September 2026 Linux Patch Roundup

Red | Vulnerability
September 2026 Linux Patch Roundup | HiveForce Labs Threat Advisory
HiveForce Labs · Threat Advisory · Vulnerability Report

September 2026 Linux Patch Roundup

More than 5,782 new vulnerabilities were addressed across Debian, Red Hat, OpenSUSE and Ubuntu in September 2026. HiveForce Labs flags 10 severe vulnerabilities, spanning the Linux kernel, Chrome V8, WinRAR, Ray, Starlette, MLflow and Canonical LXD, that are exploited or highly likely to be.

Threat Level: RedVulnerability ReportTA2026276Published September 22, 2026Admiralty A1
TA Number
TA2026276
Published
September 22, 2026
Admiralty Code
A1
Threat Level
Red
Report Type
Vulnerability Report
New Vulnerabilities
5,782+
Highlighted
352+ with patches
Severe Flagged
10
Distributions
Debian, Red Hat, OpenSUSE, Ubuntu

01 / Overview

Summary

In September, more than 5,782 new vulnerabilities were discovered and addressed within the Linux ecosystem, impacting several major distributions such as Debian, Red Hat, OpenSUSE, and Ubuntu. During this period, over 352 vulnerabilities were also highlighted, with corresponding hotfixes or patches released to resolve them. These Linux vulnerabilities span from information disclosure to privilege escalation to code execution.

HiveForce Labs has identified 10 severe vulnerabilities that are exploited or have a high potential of successful exploitation, necessitating immediate attention. To ensure protection, it is essential to upgrade systems to the latest version with the necessary security patches and appropriate security controls.

Threat Distribution
Denial of ServiceRemote Code ExecutionInformation DisclosureServer-Side Request Forgery
Adversary Tactics
Privilege EscalationExecutionInitial AccessImpactCredential Access

02 / Technical Analysis

Vulnerability Details

  1. #01

    September was a busy month for the Linux ecosystem, with over 5,782 vulnerabilities patched across major distributions and products, ranging from information disclosure bugs to privilege escalation and remote code execution flaws. Out of these, HiveForce Labs flagged 10 critical vulnerabilities that are either already being exploited or likely to be targeted soon, with three confirmed under active attack.

  2. #02

    Chrome users face a more serious threat: two V8 zero-days, CVE-2026-85046 (a type confusion bug) and CVE-2026-87491 (an out-of-bounds write flaw), both allow remote code execution inside the sandbox via a malicious webpage. What makes CVE-2026-87491 especially dangerous is that it's used as part of a full exploit chain called BlueMoon, combining it with CVE-2026-85046 and a Windows kernel privilege escalation bug (CVE-2026-85880) to compromise a machine with a single click.

  3. #03

    BlueMoon first surfaced on August 28, 2026, used by the China-linked group TA412 (also known as JungleBamboo or APT31), and was quickly picked up by several other espionage-focused actors, UTA0560, UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket. Payloads delivered through this chain include the GRIMWEDGE backdoor, the SUPERSTOMP loader (which installs the credential-stealing LONGTALE/GemStone Chrome extension), ShadowPad, and various Rust-based loaders. Targets span NGOs, US aerospace and defense firms, mining and commodity trading companies, Vietnamese manufacturers, and government and financial institutions in Indonesia and Singapore.

  4. #04

    CVE-2025-8088 is another zero-day flaw: a path traversal flaw in the Windows version of WinRAR that lets attackers run arbitrary code through specially crafted archive files.

  5. #05

    On the Linux kernel side, CVE-2025-39964 fixes a race condition in af_alg sockets where concurrent writes could corrupt internal state, the fix now enforces exclusive write ownership. Separately, CVE-2026-53266 is a memory corruption bug in netfilter's bridge ebtables SNAT target, and CVE-2026-53362 is a buffer overflow in the IPv6 stack that lets an unprivileged local user trigger kernel corruption via crafted UDPv6 traffic.

  6. #06

    A few application-layer flaws also stand out. CVE-2025-62593 affects Ray (the AI compute engine), its browser-based defense relies on checking the User-Agent header, which turns out to be trivially spoofable, making it exploitable via DNS rebinding against developers who visit a malicious site. It's fixed in version 2.52.0. CVE-2026-48710 in the Starlette framework stems from unvalidated Host headers, which could let attackers bypass security checks that rely on the reconstructed request URL, patched in 1.0.1.

