Dirty Frag: A new Linux privilege escalation vulnerability is already in the wild

2026-05-08T14:51:48Z6831283e5a3c06d3e72c1e37ca48353af0542a719d2161c65e3cfc9173903306
CISA KEVCVE-2026-0300CVE-2026-20034CVE-2026-20035CVE-2026-6973CiscoDirty FragEPMMIvantiMiraiMuddyWaterPAN-OSPalo AltoSSRFbotnetcode executionespionageexploitationkernel vulnerabilitylinuxprivilege escalationransomwarexlabs_v1zero-day

What happened

Multiple high‑risk vulnerabilities and active campaigns reported: a newly disclosed Linux kernel privilege‑escalation dubbed “Dirty Frag” has a public working exploit enabling local unprivileged users to gain root on major distributions (Ubuntu, RHEL, Fedora) and remains unpatched; Palo Alto PAN‑OS zero‑day (CVE‑2026‑0300, CVSS 9.3) is being actively exploited by suspected nation‑state actors to gain root and deploy tunneling tools; CISA added PAN‑OS CVE‑2026‑0300 and Ivanti EPMM CVE‑2026‑6973 (CVSS 7.1) to its Known Exploited Vulnerabilities catalog; Cisco patched multiple high‑severity flaws

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
6831283e5a3c06d3e72c1e37ca48353af0542a719d2161c65e3cfc9173903306
Enrichment time
2026-05-08T14:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.