LIVE · cybersecurity feed
Live wire
CVE-2026-9055 · WordPress Amelia Plugin Flaw Exploited Before CVE PublicationCVE-2026-46331 · Linux Kernel Flaw Exploited After 71 Days, Not on CISA KEVCVE-2026-84434 · CVE-2026-84434 Exploited Before Publication, No Patch WindowCVE-2024-4405 · Malicious Extensions Hijack AI Browser Agents via Prompt ForcingCVE-2026-58138 · Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the WildCVE-2025-39682 · CISA Flags Three Linux Kernel Vulnerabilities Exploited in the WildBrevo Supply-Chain Attack Infected Over 100,000 WebsitesPublic Exploits Released for Linux Kernel Root Privilege FlawsIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawCisco alerts customers to second actively exploited zero-day in as many days
CVE-2026-46331high

Linux Kernel Flaw Exploited After 71 Days, Not on CISA KEV

A Linux kernel vulnerability, CVE-2026-46331, has been confirmed as exploited, but remains absent from the US federal CISA Known Exploited Vulnerabilities (KEV) catalogue.

zeroday.news ·

A vulnerability in the Linux kernel, identified as CVE-2026-46331, has been exploited in the wild approximately 71 days after its public disclosure. The flaw, which received a CVSS score of 7.8 (High severity), involves a partial copy-on-write (COW) issue in the `net/sched` component, specifically within the `tcf_pedit_act()` function.

The vulnerability stems from `tcf_pedit_act()` calculating the COW range for `skb_ensure_writable()` before the key loop, using `tcfp_off_max_hint`. This hint, however, does not account for the runtime header offset introduced by typed keys, potentially leaving a portion of the write region un-COWed. The fix involves relocating `skb_ensure_writable()` inside the per-key loop, where the actual write offset is known, and incorporating overflow checks for offset arithmetic. For negative offsets, such as those for Ethernet header edits at ingress, `skb_cow()` is used to manage the headroom. Additionally, `offset_valid()` is now guarded against `INT_MIN` to prevent negation issues.

CVE-2026-46331 was initially published on June 16, 2026. Evidence of its exploitation first appeared on August 26, 2026, marking a 71-day window between disclosure and confirmed exploitation. While the vulnerability is listed as exploited in the VulnCheck KEV (Known Exploited Vulnerabilities) catalog, it has not been added to the CISA KEV by the U.S. federal government or the EUVD by ENISA (European Union Agency for Cybersecurity). The CIRCL aggregator mirrors the VulnCheck listing but is not considered an independent corroborating source.

The exploitation of this vulnerability was reported by Securelist on August 26, 2026. The weakness is categorized under CWE-190 (Integer Overflow or Wraparound). The EPSS (Exploit Prediction Scoring System) score for CVE-2026-46331 is 0.58%, placing it in the 46.6th percentile, indicating a moderate likelihood of exploitation.

vulnerabilities in this storyCVE-2026-46331
vulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-9055critical

WordPress Amelia Plugin Flaw Exploited Before CVE Publication

A critical privilege escalation vulnerability in the WordPress Amelia plugin was exploited before its official CVE publication. CISA has not yet added it to its Known Exploited Vulnerabilities catalog.

CVE-2026-84434high

CVE-2026-84434 Exploited Before Publication, No Patch Window

A critical vulnerability, CVE-2026-84434, was reported as exploited on September 18, 2026, one day before its official publication. This flaw has no patch window and is listed in the VulnCheck KEV but not in CISA KEV or EUVD.

vulnerability

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with a bug in the software that runs OpenAI's public help forum and moved through a weakness in OpenAI's own login system. This was security research,

CVE-2024-4405high

Malicious Extensions Hijack AI Browser Agents via Prompt Forcing

A new proof-of-concept attack named BragJack demonstrates how malicious browser extensions can hijack AI assistants within browsers like Chrome and Edge. The attack utilizes a technique called Prompt Forcing to gain control of these AI agents, successfully earning significant bug bounties and two CVEs.

nation-state

Security Affairs newsletter Round 595 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Google Gemini also Broke Out of Its Test Environment AI Helps Hackers Hijack OpenAI Staff Accounts Through […]

security

TigerByte Cyber Emerges From Stealth With $3 Million in Funding

The company has secured over $7 million in contracts with US government agencies, including the US Space Force, the US Navy, and DARPA. The post TigerByte Cyber Emerges From Stealth With $3 Million in Funding appeared first on SecurityWeek.