  7. #07

    Rounding it out, CVE-2026-64849 in MLflow allows attackers to bypass webhook URL validation through redirects, potentially exposing internal or cloud metadata services. And CVE-2026-66897 is a critical path traversal bug in Canonical LXD that lets an attacker with container access overwrite host files as root, leading to full host compromise.

  8. #08

    With active exploitation confirmed on three fronts, especially the Chrome/BlueMoon chain, patching WinRAR, Chrome, and the affected Linux kernel builds should be treated as a top priority this cycle. Timely patching, strict configuration hardening, and defense-in-depth strategies remain essential to prevent system compromise.

CVEs
CVENameAffected ProductImpactAttack Vector
CVE-2025-8088*RARLAB WinRAR Path Traversal VulnerabilityRARLAB WinRARCode ExecutionLocal
CVE-2026-85046*Google Chrome V8 Type Confusion VulnerabilityGoogle ChromeCode ExecutionNetwork
CVE-2026-87491*Google Chromium V8 Out of Bounds Write VulnerabilityGoogle Chrome (V8 Engine)Code ExecutionNetwork
CVE-2025-39964*Linux Kernel Race Condition VulnerabilityLinux kernelData Interleaving and CorruptionLocal
CVE-2025-62593*Ray-Project Ray Code Injection VulnerabilityRay-Project RayCode ExecutionNetwork
CVE-2026-48710*Kludex Starlette HTTP Request/Response Smuggling VulnerabilityKludex StarletteExpose Sensitive DataNetwork
CVE-2026-53266*Linux Kernel Out-of Bounds Write VulnerabilityLinux kernelCode ExecutionLocal
CVE-2026-53362*Linux Kernel Unspecified VulnerabilityLinux kernelCode ExecutionLocal
CVE-2026-64849*MLflow Server-Side Request Forgery VulnerabilityMLflowServer-Side Request ForgeryNetwork
CVE-2026-66897Canonical LXD Path Traversal VulnerabilityCanonical LXDCode ExecutionNetwork

* Notable CVEs: vulnerabilities that are either exploited in zero-day attacks, included in the CISA KEV catalog, utilized in malware operations, or targeted by threat actors in their campaigns.

Notable CVEs
Notable CVE

CVE-2025-39964

Name
Linux Kernel Race Condition Vulnerability
Celebrity Vulnerability
No
Zero-Day
No
CISA KEV
Yes
Affected Products
Linux Kernel, SUSE, Debian, Redhat, Ubuntu
Affected CPE
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:*cpe:2.3:o:canonical:ubuntu_linux:*:*:*:*:*:*:*:*cpe:2.3:o:opensuse:leap:*:*:*:*:*:*:*:*cpe:2.3:o:redhat:enterprise_linux:*:*:*:*:*:*:*:*
CWE ID
CWE-362
Associated TTPs
T1499: Endpoint Denial of Service
Patch Links
SUSE, Debian, Redhat, Ubuntu
Notable CVE

CVE-2025-62593

Name
Ray-Project Ray Code Injection Vulnerability
Celebrity Vulnerability
No
Zero-Day
No
CISA KEV
Yes
Affected Products
Ray Prior to version 2.52.0, Redhat
Associated Attacks / Ransomware
RondoDox ShadowRay 2.0
Affected CPE
cpe:2.3:a:anyscale:ray:*:*:*:*:*:*:*:*cpe:2.3:o:redhat:enterprise_linux:*:*:*:*:*:*:*:*
CWE ID
CWE-94, CWE-352
Associated TTPs
T1189: Drive-by Compromise, T1059: Command and Scripting Interpreter
Patch Links
RHEL
Notable CVE

CVE-2025-8088

Name
RARLAB WinRAR Path Traversal Vulnerability
Celebrity Vulnerability
No
Zero-Day
Yes
CISA KEV
Yes
Affected Products
WinRAR Versions up to and including 7.12, SUSE
Associated Actor
Amaranth-Dragon
Associated Attacks / Ransomware
Amaranth Loader, TGAmaranth RAT
Affected CPE
cpe:2.3:a:rarlab:winrar:*:*:*:*:*:*:*:*cpe:2.3:o:suse:sles:*:*:*:*:*:*:*:*
CWE ID
CWE-35
Associated TTPs
T1204: User Execution, T1204.002: Malicious File, T1059: Command and Scripting Interpreter
Patch Links
Winrar, SUSE
Notable CVE

