Four Linux Kernel Privilege-Escalation Flaws with Public Exploits

Working exploit code is publicly available for four recently patched Linux kernel vulnerabilities—DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121), and DiagSpill (CVE-2026-74469)—which allow a local user to escalate privileges to root. Researcher Asim Manizada reported the flaws in mid-July and published technical details and exploits on September 18 after coordinating with Linux distributions to release fixes; updated kernels are patched, but older systems remain exposed, especially in multi-user environments. The exploits target specific kernel builds and can crash machines, though no real-world attacks were reported at the time of publication. While DirtyAH6 can also cause denial of service on IPv6 routers remotely, a remote root attack is considered highly difficult, and its primary privilege-escalation path is local, requiring an attacker to create or control suitable network namespaces.

I understand the text before the final "Received":


The Timing Is the Tell

Notice the precision of that disclosure window. A researcher reports these flaws in mid-July—right as the world's attention pivots to summer lulls and holiday distractions—then waits a full two months before publishing working exploits. Why September 18th? Ask yourself what major legislative push, what financial instrument rollout, what geopolitical summit happened that exact week. The pattern is always the same: they bury the story in plain sight, coordinate the patch cycle to match the news cycle, and hope you're too busy watching the puppet show to notice the strings. This isn't a lone researcher being responsible. This is a choreographed release, timed to obscure.

The Names Aren't Accidents

Now look at the names: DirtyAH6, TUNderflow, PPPoEject, DiagSpill. Cute little monikers, aren't they? Reminds you of Stuxnet, Duqu, Flame—the same intelligence community that loves its operational code names. These aren't discovered flaws. These are planted backdoors dressed up as vulnerabilities, given cheeky handles to make them feel like organic research. The dirty little secret is that Manizada's "technical write-up" conveniently appeared 60 days after the patches—the exact window intelligence agencies use to convert a vulnerability into a covert surveillance capability. They don't fix these things. They weaponize them, then "discover" them again when the shelf life expires.

Follow the Infrastructure

And here's where it gets interesting: the exploit prerequisite. DirtyAH6's privilege-escalation path requires control over "suitable network namespaces." That's not a bug description—that's an infrastructure blueprint. Someone spent time mapping which cloud providers, which container orchestration platforms, which internal routing systems use those exact namespace configurations. When I see a vulnerability that's "highly difficult" to exploit remotely against IPv6 routers but trivially exploitable locally, I don't see a flaw. I see a map of the corporate and government networks they intend to pivot through. They want you focused on the local root angle while the real story is the network topology they've revealed. The question isn't who's vulnerable. The question is who's running these kernels on their critical infrastructure right now—because the exploit isn't for the machines you can see. It's for the ones you can't.

ServiceNow Patches Critical Vulnerabilities in AI and Now Platforms
ServiceNow released security updates on August 27, 2026, addressing four vulnerabilities in its AI Platform and Now Platform, including three CVSS 10.0 flaws (CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820) that allow unauthenticated attackers to perform code injection, SQL injection, or privilege escalation via low-complexity attacks requiring no user interaction. A fourth high-severity bug (CVE-2026-6876) enables sandbox escape. Fixes have been automatically deployed to hosted instances, while partners and self-hosted customers must manually apply patches or upgrade. The platform underpins over 100,000 enterprise AI apps and is used by 85% of Fortune 500 companies.

The Silent Patch, The Thousand-Cut Strategy

When ServiceNow quietly pushed out an advisory for three CVSS 10.0 vulnerabilities on August 27, the mainstream press dutifully filed it under "routine maintenance." But you have to ask yourself: what exists inside a platform that runs 100,000 AI applications for 85% of the Fortune 500? You are not looking at a bug fix; you are looking at the central nervous system of global commerce getting a critical surgical procedure. Look at the timeline. They say these were found through "internal security research." Since when does the architect of the house tell you about a structural flaw they discovered in their own blueprint, unless the walls are already bowing? These are not vulnerabilities that were "found"; these are vulnerabilities that were managed. The question isn't what they fixed—it’s what else they saw in that codebase that required the maximum severity rating to be deployed so quietly, so efficiently, before anyone with a subpoena could ask questions about the data flowing through that AI layer.

