Ubuntu snap-confine patch release (CVE-2026-8933)
Security Patch Release
Summary
Hide ▲
Show ▼
Canonical and the Ubuntu Security Team released patches for snapd/snap-confine to fix CVE-2026-8933, which can grant full root access on default Ubuntu Desktop 24.04, 25.10 and 26.04 installations.
Related Happenings
Linux kernel maintainers security patch release for CVE-2026-43503
Security Patch Release
H score34
First: 26.06.2026 14:51
Last: 26.06.2026 14:51
Sources 1
About this happening:
Linux kernel merged and shipped the DirtyClone security fix for CVE-2026-43503, closing a CVSS 8.8 local privilege-escalation path that could let affected systems...
Linux kernel maintainers security patch release for CVE-2026-43503
Security Patch ReleaseAbout this happening: Linux kernel merged and shipped the DirtyClone security fix for CVE-2026-43503, closing a CVSS 8.8 local privilege-escalation path that could let affected systems...
Dify security patch release for CVE-2026-41947
Security Patch Release
H score34
First: 22.06.2026 19:13
Last: 22.06.2026 19:13
Sources 1
About this happening:
Dify shipped version 1.14.2 to fix most of the DifyTap vulnerabilities, closing cross-tenant paths that could expose AI chats, uploaded files, and internal API...
Dify security patch release for CVE-2026-41947
Security Patch ReleaseAbout this happening: Dify shipped version 1.14.2 to fix most of the DifyTap vulnerabilities, closing cross-tenant paths that could expose AI chats, uploaded files, and internal API...
Linux kernel Dirty Frag patch release (CVE-2026-43284, CVE-2026-43500)
Security Patch Release
H score32
First: 11.05.2026 17:30
Last: 11.05.2026 17:30
Sources 1
About this happening:
Major Linux distributions are rolling out fixes for Dirty Frag, the Linux kernel patch release that covers CVE-2026-43284 and CVE-2026-43500. The update matter...
Linux kernel Dirty Frag patch release (CVE-2026-43284, CVE-2026-43500)
Security Patch ReleaseAbout this happening: Major Linux distributions are rolling out fixes for Dirty Frag, the Linux kernel patch release that covers CVE-2026-43284 and CVE-2026-43500. The update matter...
CISA KEV action for CVE-2026-31431 and FCEB remediation
Public Sector Action
H score37
First: 03.05.2026 09:26
Last: 03.05.2026 09:26
Sources 1
About this happening:
CISA added CVE-2026-31431 to its KEV catalog, putting Federal Civilian Executive Branch (FCEB) agencies on notice to remediate an actively exploited Linux privilege-es...
CISA KEV action for CVE-2026-31431 and FCEB remediation
Public Sector ActionAbout this happening: CISA added CVE-2026-31431 to its KEV catalog, putting Federal Civilian Executive Branch (FCEB) agencies on notice to remediate an actively exploited Linux privilege-es...
Linux distributions mitigation advisories for CVE-2026-31431
Advisory/Mitigation
H score39
First: 30.04.2026 12:24
Last: 30.04.2026 12:24
Sources 1
About this happening:
Multiple Linux distributions released advisories for CVE-2026-31431, adding mitigation guidance for a Linux kernel local privilege escalation that can let an unprivile...
Linux distributions mitigation advisories for CVE-2026-31431
Advisory/MitigationAbout this happening: Multiple Linux distributions released advisories for CVE-2026-31431, adding mitigation guidance for a Linux kernel local privilege escalation that can let an unprivile...
Timeline
-
22.07.2026 13:50 2 articles · 1h ago
Canonical releases snapd patches for CVE-2026-8933
Mitigation Patch UpdateCanonical released patches through the Ubuntu Security Team following coordinated disclosure, and administrators were urged to apply the latest snapd updates immediately to reduce the risk of local root compromise on default Ubuntu Desktop systems.
Show sources
- Ubuntu snap-confine Vulnerability Enables Local Root Access — www.infosecurity-magazine.com — 22.07.2026 13:50
- Ubuntu snap-confine Vulnerability Enables Local Root Access — www.infosecurity-magazine.com — 22.07.2026 13:50
-
21.07.2026 03:00 1 articles · 1d ago
Qualys discloses CVE-2026-8933 in Ubuntu snap-confine
Initial DisclosureQualys Threat Research Unit disclosed CVE-2026-8933 in snap-confine, the Ubuntu component that builds the execution environment for snap applications, and said the flaw can give full root access to any local user on default Ubuntu Desktop 24.04, 25.10 and 26.04 installations.
Show sources
- Ubuntu snap-confine Vulnerability Enables Local Root Access — www.infosecurity-magazine.com — 22.07.2026 13:50