FalconFlank is public, independently reproduced and unpatched; NVIDIA fixed the initrd parser, but older vulnerable boot images remain acceptable.
The complete exploit is public and independently reproduced, and no patch is available.
CrowdStrike Falcon Sensor deployments on Windows endpoints using the Microsoft Office suspicious-macro-removal prevention policy.
Local privilege escalation from a standard user to SYSTEM
The change is a working escalation through the endpoint-defense workflow trusted to remediate hostile Office content, not merely another local race.
With Microsoft Office File Suspicious Macro Removal enabled, an unprivileged user can use junction, oplock and transacted-file races to redirect Falcon's privileged filesystem work into the protected PowerShell bcrypt.dll path.
The MareBackup scheduled task later loads the substituted DLL as SYSTEM, and the payload's named pipe accepts commands.
CrowdStrike acknowledged the investigation and recommends disabling the implicated prevention policy while keeping its other protection enabled; no patch was available at cutoff.
NVIDIA removed eval and added field validation, but older vulnerable boot images remain acceptable.
NVIDIA Jetson Linux, the board-support package and boot stack for Jetson Xavier, Orin, and Thor embedded edge-AI systems.
Secure Boot bypass, pre-boot root execution and LUKS key disclosure
This leads despite niche reach because one demonstrated device-in-hand path defeats both signed-boot execution integrity and encrypted-root secrecy, while the update does not make older vulnerable images unbootable.
An attacker with the device can place a crafted cryptluks file on the plaintext boot partition and use Device Manager to feed its enc_dm_name value into eval inside the signed initrd.
That produces a root shell before disk unlock, from which the LUKS trusted application discloses the encrypted root filesystem's key.
The shipped parser change removes eval and validates the field, but the platform enforces no anti-rollback and continues accepting pre-fix images.
Assessment based on public material available through 2026-09-04.
VMware Workstation on Windows or Linux hosts and VMware Fusion on macOS, which run desktop virtual machines.
Crafted guest input reaches an integer overflow in VMXNET3 or a stack buffer overflow in HGFS, crossing Workstation or Fusion's guest boundary into host-side code execution.
Broadcom shipped fixes, and no researcher demonstration or public exploit was available by the cutoff.
PostgreSQL database servers on Windows, Linux and macOS, including installations using logical replication, backup or change-data-capture accounts.
The replication protocol accepted an unrestricted logical-decoding plugin path, allowing a non-superuser REPLICATION role to load a chosen library as the PostgreSQL operating-system account.
The attacker still needs a library-delivery route: Cyera demonstrated an SMB-hosted DLL on Windows, while NFS automounts or a separate file-write primitive can supply the path elsewhere.
Once loaded, the library can modify pg_authid and install persistent superuser access.
Fixed releases are available, but anti-rollback is not enforced and pre-fix images remain accepted.
Microsoft Entra Connect Health, the Microsoft-hosted monitoring service for on-premises Entra Connect Sync, AD FS, and AD DS agents.
Global Reader—and Security Reader for the demonstrated AD FS path—could invoke credentials/read, receive the live AgentKey and disconnect the legitimate agent when the read rotated that key.
The stolen key minted an agent bearer token and exposed write-capable Event Hub and Blob credentials for forged telemetry or monitoring disruption.
The report found no broader Graph, Key Vault, ARM or storage-read pivot, and remediation remained partial without complete revocation.
Jenkins, a Java-based automation and continuous-integration controller commonly entrusted with build credentials and artifact production.
A crafted config.xml can deserialize a nested PersistenceRoot object, expose its Stapler routes and reach the improperly protected Script Console in the controller process.
Jenkins published fixed releases, and no public exploit code was located by the cutoff.
libheif, a cross-platform HEIF/AVIF decoding library used by Linux applications, Android apps that bundle it, and server-side image pipelines.
In the uncompressed codec, mismatched Cb and Cr bit depths cause two-byte attacker-selected samples to overrun a one-byte chroma plane.
The researcher converted it into file disclosure and PHP execution only on an exact Debian and WordPress target that also required a valid Author account.
Portable execution across arbitrary consumers was not demonstrated; a patch exists but was not assessed for this brief.
