Find notable cyber news and cases, enriched with sources, timelines, and signals.

Ubuntu snap-confine local privilege escalation (CVE-2026-8933)

Vulnerability
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-8933 exposes default Ubuntu Desktop 24.04, 25.10 and 26.04 installs to local root escalation through snap-confine, letting an unprivileged user gain full host control. Canonical has released snapd updates through the Ubuntu Security Team, and administrators should verify the fix is installed. A published PoC shows the flaw can be driven through a race condition during sandbox setup.

Related Happenings

CISA KEV action for CVE-2026-31431 and FCEB remediation

Public Sector Action
H score37 First: 03.05.2026 09:26 Last: 03.05.2026 09:26 Sources 1

About this happening: CISA added CVE-2026-31431 to its KEV catalog, putting Federal Civilian Executive Branch (FCEB) agencies on notice to remediate an actively exploited Linux privilege-es...

Linux distributions mitigation advisories for CVE-2026-31431

Advisory/Mitigation
H score39 First: 30.04.2026 12:24 Last: 30.04.2026 12:24 Sources 1

About this happening: Multiple Linux distributions released advisories for CVE-2026-31431, adding mitigation guidance for a Linux kernel local privilege escalation that can let an unprivile...

Linux kernel AppArmor confused deputy vulnerabilities CrackArmor security flaw

Vulnerability
H score56 First: 13.03.2026 10:18 Last: 13.03.2026 10:18 Sources 1

About this happening: Researchers disclosed CrackArmor, nine confused deputy flaws in the Linux kernel's AppArmor module that can let unprivileged users bypass protections, gain root*...

Timeline

  1. 22.07.2026 13:50 2 articles · 1h ago

    Qualys discloses CVE-2026-8933 root escalation in Ubuntu snap-confine

    Initial Disclosure

    Qualys Threat Research Unit disclosed CVE-2026-8933 in snap-confine, the Ubuntu component that builds the execution environment for snap applications, and said it can give full root access to any local user on default Ubuntu Desktop 24.04, 25.10 and 26.04 installations. Canonical later released patches through the Ubuntu Security Team following coordinated disclosure, and administrators were urged to apply the latest snapd updates immediately.

    Show sources