September 2026 Linux Patch Roundup
More than 5,782 new vulnerabilities were addressed across Debian, Red Hat, OpenSUSE and Ubuntu in September 2026. HiveForce Labs flags 10 severe vulnerabilities, spanning the Linux kernel, Chrome V8, WinRAR, Ray, Starlette, MLflow and Canonical LXD, that are exploited or highly likely to be.
TA2026276Published September 22, 2026Admiralty A1TA2026276A15,782+352+ with patches10Summary
In September, more than 5,782 new vulnerabilities were discovered and addressed within the Linux ecosystem, impacting several major distributions such as Debian, Red Hat, OpenSUSE, and Ubuntu. During this period, over 352 vulnerabilities were also highlighted, with corresponding hotfixes or patches released to resolve them. These Linux vulnerabilities span from information disclosure to privilege escalation to code execution.
HiveForce Labs has identified 10 severe vulnerabilities that are exploited or have a high potential of successful exploitation, necessitating immediate attention. To ensure protection, it is essential to upgrade systems to the latest version with the necessary security patches and appropriate security controls.
Threat Distribution
Adversary Tactics
Vulnerability Details
- #01
September was a busy month for the Linux ecosystem, with over
5,782vulnerabilities patched across major distributions and products, ranging from information disclosure bugs to privilege escalation and remote code execution flaws. Out of these, HiveForce Labs flagged10critical vulnerabilities that are either already being exploited or likely to be targeted soon, with three confirmed under active attack. - #02
Chrome users face a more serious threat: two V8 zero-days,
CVE-2026-85046(a type confusion bug) andCVE-2026-87491(an out-of-bounds write flaw), both allow remote code execution inside the sandbox via a malicious webpage. What makesCVE-2026-87491especially dangerous is that it's used as part of a full exploit chain called BlueMoon, combining it withCVE-2026-85046and a Windows kernel privilege escalation bug (CVE-2026-85880) to compromise a machine with a single click. - #03
BlueMoon first surfaced on
August 28, 2026, used by the China-linked group TA412 (also known as JungleBamboo or APT31), and was quickly picked up by several other espionage-focused actors, UTA0560, UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket. Payloads delivered through this chain include the GRIMWEDGE backdoor, the SUPERSTOMP loader (which installs the credential-stealing LONGTALE/GemStone Chrome extension), ShadowPad, and various Rust-based loaders. Targets span NGOs, US aerospace and defense firms, mining and commodity trading companies, Vietnamese manufacturers, and government and financial institutions in Indonesia and Singapore. - #04
CVE-2025-8088is another zero-day flaw: a path traversal flaw in the Windows version of WinRAR that lets attackers run arbitrary code through specially crafted archive files. - #05
On the Linux kernel side,
CVE-2025-39964fixes a race condition inaf_algsockets where concurrent writes could corrupt internal state, the fix now enforces exclusive write ownership. Separately,CVE-2026-53266is a memory corruption bug in netfilter's bridge ebtables SNAT target, andCVE-2026-53362is a buffer overflow in the IPv6 stack that lets an unprivileged local user trigger kernel corruption via crafted UDPv6 traffic. - #06
A few application-layer flaws also stand out.
CVE-2025-62593affects Ray (the AI compute engine), its browser-based defense relies on checking the User-Agent header, which turns out to be trivially spoofable, making it exploitable via DNS rebinding against developers who visit a malicious site. It's fixed in version2.52.0.CVE-2026-48710in the Starlette framework stems from unvalidated Host headers, which could let attackers bypass security checks that rely on the reconstructed request URL, patched in1.0.1. - #07
Rounding it out,
CVE-2026-64849in MLflow allows attackers to bypass webhook URL validation through redirects, potentially exposing internal or cloud metadata services. AndCVE-2026-66897is a critical path traversal bug in Canonical LXD that lets an attacker with container access overwrite host files as root, leading to full host compromise. - #08
With active exploitation confirmed on three fronts, especially the Chrome/BlueMoon chain, patching WinRAR, Chrome, and the affected Linux kernel builds should be treated as a top priority this cycle. Timely patching, strict configuration hardening, and defense-in-depth strategies remain essential to prevent system compromise.
