Cisco also reports exploitation of unauthenticated paths that can end in root on Secure Email Gateway and ISE.
Four target-specific chains start from an ordinary local account.
Linux kernel networking subsystems AH6/XFRM, TUN/TAP with Open vSwitch, PPPoE, and SCTP diagnostics across supported and historical kernel series.
Local root through four feature-dependent kernel-memory corruption chains
This is not identifier churn: public grooming and end-to-end chains now convert four feature-dependent corruptions into root from an ordinary account.
DirtyAH6, TUNderflow and PPPoEject use unprivileged user and network namespaces; DiagSpill instead needs SCTP and sctp_diag.
The chains redirect the corruptions through file-backed pages, an fdtable or callback, or page tables, then install credentials, a PAM rule or a sudoers entry and open a root shell. The report maps each flaw to fixed stable releases.
The revocation answer means no revocation is required by this source-code fix. The EOL answer is scoped to upstream stable releases; downstream vendor backports were not established.
The destination sees the device's real source address and packet timing.
Android phones whose framework and Wi-Fi firmware expose unprivileged NAT-T keepalive offload, including a demonstrated Pixel 8 Pro running Android 16.
VPN-lockdown bypass for real network-identity and activity-timing disclosure
The change is a demonstrated escape from an explicit operating-system guarantee through public APIs available to an ordinary app.
With Always-on VPN and Block connections without VPN enabled, an app can request a NAT-T socket keepalive. Android passes it to Wi-Fi hardware offload without applying the caller UID's effective lockdown policy.
Researchers captured the resulting UDP/4500 traffic outside the tunnel on a Pixel 8 Pro. Samsung and Nothing devices exposed compatible active offload slots, but we do not yet know the full affected-device population.
No management access or recipient action is required.
Cisco Secure Email Gateway, physical and virtual email-security appliances running AsyncOS.
Unauthenticated root command execution through email delivery
The gateway processes the hostile object itself, and Cisco reports exploitation of the message-to-database-to-root path.
Insufficient parser validation lets crafted SQL reach the appliance database; PostgreSQL program execution then reaches operating-system commands running as root.
Cisco reports exploitation and has published fixed AsyncOS releases. Pre-fix images remain accepted.
Cisco’s x90 hardware notice places the last date of support and vulnerability/security support at September 30, 2025.
The path needs management-plane reachability but no credentials or user interaction.
Cisco Identity Services Engine and ISE Passive Identity Connector, network-access-control systems deployed as appliances or virtual machines.
Unauthenticated root command execution on a network-access-control appliance
Observed exploitation turns the management-plane authentication failure into a current root risk, although the interface must be reachable.
A crafted unauthenticated API request bypasses the web management interface; Cisco says successful exploitation may then produce root command execution.
Cisco and the Canadian Cyber Centre identify fixed releases, and both record the exploitation.
iOS and iPadOS, Apple's operating systems for supported iPhones and iPads.
Apple fixed the race, but the disclosed record stops at the sandbox-to-kernel primitive and supplies no public exploit. Pre-fix images remain accepted.
Apple operating systems on supported iPhone, iPad, Mac, Apple TV, Apple Watch, and Vision Pro devices.
Apple identifies an out-of-bounds write and has shipped fixes across eight operating-system families.
We do not know the Bluetooth profile, radio mode, pairing requirement or resulting execution context.
macOS on supported Apple-silicon Mac computers.
The path starts from a local app on a supported Apple-silicon Mac. Apple added entitlement checks, but has not identified the entitlement, API, service or invocation sequence, and pre-fix images remain accepted.
WordPress, a web content-management system, chained with the Mobile Repair Zone catalog theme or another theme exposing a comparable pre-activation installer.
A logged-in administrator must open a crafted theme-preview URL, but the attacker needs no WordPress account and the selector injection triggers installation without an Install or Activate click.
The demonstrated theme then exposes an unauthenticated package installer that fetches an attacker-selected plugin and executes its PHP. WordPress has fixed the forced install-and-preview issue.