CVE-2026-48710

Name
Kludex Starlette HTTP Request/Response Smuggling Vulnerability
Celebrity Vulnerability
BadHost
Zero-Day
No
CISA KEV
Yes
Affected Products
Kludex Starlette Prior to version 1.0.1, Redhat
Affected CPE
cpe:2.3:a:encode:starlette:*:*:*:*:*:python:*:*cpe:2.3:o:redhat:enterprise_linux:*:*:*:*:*:*:*
CWE ID
CWE-1289, CWE-444
Associated TTPs
T1059: Command and Scripting Interpreter, T1068: Exploitation for Privilege Escalation
Patch Links
RHEL
Notable CVE

CVE-2026-53266

Name
Linux Kernel Out-of-Bounds Write Vulnerability
Celebrity Vulnerability
No
Zero-Day
No
CISA KEV
Yes
Affected Products
Linux Kernel Version before 5.10, Ubuntu
Affected CPE
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*cpe:2.3:o:canonical:ubuntu_linux:*:*:*:*:*:*:*:*
CWE ID
CWE-787
Associated TTPs
T1059: Command and Scripting Interpreter, T1068: Exploitation for Privilege Escalation
Patch Links
Ubuntu
Notable CVE

CVE-2026-53362

Name
Linux Kernel Unspecified Vulnerability
Celebrity Vulnerability
No
Zero-Day
No
CISA KEV
Yes
Affected Products
Linux kernel, Ubuntu
Affected CPE
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*cpe:2.3:o:canonical:ubuntu_linux:*:*:*:*:*:*:*:*
CWE ID
CWE-122, CWE-787
Associated TTPs
T1068: Exploitation for Privilege Escalation
Patch Links
Linux Kernel, Ubuntu
Notable CVE

CVE-2026-64849

Name
MLflow Server-Side Request Forgery Vulnerability
Celebrity Vulnerability
No
Zero-Day
No
CISA KEV
Yes
Affected Products
MLflow (Before 3.15.0), Redhat
Affected CPE
cpe:2.3:a:mlflow:mlflow:*:*:*:*:*:*:*:*cpe:2.3:o:redhat:enterprise_linux:*:*:*:*:*:*:*:*
CWE ID
CWE-918
Associated TTPs
T1190: Exploit Public-Facing Application, T1552: Unsecured Credentials
Patch Links
mlflow, RHEL
Notable CVE

CVE-2026-85046

Name
Google Chrome V8 Type Confusion Vulnerability
Celebrity Vulnerability
No
Zero-Day
Yes
CISA KEV
Yes
Affected Products
Google Chrome (Before 152.0.7977.82 Linux; Before 152.0.7977.82/.83 Windows, macOS)
Affected CPE
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
CWE ID
CWE-843
Associated TTPs
T1190: Exploit Public-Facing Application, T1059.007: Command and Scripting Interpreter: JavaScript
Patch Links
Chrome
Notable CVE

CVE-2026-87491

Name
Google Chromium V8 Out of Bounds Write Vulnerability
Celebrity Vulnerability
No
Zero-Day
Yes
CISA KEV
Yes
Affected Products
Google Chrome versions before 153.0.8010.36 on Windows, macOS, and Linux
Associated Actor
TA412, UTA0560, UNK_LateNight, UNK_DoubleCheck, UNK_QuietRacket
Associated Attacks / Ransomware
GRIMWEDGE, SUPERSTOMP, LONGTALE (aka GemStone), ShadowPad
Affected CPE
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
CWE ID
CWE-787
Associated TTPs
T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter
Patch Links
Chrome

03 / Action Plan

Recommendations

Proactive Strategies
  1. 01
    Patch Actively Exploited Zero-Days First

    Prioritize WinRAR, Chrome (CVE-2026-85046, CVE-2026-87491), and the affected Linux kernel builds ahead of routine patch cycles, since these are already being exploited in the wild.

  2. 02
    Enable Auto-Updates on High-Risk Applications

    Configure browsers and frequently targeted software to update automatically, shrinking the window attackers have to exploit newly disclosed zero-days.

  3. 03
    Validate Redirects on Webhook Endpoints

    Pin and re-verify the resolved destination after redirects for services like MLflow, so SSRF techniques can't be used to reach internal or cloud metadata services.

  4. 04
    Restrict Container and Template Permissions

    Limit who can edit or launch container images in platforms like LXD, reducing the risk of host-level compromise through path traversal flaws.