CVEs
| CVE | Name | Affected Product | Impact | Attack Vector |
|---|---|---|---|---|
CVE-2025-8088* | RARLAB WinRAR Path Traversal Vulnerability | RARLAB WinRAR | Code Execution | Local |
CVE-2026-85046* | Google Chrome V8 Type Confusion Vulnerability | Google Chrome | Code Execution | Network |
CVE-2026-87491* | Google Chromium V8 Out of Bounds Write Vulnerability | Google Chrome (V8 Engine) | Code Execution | Network |
CVE-2025-39964* | Linux Kernel Race Condition Vulnerability | Linux kernel | Data Interleaving and Corruption | Local |
CVE-2025-62593* | Ray-Project Ray Code Injection Vulnerability | Ray-Project Ray | Code Execution | Network |
CVE-2026-48710* | Kludex Starlette HTTP Request/Response Smuggling Vulnerability | Kludex Starlette | Expose Sensitive Data | Network |
CVE-2026-53266* | Linux Kernel Out-of Bounds Write Vulnerability | Linux kernel | Code Execution | Local |
CVE-2026-53362* | Linux Kernel Unspecified Vulnerability | Linux kernel | Code Execution | Local |
CVE-2026-64849* | MLflow Server-Side Request Forgery Vulnerability | MLflow | Server-Side Request Forgery | Network |
CVE-2026-66897 | Canonical LXD Path Traversal Vulnerability | Canonical LXD | Code Execution | Network |
* Notable CVEs: vulnerabilities that are either exploited in zero-day attacks, included in the CISA KEV catalog, utilized in malware operations, or targeted by threat actors in their campaigns.
Notable CVEs
CVE-2025-39964
- Name
- Linux Kernel Race Condition Vulnerability
- Celebrity Vulnerability
- No
- Zero-Day
- No
- CISA KEV
- Yes
- Affected Products
- Linux Kernel, SUSE, Debian, Redhat, Ubuntu
- Affected CPE
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:*cpe:2.3:o:canonical:ubuntu_linux:*:*:*:*:*:*:*:*cpe:2.3:o:opensuse:leap:*:*:*:*:*:*:*:*cpe:2.3:o:redhat:enterprise_linux:*:*:*:*:*:*:*:*- CWE ID
CWE-362- Associated TTPs
T1499: Endpoint Denial of Service- Patch Links
- SUSE, Debian, Redhat, Ubuntu
CVE-2025-62593
- Name
- Ray-Project Ray Code Injection Vulnerability
- Celebrity Vulnerability
- No
- Zero-Day
- No
- CISA KEV
- Yes
- Affected Products
- Ray Prior to version
2.52.0, Redhat - Associated Attacks / Ransomware
- RondoDox ShadowRay 2.0
- Affected CPE
cpe:2.3:a:anyscale:ray:*:*:*:*:*:*:*:*cpe:2.3:o:redhat:enterprise_linux:*:*:*:*:*:*:*:*- CWE ID
CWE-94,CWE-352- Associated TTPs
T1189: Drive-by Compromise,T1059: Command and Scripting Interpreter- Patch Links
- RHEL
CVE-2025-8088
- Name
- RARLAB WinRAR Path Traversal Vulnerability
- Celebrity Vulnerability
- No
- Zero-Day
- Yes
- CISA KEV
- Yes
- Affected Products
- WinRAR Versions up to and including
7.12, SUSE - Associated Actor
- Amaranth-Dragon
- Associated Attacks / Ransomware
- Amaranth Loader, TGAmaranth RAT
- Affected CPE
cpe:2.3:a:rarlab:winrar:*:*:*:*:*:*:*:*cpe:2.3:o:suse:sles:*:*:*:*:*:*:*:*- CWE ID
CWE-35- Associated TTPs
T1204: User Execution,T1204.002: Malicious File,T1059: Command and Scripting Interpreter- Patch Links
- Winrar, SUSE
CVE-2026-48710
- Name
- Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Celebrity Vulnerability
- BadHost
- Zero-Day
- No
- CISA KEV
- Yes
- Affected Products
- Kludex Starlette Prior to version
1.0.1, Redhat - Affected CPE
cpe:2.3:a:encode:starlette:*:*:*:*:*:python:*:*cpe:2.3:o:redhat:enterprise_linux:*:*:*:*:*:*:*- CWE ID
CWE-1289,CWE-444- Associated TTPs
T1059: Command and Scripting Interpreter,T1068: Exploitation for Privilege Escalation- Patch Links
- RHEL
CVE-2026-53266
- Name
- Linux Kernel Out-of-Bounds Write Vulnerability
- Celebrity Vulnerability
- No
- Zero-Day
- No
- CISA KEV
- Yes
- Affected Products
- Linux Kernel Version before
5.10, Ubuntu - Affected CPE
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*cpe:2.3:o:canonical:ubuntu_linux:*:*:*:*:*:*:*:*- CWE ID
CWE-787- Associated TTPs
T1059: Command and Scripting Interpreter,T1068: Exploitation for Privilege Escalation- Patch Links
- Ubuntu
CVE-2026-53362
- Name
- Linux Kernel Unspecified Vulnerability
- Celebrity Vulnerability
- No
- Zero-Day
- No
- CISA KEV
- Yes
