CVE
CVE-2026-46331
net/sched: fix pedit partial COW leading to page cache corruption
MITRE ATT&CK TTPs 5
Source Articles
Exploits and vulnerabilities in Q2 2026
In Q2 2026, a significant increase in registered vulnerabilities was observed, driven by AI-assisted discovery tools. Multiple critical vulnerabilities were exploited in both Windows and Linux systems, including local privilege escalation flaws in the Linux kernel's caching subsystem (e.g., Dirty Frag family) and newly disclosed Windows Defender and BitLocker bypass vulnerabilities. Exploitation of AI/LLM platforms such as OpenClaw, Dify, and Open WebUI surged, with vulnerabilities enabling session compromise, unauthorized access, and message manipulation. APT groups increasingly targeted newly published and zero-day vulnerabilities, using C2 frameworks like Sliver and Metasploit for post-exploitation. The report highlights growing risks from insecure AI tooling and the need for enhanced access controls and real-time monitoring.
securelist Aug 26, 2026
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
A sandbox escape vulnerability named SharedRoot has been discovered in Anthropic's Claude Cowork, allowing an AI agent to break out of its Linux VM and access arbitrary files on the host macOS system. The flaw stems from the entire host filesystem being mounted read-write into the VM, enabling privilege escalation via exploitation of CVE-2026-46331 (pedit COW) in the guest kernel. Although Anthropic has not issued a direct fix, the latest version defaults to cloud execution, mitigating the risk for most users, but local execution remains vulnerable.
hacker-news Jul 23, 2026