Dell System Update (DSU) versions before 2.3.0.0 contain CVE-2026-86360, a critical path-traversal vulnerability that can enable unauthenticated attackers with remote access to execute arbitrary code with root privileges on unpatched PowerEdge servers. Dell also addressed CVE-2026-86361 and CVE-2026-86362, which could let low-privileged local attackers gain higher privileges through incorrect permissions or access controls.
Why it matters
Successful exploitation may provide filesystem access, complete compromise of the vulnerable application and underlying operating system, and full control of the affected server.
Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily
Exploitation · Helpnetsecurity
What happened
CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog; it is described as a memory overflow affecting Citrix NetScaler ADCs and Gateways. Citrix reported observing targeted attacks against unmitigated NetScaler deployments that can cause denial of service.
Why it matters
If the condition is triggered repeatedly, the NetScaler service may remain unavailable, according to Citrix.
Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily
Cloud · Theregister Security
What happened
Vercel CEO Guillermo Rauch said the company confirmed a KVM zero-day through its Sandbox bounty program, describing it as affecting Linux virtualization; public technical details were not yet available. The report identifies Vercel Sandbox as using Firecracker MicroVMs, which relies on Linux KVM; AWS created Firecracker.
Why it matters
The reported issue is characterized as a guest-to-host escape: a guest-VM operator could potentially take over the host and possibly control other guest VMs.
Known limitation: This item is supported by one source record and has not been independently corroborated here.
Evidence is visible. Uncertainty stays visible too.
Baitaphish separates source records from interpretations, labels AI-assisted enrichment, and avoids turning ingestion volume into unsupported claims about threats, prevalence, or risk.