- Affected Products
- Linux kernel, Ubuntu
- Affected CPE
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*cpe:2.3:o:canonical:ubuntu_linux:*:*:*:*:*:*:*:*- CWE ID
CWE-122,CWE-787- Associated TTPs
T1068: Exploitation for Privilege Escalation- Patch Links
- Linux Kernel, Ubuntu
CVE-2026-64849
- Name
- MLflow Server-Side Request Forgery Vulnerability
- Celebrity Vulnerability
- No
- Zero-Day
- No
- CISA KEV
- Yes
- Affected Products
- MLflow (Before
3.15.0), Redhat - Affected CPE
cpe:2.3:a:mlflow:mlflow:*:*:*:*:*:*:*:*cpe:2.3:o:redhat:enterprise_linux:*:*:*:*:*:*:*:*- CWE ID
CWE-918- Associated TTPs
T1190: Exploit Public-Facing Application,T1552: Unsecured Credentials- Patch Links
- mlflow, RHEL
CVE-2026-85046
- Name
- Google Chrome V8 Type Confusion Vulnerability
- Celebrity Vulnerability
- No
- Zero-Day
- Yes
- CISA KEV
- Yes
- Affected Products
- Google Chrome (Before
152.0.7977.82Linux; Before152.0.7977.82/.83Windows, macOS) - Affected CPE
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*- CWE ID
CWE-843- Associated TTPs
T1190: Exploit Public-Facing Application,T1059.007: Command and Scripting Interpreter: JavaScript- Patch Links
- Chrome
CVE-2026-87491
- Name
- Google Chromium V8 Out of Bounds Write Vulnerability
- Celebrity Vulnerability
- No
- Zero-Day
- Yes
- CISA KEV
- Yes
- Affected Products
- Google Chrome versions before
153.0.8010.36on Windows, macOS, and Linux - Associated Actor
- TA412, UTA0560, UNK_LateNight, UNK_DoubleCheck, UNK_QuietRacket
- Associated Attacks / Ransomware
- GRIMWEDGE, SUPERSTOMP, LONGTALE (aka GemStone), ShadowPad
- Affected CPE
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*- CWE ID
CWE-787- Associated TTPs
T1190: Exploit Public-Facing Application,T1059: Command and Scripting Interpreter- Patch Links
- Chrome
Recommendations
Proactive Strategies
- 01Patch Actively Exploited Zero-Days First
Prioritize WinRAR, Chrome (
CVE-2026-85046,CVE-2026-87491), and the affected Linux kernel builds ahead of routine patch cycles, since these are already being exploited in the wild. - 02Enable Auto-Updates on High-Risk Applications
Configure browsers and frequently targeted software to update automatically, shrinking the window attackers have to exploit newly disclosed zero-days.
- 03Validate Redirects on Webhook Endpoints
Pin and re-verify the resolved destination after redirects for services like MLflow, so SSRF techniques can't be used to reach internal or cloud metadata services.
- 04Restrict Container and Template Permissions
Limit who can edit or launch container images in platforms like LXD, reducing the risk of host-level compromise through path traversal flaws.
- 05Isolate Developer Tools from General Browsing
Keep AI/ML platforms such as Ray on separate networks or machines from everyday browsing to limit exposure to malvertising and DNS rebinding attacks.
- 06Deploy Detection for Multi-Stage Exploit Chains
Use EDR tooling capable of flagging chained exploitation behavior, since attacks like BlueMoon combine several CVEs to achieve full compromise from a single click.
Reactive Strategies
- 01Isolate Hosts Showing Compromise Indicators
If payloads like GRIMWEDGE, SUPERSTOMP, or ShadowPad are detected, disconnect the affected endpoint immediately to stop lateral movement.
- 02Rotate Exposed Credentials and Sessions
After detecting credential-stealing tools like the LONGTALE/GemStone extension, reset all potentially exposed passwords, tokens, and active sessions.
- 03Hunt for Known Threat Actor Indicators
Proactively search logs and endpoints for IOCs tied to TA412 and related clusters to catch any compromise that evaded initial detection.
MITRE ATT&CK TTPs
Detect, Mitigate & Patch
References & Patch Links
References
https://lore.kernel.org/linux-cve-announce/https://github.com/leonov-av/linux-patch-wednesdayhttps://www.debian.org/security/#DSAShttps://lists.ubuntu.com/archives/ubuntu-security-announce/https://access.redhat.com/security/security-updates/https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/
