CVE Tools

В фокусе RVD: трендовые уязвимости июня

Хабр — Информационная безопасностьBy sea-team

Rounduplinux kernelpan-os

Our summary

In June, R-Vision highlighted 4 high-impact “trending” vulnerabilities: CVE-2026-43500 and CVE-2026-43284 in Linux (Dirty Frag) enabling local root privilege escalation via page cache manipulation, and affecting common distributions such as Ubuntu, Debian, and RHEL. It also covered CVE-2026-0257 in Palo Alto Networks PAN-OS GlobalProtect, where an Authentication Override configuration flaw can allow attackers to forge VPN cookies and bypass authentication/MFA, with CVE-2026-0257 listed in CISA KEV. Finally, CVE-2026-44815 in Windows DHCP Client can be triggered remotely by a malicious DHCP response to achieve SYSTEM-level arbitrary code execution, making timely patching critical.

Read at Хабр — Информационная безопасность

Хабр — Информационная безопасность publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store