Security News

Cybersecurity news aggregator

CRITICAL Vulnerabilities SC Media

Ubuntu snap-confine vulnerability grants root access

A critical local privilege escalation vulnerability (CVE-2026-8933, CVSS 7.8 HIGH) in Ubuntu's snap-confine component exploits a race condition during sandbox setup, allowing local attackers to mount a FUSE filesystem, bypass isolation, and write arbitrary files to gain root access. The flaw stems from a security hardening change introduced in July 2025 and affects default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. Administrators must apply the latest snapd updates immediately.
Read Full Article →

Vulnerability Management Ubuntu snap-confine vulnerability grants root access July 22, 2026 Share By SC Staff (Ralf – stock.adobe.com) A critical vulnerability in Ubuntu's snap-confine component has been disclosed, potentially granting full root access to local users on default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The flaw, tracked as CVE-2026-8933, was detailed in new research by the Qualys Threat Research Unit, according to a recent report by Infosecurity Magazine. The vulnerability stems from a security hardening change made in July 2025, where snap-confine shifted to a set-capabilities model. This created a narrow window during the sandbox setup where a race condition could be exploited. Attackers could mount a FUSE filesystem over a temporary directory, bypass isolation, and use a symlink to write to arbitrary files. A secondary race condition widened file permissions before ownership was transferred to root. The exploit could also bypass AppArmor confinement by dropping a malicious rules file, forcing systemd-udevd to execute commands as root. This local privilege escalation flaw affects a wide range of Ubuntu Desktop systems, including workstations and administrative endpoints, as the affected snapd package is included in default installations. Qualys urges administrators to apply the latest snapd updates immediately. Source: Infosecurity Magazine SC Staff Related Patch/Configuration Management Microsoft ends extended security updates for Exchange 2016 and 2019 in October 2026 SC Staff July 22, 2026 The Exchange Server team confirmed that there will be no further extensions beyond the current Period 2 ESU program, which concludes in October 2026. Vulnerability Management F5 fixes critical nginx vulnerability CVE-2026-42533 SC Staff July 20, 2026 The vulnerability, with a CVSS score of 9.2, allows an unauthenticated attacker to trigger a heap buffer overflow by sending specially crafted HTTP requests. Vulnerability Management HollowByte vulnerability allows denial-of-service attacks on OpenSSL SC Staff July 20, 2026 The HollowByte vulnerability, detailed by Okta's Red Team, exploits a flaw in how OpenSSL handles TLS handshake messages. Related Events Cybercast Why Mythos is the cybersecurity crisis we need On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds

Share this article