local privilege escalation

Winsage
September 10, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) catalog, adding critical vulnerabilities that need immediate attention. 1. CVE-2026-75650: A vulnerability in Adobe Commerce and Magento with a CVSS score of 10.0, allowing unauthenticated remote code execution. Affected versions include Magento Open Source releases 2.4.7, 2.4.8, and 2.4.9. It has been actively exploited since September 4. 2. CVE-2026-81963: A Microsoft Windows vulnerability with a CVSS score of 7.8, related to a link-following issue within the Update Stack, allowing local attackers to escalate privileges. It is currently being exploited. 3. CVE-2026-85880: Another Microsoft Windows vulnerability rated at 7.8, involving a heap-based buffer overflow in the ALPC component, permitting local privilege escalation. This flaw is also actively exploited. 4. CVE-2026-86218: A N-able N-central vulnerability with a CVSS score of 10.0, allowing pre-authenticated remote code execution. N-able has released an emergency hotfix for this issue. Federal agencies must address these vulnerabilities by specified deadlines: Windows flaws by September 22 and other vulnerabilities by September 11, 2026, in accordance with Binding Operational Directive (BOD) 22-01. Private organizations are advised to review the KEV catalog and take necessary actions to strengthen their infrastructure against these vulnerabilities.
Winsage
September 10, 2026
Microsoft's Patch Tuesday on September 8, 2026, addressed two critical Windows privilege escalation vulnerabilities: CVE-2026-85880 and CVE-2026-81963, both with a CVSS score of 7.8. CVE-2026-85880 is a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC), allowing attackers with low-privilege local access to escalate privileges to SYSTEM. CVE-2026-81963 involves improper link resolution in the Windows Update Stack, enabling similar privilege escalation. Both vulnerabilities require no user interaction and have been actively exploited prior to the patch release. CISA added them to its Known Exploited Vulnerabilities catalog on September 8, 2026, with a remediation deadline of September 22 for U.S. federal agencies. CVE-2026-85880 affects various Windows 10 and Server versions but excludes Windows 11 and Windows Server 2025. CVE-2026-81963 impacts newer Windows platforms, including Windows 11 and Windows Server 2025. Microsoft released security updates for both vulnerabilities on September 8, 2026, and organizations are advised to prioritize these updates. Security teams should monitor for signs of privilege escalation and unusual SYSTEM-level activities related to these vulnerabilities.
Winsage
September 9, 2026
Recent investigations have identified the BlueMoon exploit kit, used by espionage-driven threat activity clusters, particularly linked to APT31, a China-aligned state-sponsored group, since August 28, 2026. BlueMoon exploits three vulnerabilities: CVE-2026-85046 (a type confusion vulnerability in Google Chrome's V8 engine), an unassigned V8 sandbox escape, and CVE-2026-85880 (a heap-based buffer overflow in Windows ALPC). Google and Microsoft have released patches for these vulnerabilities, which were exploited as "patch-gap" zero-days. The attack vectors typically begin with phishing emails that lead victims to malicious URLs, triggering the vulnerabilities for code execution and privilege escalation. Variants of BlueMoon have been detected, featuring modifications for specific campaigns. Notable attack chains include: - APT31 targeting NGOs and mining firms in the U.S. with a malicious browser add-on called GemStone. - UNK_LateNight targeting U.S. aerospace companies, deploying BlueMoon alongside the ShadowPad backdoor. - UNK_DoubleCheck targeting a Vietnamese manufacturer, using DLL sideloading to execute a Rust binary. - UNK_QuietRacket targeting government and financial organizations in Indonesia and Singapore, modifying BlueMoon to execute a .NET assembly. CISA added the Chrome flaw to its Known Exploited Vulnerabilities catalog on September 4, 2026, requiring federal agencies to apply patches by September 18, 2026. Indicators of compromise include specific process trees, files, folders, scheduled tasks, mutexes, and registry keys. Proofpoint has released detection rules to help organizations identify and mitigate these threats.
Winsage
August 13, 2026
Nightmare Eclipse has released a new zero-day exploit called ShieldBreak, which can bypass Microsoft's RoguePlanet patch (CVE-2026-50656) and allow attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. The exploit has been confirmed by security expert Kevin Beaumont, who provided detection methods for it. ShieldBreak is the tenth zero-day from Nightmare Eclipse since April and was released shortly after Microsoft's monthly Patch Tuesday. The exploit allows local privilege escalation and has a 100% success rate on the latest version of Windows 11 and Windows Server 2025, while Windows 10 remains vulnerable. Microsoft is aware of the vulnerability and is investigating it, emphasizing the importance of coordinated vulnerability disclosure. Previous exploits from Nightmare Eclipse include LegacyHive and GreatXML, with earlier vulnerabilities having been patched but recent ones still unaddressed. Microsoft had threatened legal action against Nightmare Eclipse in May but later reconsidered its approach to vulnerability disclosure.
Winsage
August 12, 2026
Microsoft's August Patch Tuesday update addressed 421 vulnerabilities across various products, including multiple versions of Windows (11 25H2/24H2, 11 23H2, and 10). A critical zero-day flaw, the "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability," allows attackers with lower-level access to gain system privileges without user interaction. Additionally, the update addresses two other zero-day flaws, including the "Windows User Profile Service Elevation of Privilege Vulnerability," which has not yet been exploited but was publicly disclosed. The update is mandatory and should automatically install on supported PCs, with users encouraged to verify its application. The update also includes minor improvements to Windows features, such as enhancements to File Explorer, Windows Hello, Voice Access, and touchpad controls.
Search