CVE-2026-16526
A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to
CVSS
8.8
Alto
EPSS
0.5%
p38
KEV
—
Exploit Today
11
0-100
Publicado: 30 jul 2026 · Última mod.: 21 ago 2026 · CWE-403
0.5%EPSS · 30 días0.8%
2026-07-312026-08-27
A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:55560
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:55617
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:55740
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-16526
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2506026
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-332634.3 MED—
———When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with epoll() panic caused by file descriptor handling issues. If running in high-security mode (default for community releases), only the new submission connection gets terminated. If running in high-performance mode (default for Pro releases), all connections handled by the submission-login process will be terminated. The crashes can cause failure for user to send a message, or it can cause duplicate messages to be sent. If TLS is not used (in the backend server processing the submission), duplicate deliveries cannot happen, because the crash can only happen at AUTH stage. Limit the number of connections handled by single submission-login process. This has a performance impact though. Update to non-vulnerable version. No publicly available exploits are known.12hCVE-2026-122969.6 CRÍ32.2%
——10Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.45dCVE-2024-216268.6 ALT97.0%
——29runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.5d