Intel TDX, hardware-isolated confidential virtual machines on Xeon cloud servers.
With the interposer installed and the host or hypervisor under attacker control, suppressed DDR5 writes leave prepared stale ciphertext that TDX accepts.
Researchers used the primitive to change a trust domain's debug state, access plaintext and replace a launch measurement; the hardware designs and attack code are public.
AMD SEV-SNP, encrypted confidential virtual machines on DDR5 EPYC servers.
The interposer and privileged host control let an attacker reintroduce stale encrypted page contents; known plaintext can turn that into changes to victim data or code pages.
AMD lists affected processor families but plans no CVE or mitigation because it excludes physical memory-bus attacks from its threat model.
Synology DiskStation Manager, the embedded operating system and management environment for Synology NAS appliances.
The attacker must reach the affected SCGI or login path, but we do not know its default exposure, service privilege, writable paths or whether file write composes into execution.
Synology provides fixed current branches, but affected end-of-life hardware is outside their reach.
Supported Google Pixel phones and tablets running Android with Google device firmware below the September 2026 patch level.
The path needs adjacent or proximal network reach and an unspecified low-privilege prerequisite, but no device-owner interaction; a modem logic error then bypasses permission checks.
We do not know the radio transaction, affected models, prerequisite privilege or destination privilege.
Supported Google Pixel phones and their cellular-modem software.
A crafted modem input triggers a heap-buffer overflow and out-of-bounds write, but the required low-privilege network role and affected modem families are not public.
The September 2026 Pixel patch level addresses the vulnerability.
Unbound, a cross-platform recursive and caching DNS resolver commonly deployed on Linux and network infrastructure.
After the attacker induces a query to a controlled zone, a self-referential compression pointer makes DNSSEC validation write beyond the allocated buffer.
Resolver-process code execution remains unproved. NLnet Labs identifies a fixed release, but the fix was not read for a Priority Finding.
Check Point Security Management, Multi-Domain Security Management, Log, and Multi-Domain Log Servers controlling and recording security infrastructure.
The reported overlong-username trigger reaches a stack overflow in the login process; Trusted Clients restrictions can narrow which source hosts reach it.
Check Point provides fixed releases and LivePatch, but the fix was not read for a Priority Finding.
Acronis Backup integrations for cPanel/WHM, Plesk and DirectAdmin on Linux hosting servers.
A low-privilege user on an affected hosting server can alter a file or path later consumed by the privileged backup service.
Acronis identifies fixed releases, but the fix was not read for a Priority Finding.
TP-Link Tapo C120 and C200, Wi-Fi-connected home and small-business security cameras running embedded firmware.
A LAN peer needs only HTTPS reachability, not an existing session; the resulting token reaches configuration, live streams and stored recordings.
TP-Link identifies fixed firmware, but the fix was not read for a Priority Finding.
FFmpeg, a cross-platform multimedia decoding and processing library used by media applications and services.
An affected consumer must decode the bitstream; missing entry-point bounds enforcement then produces an out-of-bounds CTU-index write.
Code-execution control and an automatic remote delivery path remain unproved. The fix reached master and release/9.0, but it was not read for a Priority Finding.
TOTOLINK A3002MU, a dual-band home and small-office Wi-Fi router running embedded Linux firmware.
A fail-open session check exposes the Boa handlers; formWsc then passes shell-bearing peerPin input to system() as root.
Public exploit code is available and no patch was identified, but the path is confined to LAN reachability on one obscure router.
Raspberry Pi RP2350 A4, a dual-core microcontroller used in embedded devices.
The path requires possession, destructive backside decapsulation, SWD access and laboratory-grade photon-emission and laser-fault equipment.
Researchers nevertheless restored the Secure debugger and recovered the vendor-challenge 128-bit secret from OTP.
No additional findings today.
DDRop's low-cost interposer breaks TDX and SEV-SNP freshness assumptions; no separate bootloader change was established.
The same brief, every morning. One email a day, nothing else.
fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.