices

6 July 2026  |  dark6  |  Vulnerability

A newly disclosed Linux kernel flaw dubbed “Bad Epoll” (CVE-2026-46242) lets a local, unprivileged user escalate to root on Linux servers, desktops, and Android devices via a use-after-free...

>> read more

Researchers Chain DLL Sideloading and an RPC Flaw to Gain Root Access Inside Claude Cowork’s Sandbox

4 July 2026  |  dark6  |  Vulnerability

Security researchers at Armadin found a way to chain DLL sideloading with a flaw in an internal RPC protocol to escalate privileges and execute commands as root inside...

>> read more

State-Sponsored Hackers Exploit Cisco Catalyst SD-WAN Manager Zero-Day to Gain Root Access

25 June 2026  |  dark6  |  Vulnerability

A state-sponsored threat actor exploited zero-day CVE-2026-20245 in Cisco Catalyst SD-WAN Manager to gain root access via a malicious CSV upload. The multi-phase intrusion also leveraged two CVSS...

>> read more