A seven-year-old undetected race condition in XFS allows unprivileged processes to overwrite arbitrary files and gain root access, but can only be fixed through a kernel update.
The LegacyHive vulnerability enables privilege escalation on Windows 10 2004+ and Windows Server 2022; an unofficial micropatch from ACROS Security is available, with an official CVE and update pending.
The BSI warns of multiple Linux kernel vulnerabilities that enable DoS and privilege escalation and pose a significant threat in enterprise environments.
A publicly disclosed zero-day exploit (Legacyhive) allows Windows users to obtain administrative privileges and is currently not being addressed by a Microsoft patch.
Adobe fixes 88 vulnerabilities in a major patch cycle, including eight critical flaws in ColdFusion that enable remote code injection, SQL injection, and authentication bypass.
Manipulated browser extensions can trick the Claude extension into performing actions in Gmail, Google Docs, and Calendar contexts, which Manifold Security has reproduced since May and Anthropic has yet to fix.
The 15-year-old Linux kernel vulnerability GhostLock (CVE-2026-43499) enables root access via local threading calls on nearly all distributions, while patch distribution remains irregular.