F5 BIG-IP application-delivery and security appliances and BIG-IQ centralized management systems through their management interfaces.
An undisclosed TMUI request fails to enforce the caller's role, allowing even the lowest authenticated management role to mint a persistent administrator identity.
F5 published fixed versions, and no public exploit was identified by the cutoff.
SonicWall SMA1000 enterprise SSL-VPN gateways, including physical SMA 6210/7210 appliances and the SMA 8200v virtual appliance.
The first flaw lets an unauthenticated WorkPlace client proxy requests toward internal services, while the second injects commands through the administrator-only Appliance Management Console.
We do not know whether the proxy path can supply the administrator state needed for command injection, so the public record does not establish unauthenticated code execution.
SonicWall published fixes, but their implementation was not assessed for this brief.
AMD 7-Series FPGAs, programmable devices used in embedded systems; demonstrated on an XC7A200T Artix-7 and believed by AMD to apply to similarly configured 7-Series and Zynq-7000 devices.
With the chip in hand, backside die access and specialized optical equipment, researchers observed data after decryption as it crossed ICAP and recovered plaintext from an XC7A200T.
Broader 7-Series and Zynq-7000 applicability is stated only in principle, and no fix is available.
Public Docker Hub images published under Apache, GitLab, Okteto-related, SAP, and Toradex namespaces, with credentials authorizing access to external cloud services.
Unauthenticated image pulls exposed credentials for Apache GitHub, Okteto Terraform, Toradex Slack, GitLab CI and an OpenAI account; validation found administrative or write-capable access among the strongest cases.
BlueZ 5.87, the Linux Bluetooth userspace stack and its root-owned bluetoothd daemon.
After the victim actively connects, a response count of 255 writes 251 attacker-selected bytes beyond a four-byte stack array and feeds the same count toward a second oversized copy.
Researchers demonstrated the first overwrite over the air, but not instruction-pointer control on a hardened distribution build.
No patch was available by the cutoff.
GNOME Remote Desktop 51 pre-release Remote Login deployments on Linux distributions embedding FreeRDP 3.28 through 3.30.
A rejected negotiation continues into a disabled security mechanism, after which a heap disclosure supplies addresses for a controlled eight-byte overwrite of a live function-pointer-bearing object.
Researchers demonstrated pre-authentication execution, but the complete exploit was not published and the scope is limited to GNOME 51 pre-release Remote Login.
FreeRDP published fixes, but their implementation was not assessed for this brief.
libheif, a cross-platform HEIF/AVIF library, when used by tiled-image viewers, converters, thumbnailers, or server pipelines through its tile-decoding API.
A missed sibling branch wraps tile-offset arithmetic to zero and calls memcpy with an invalid pointer and a one-terabyte length; the public reproducer crashed three clean runs out of three.
Only denial of service is established, and the new patch was not assessed for this brief.
TP-Link Archer AX55 V4, an embedded Wi-Fi 6 home router.
Affected firmware combines a firmware-wide RSA-1024 private key with weakened AES session-key construction, allowing an observer of the HTTP management login to decrypt the password.
TP-Link fixed the affected Archer AX55 V4 firmware; no public researcher write-up or exploit was available by the cutoff.
TP-Link TL-MR100 V3.20, an embedded 4G LTE Wi-Fi router.
A crafted encrypted request to /cgi/login triggers a stack overflow before authentication and overwrites saved control-flow data.
Service termination is established, but code execution is not; TP-Link's published fix was not assessed for this brief.
TP-Link Archer AX55 V4, an embedded Wi-Fi 6 home router running an EasyMesh daemon.
When Mesh mode is enabled, unauthenticated LAN input reaches a stack-based overflow and terminates easymesh; code execution remains unproved.
TP-Link published fixed firmware, but its implementation was not assessed for this brief.
No additional findings today.
The Jetson boot chain and FPGA plaintext recovery changed physical-device capability; SMA1000 exploitation remained a pair of publicly unlinked primitives.
Physical possession now enables a practical Jetson root-and-key chain and laboratory-grade plaintext recovery from an encrypted AMD FPGA.
Canva transferred authenticated session authority to an external WebView origin, while libheif added one target-specific overwrite chain and one residual crash path.
The same brief, every morning. One email a day, nothing else.
fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.