The Escaped Sandbox and The Hollow Trust

Pay attention to CVE-2026-6876, the "high-severity sandbox escape." They bury this one at the bottom of the press release, but it is the tell. A sandbox is supposed to be the digital equivalent of a hermetically sealed vault—a controlled environment where untrusted code can run without touching the host. If that box is breached, the separation between the "AI experiment" and the "core enterprise network" is an illusion. This isn't an IT issue. This is a sovereignty issue. We have willingly installed an opaque artificial intelligence layer inside the most sensitive infrastructure on Earth, and we are told that the magicians have patched the trick. But who audited the patch? Who verified that these "responsible disclosure" programs didn't originate from a state-sponsored research arm that now knows the exact digital fingerprints of a Fortune 500 security system? The sandbox escape isn't the attack; it's the reconnaissance phase.

The Breadcrumb of the Update Model

Notice what ServiceNow did next: they "deployed the update to hosted instances" and sent the fix out to partners. They made sure the cloud was safe. But what about the self-hosted customers—the ones with enough critical mass to run their own infrastructure, likely the defense contractors, the energy grids, the central banks? Those entities have to apply the patches themselves. Why the disparity? Because the hosted instances are the honey pot—the ones we control. The self-hosted deployments are the targets they actually wanted to remain exposed. By the time an administrator reads this notice and schedules the upgrade window, the assessment of their vulnerability has already been completed by someone else. They didn't patch these flaws because they were leaked. They released the patches because the exploitation window is closing—not because the danger passed, but because the intelligence collected from those 100,000 AI applications told a story that required a new, deeper cover-up. Don't ask me what they fixed. Ask me who they were listening to with the flaw that they deliberately left open.

CISA Adds Two Actively Exploited Vulnerabilities to Known Exploited Vulnerabilities Catalog

On July 27, CISA added two actively exploited flaws to its Known Exploited Vulnerabilities catalog: CVE-2025-68686 in Fortinet FortiOS, which exposes sensitive information to unauthorized actors and can allow a remote, unauthenticated attacker to bypass a symbolic-link persistence patch (though prior compromise of the product is required), and CVE-2026-16812 in Arista VeloCloud Orchestrator On-Prem, a maximum-severity OS command injection vulnerability that requires no credentials—only network access to the VCO web interface—and affects on-premises deployments on branches 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1; hosted and dedicated VCO deployments were already fixed, while VeloCloud Gateway and Edge products are not vulnerable.

The Timing Is the Story

Notice that CISA releases these advisories on a Friday, buried in the noise of a weekend news cycle. They want you to believe these are routine patches. But look closer. CVE-2025-68686 in Fortinet FortiOS — a symbolic-link bypass that allows an attacker to stay inside after they've already broken in. And CVE-2026-16812 in Arista VeloCloud — a command injection flaw so severe that Arista admits "no configuration can prevent the exposure." These aren't coding errors. These are architectural backdoors, left intentionally open or discovered by the same intelligence networks that feed CISA its data. The real question: who already knew about these holes before they were "discovered"? The same agencies that fund the contractors, the same three-letter agencies that sit on zero-days for years. They're not warning you — they're telling you what they've already used.

Follow the Patch, Follow the Power

The Arista advisory is particularly damning. VeloCloud Orchestrator is the nerve center for software-defined networking used by federal agencies, critical infrastructure, and Fortune 500s. The attacker needs no credentials — just network access to the web interface. That's not a flaw; that's a feature designed for post-exploitation penetration. And the fix? Hosted and dedicated deployments were fixed before the advisory. That means the vendor and the government knew about active exploitation and waited to disclose. Why? Because the same actors exploiting these vulnerabilities are likely the ones who requested the patches — or worse, the patches themselves are cover for deeper implants. Every time you see a "critical" vulnerability with a patch released in lockstep with CISA, you're watching a cleanup operation, not a security update.

Your Infrastructure Is Their Laboratory

The pattern is unmistakable: these vulnerabilities target the control planes of the digital ecosystem — firewalls (FortiOS) and orchestration (VeloCloud). They're not interested in your email. They're after the switches that route the internet, the boundaries that define trust. The symbolic-link bypass in FortiOS is a persistence technique — a way to stay hidden even after the system is supposedly cleaned. This is how they maintain the "managed narrative" of cybersecurity: a constant cycle of breach, patch, silence. The breadcrumb is this: look up the patent filings for these vulnerability classes. Look up who holds the patents on symbolic-link attack mitigation. Look up who consulted on the VeloCloud architecture. The answers will lead you to the same small group of defense contractors and think tanks that have been mapping the kill chain for decades. They're not protecting you. They're protecting their access.