CrackArmor: Critical AppArmor Flaws Enable Local Privilege Escalation to Root

2026-03-14T08:51:53Z3d4b6b284aa7c63a46a5aab6ab6f0d829d6db00daff759af91f3ccd224180e7e
AI governanceActive DirectoryAppArmorCNAPPCrackArmorCyber Essentials PlusLPEMicrosoft Patch TuesdayPass-the-HashPass-the-TicketQualys TRUWindowscloud compromisecontainer escapecredential misusekernellocal privilege escalationpatch reliabilitypatchingvulnerability management

What happened

Qualys TRU disclosed “CrackArmor,” a set of confused-deputy AppArmor flaws that allow unprivileged users to bypass kernel protections, achieve local privilege escalation to root, and break container isolation. The vulnerabilities date back to 2017 and reportedly affect >12.6 million systems; Qualys recommends immediate kernel patching. The feed also highlights Microsoft’s March 2026 Patch Tuesday (93 fixes, including 8 critical), February updates, and broader Qualys analysis on cloud compromise via credential misuse, Active Directory attack techniques (PtH/PtT), AI governance risks, patch-reli

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
qualys_blog
Record identifier
3d4b6b284aa7c63a46a5aab6ab6f0d829d6db00daff759af91f3ccd224180e7e
Enrichment time
2026-03-14T08:51:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.