  5. 05
    Isolate Developer Tools from General Browsing

    Keep AI/ML platforms such as Ray on separate networks or machines from everyday browsing to limit exposure to malvertising and DNS rebinding attacks.

  6. 06
    Deploy Detection for Multi-Stage Exploit Chains

    Use EDR tooling capable of flagging chained exploitation behavior, since attacks like BlueMoon combine several CVEs to achieve full compromise from a single click.

Reactive Strategies
  1. 01
    Isolate Hosts Showing Compromise Indicators

    If payloads like GRIMWEDGE, SUPERSTOMP, or ShadowPad are detected, disconnect the affected endpoint immediately to stop lateral movement.

  2. 02
    Rotate Exposed Credentials and Sessions

    After detecting credential-stealing tools like the LONGTALE/GemStone extension, reset all potentially exposed passwords, tokens, and active sessions.

  3. 03
    Hunt for Known Threat Actor Indicators

    Proactively search logs and endpoints for IOCs tied to TA412 and related clusters to catch any compromise that evaded initial detection.


04 / Adversary Behaviour

MITRE ATT&CK TTPs

Detect, Mitigate & Patch
CVE IDTTPsDetectionMitigationPatch
CVE-2025-8088*T1204: User Execution, T1204.002: Malicious File, T1059: Command and Scripting InterpreterDET0294 User Execution – Malicious File via download/open → spawn chain (T1204.002), DET0516 Behavioral Detection of Command and Scripting Interpreter AbuseM1038 Execution PreventionPatched
Winrar, SUSE
CVE-2026-85046*T1190: Exploit Public-Facing Application, T1059.007: Command and Scripting Interpreter: JavaScriptDET0080 Exploit Public-Facing Application – multi-signal correlation (request → error → post-exploit process/egress), DET0264 Cross-Platform Detection of JavaScript Execution AbuseM1051 Update Software, M1038 Execution PreventionPatched
Chrome
CVE-2026-87491*T1190: Exploit Public-Facing Application, T1059: Command and Scripting InterpreterDET0080 Exploit Public-Facing Application – multi-signal correlation (request → error → post-exploit process/egress), DET0516 Behavioral Detection of Command and Scripting Interpreter AbuseM1051 Update Software, M1038 Execution PreventionPatched
Chrome
CVE-2025-39964*T1499: Endpoint Denial of ServiceDET0208 Endpoint Resource Saturation and Crash Pattern Detection Across PlatformsM1037 Filter Network TrafficPatched
SUSE, Debian, Redhat, Ubuntu
CVE-2025-62593*T1189: Drive-by Compromise, T1059: Command and Scripting InterpreterDET0176 Drive-by Compromise — Behavior-based, Multi-platform Detection Strategy (T1189), DET0516 Behavioral Detection of Command and Scripting Interpreter AbuseM1051 Update Software, M1038 Execution PreventionPatched
RHEL
CVE-2026-48710*T1059: Command and Scripting Interpreter, T1068: Exploitation for Privilege EscalationDET0516 Behavioral Detection of Command and Scripting Interpreter Abuse, DET0514 Detection Strategy for Exploitation for Privilege EscalationM1045 Code SigningPatched
RHEL
CVE-2026-53266*T1059: Command and Scripting Interpreter, T1068: Exploitation for Privilege EscalationDET0516 Behavioral Detection of Command and Scripting Interpreter Abuse, DET0514 Detection Strategy for Exploitation for Privilege EscalationM1045 Code SigningPatched
Ubuntu
CVE-2026-53362*T1068: Exploitation for Privilege EscalationDET0514 Detection Strategy for Exploitation for Privilege EscalationM1038 Execution Prevention, M1050 Exploit ProtectionPatched
Linux Kernel, Ubuntu
CVE-2026-64849*T1190: Exploit Public-Facing Application, T1552: Unsecured CredentialsDET0080 Exploit Public-Facing Application – multi-signal correlation (request → error → post-exploit process/egress), DET0412 Detect Access or Search for Unsecured Credentials Across PlatformsM1030 Network Segmentation, M1051 Update Software, M1035 Limit Access to Resource Over NetworkPatched
mlflow, RHEL
CVE-2026-66897T1068: Exploitation for Privilege EscalationDET0514 Detection Strategy for Exploitation for Privilege EscalationM1038 Execution Prevention, M1051 Update SoftwareNot patched
Debian, Ubuntu

05 / Sources

References & Patch Links

References

Reduce real exposure. Not just vulnerability volume.