Dirty Frag: A new Linux privilege escalation vulnerability is already in the wild
2026-05-08T14:51:48Z•6831283e5a3c06d3e72c1e37ca48353af0542a719d2161c65e3cfc9173903306
CISA KEVCVE-2026-0300CVE-2026-20034CVE-2026-20035CVE-2026-6973CiscoDirty FragEPMMIvantiMiraiMuddyWaterPAN-OSPalo AltoSSRFbotnetcode executionespionageexploitationkernel vulnerabilitylinuxprivilege escalationransomwarexlabs_v1zero-day
What happened
Multiple high‑risk vulnerabilities and active campaigns reported: a newly disclosed Linux kernel privilege‑escalation dubbed “Dirty Frag” has a public working exploit enabling local unprivileged users to gain root on major distributions (Ubuntu, RHEL, Fedora) and remains unpatched; Palo Alto PAN‑OS zero‑day (CVE‑2026‑0300, CVSS 9.3) is being actively exploited by suspected nation‑state actors to gain root and deploy tunneling tools; CISA added PAN‑OS CVE‑2026‑0300 and Ivanti EPMM CVE‑2026‑6973 (CVSS 7.1) to its Known Exploited Vulnerabilities catalog; Cisco patched multiple high‑severity flaws
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 6831283e5a3c06d3e72c1e37ca48353af0542a719d2161c65e3cfc9173903306
- Enrichment time
- 2026-05-08T14:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.