Find notable cyber news and cases, enriched with sources, timelines, and signals.

Ubuntu snap-confine patch release (CVE-2026-8933)

Security Patch Release
First reported
Last updated
Happening score
H score 34
2 unique sources, 2 articles

Summary

Hide ▲

Canonical released snapd updates through the Ubuntu Security Team to fix CVE-2026-8933, a local privilege escalation in snap-confine that can let an unprivileged user obtain root access on default Ubuntu Desktop 24.04, 25.10, and 26.04 installations. Qualys Threat Research Unit disclosed the flaw on July 21 and described a race condition during sandbox initialization that can be chained to write malicious rules under /run/udev/rules.d/ and trigger systemd-udevd as root. Administrators were urged to verify the installed snapd version and apply the latest package updates immediately to reduce the risk of local root compromise on exposed desktop and endpoint systems.

Related Happenings

OpenWrt security patch release for CVE-2026-53921

Security Patch Release
H score37 First: 28.07.2026 15:56 Last: 28.07.2026 15:56 Sources 1

About this happening: OpenWrt released 24.10.8 and 25.12.5 to close a critical DHCPv6 stack overflow in odhcpd, reducing the risk of root code execution on exposed routers. The...

Linux kernel upstream security patch release for CVE-2026-53264

Security Patch Release
H score32 First: 28.07.2026 11:04 Last: 28.07.2026 11:04 Sources 1

About this happening: Linux kernel maintainers have backported CVE-2026-53264 fixes across stable branches, closing a local privilege-escalation path that can turn a local user into root on...

Linux kernel stable maintainers security patch release for CVE-2026-53359

Security Patch Release
H score41 First: 06.07.2026 20:37 Last: 06.07.2026 20:37 Sources 1

About this happening: The Linux kernel shipped stable fixes for CVE-2026-53359, closing a KVM use-after-free on x86 hosts with nested virtualization. The fix reached 7.1.3, 6.18.3...

Linux kernel maintainers security patch release for CVE-2026-43503

Security Patch Release
H score34 First: 26.06.2026 14:51 Last: 26.06.2026 14:51 Sources 1

About this happening: Linux kernel merged and shipped the DirtyClone security fix for CVE-2026-43503, closing a CVSS 8.8 local privilege-escalation path that could let affected systems...

Dify security patch release for CVE-2026-41947

Security Patch Release
H score34 First: 22.06.2026 19:13 Last: 22.06.2026 19:13 Sources 1

About this happening: Dify shipped version 1.14.2 to fix most of the DifyTap vulnerabilities, closing cross-tenant paths that could expose AI chats, uploaded files, and internal API...

Timeline

  1. 22.07.2026 13:50 3 articles · 13d ago

    Canonical releases snapd patches for CVE-2026-8933

    Mitigation Patch Update

    Canonical released patches through the Ubuntu Security Team following coordinated disclosure, and administrators were urged to apply the latest snapd updates immediately to reduce the risk of local root compromise on default Ubuntu Desktop systems.

    Show sources
  2. 21.07.2026 03:00 1 articles · 15d ago

    Qualys discloses CVE-2026-8933 in Ubuntu snap-confine

    Initial Disclosure

    Qualys Threat Research Unit disclosed CVE-2026-8933 in snap-confine, the Ubuntu component that builds the execution environment for snap applications, and said the flaw can give full root access to any local user on default Ubuntu Desktop 24.04, 25.10 and 26.04 installations.

    Show sources