CVE-2018-14634Active Exploitation(canonical / big-ip_access_policy_manager)

HIGHCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch canonical big-ip_access_policy_manager systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable.

7.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-02-16. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-190

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • big-ip_access_policy_manager
  • big-ip_advanced_firewall_manager
  • big-ip_analytics
  • big-ip_application_acceleration_manager

Threat summary

  • Active exploitation appears in 7 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 8 observed days

What's happening

  • Active exploitation reported across 7 signals
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • Disclo: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-02-03); latest day: 1
  • 9 total mentions across 8 days

Affected systems

Products
big-ip_access_policy_managerbig-ip_advanced_firewall_managerbig-ip_analyticsbig-ip_application_acceleration_managerbig-ip_application_security_managerbig-ip_domain_name_systembig-ip_edge_gatewaybig-ip_fraud_protection_servicebig-ip_global_traffic_managerbig-ip_link_controller

14 versions affected across 28 products

Deep dive

Activity timeline9 mentions / 8d
01122Mentions · 2026-01-28: 1Mentions · 2026-01-29: 1Mentions · 2026-02-02: 1Mentions · 2026-02-03: 2Mentions · 2026-02-04: 1Mentions · 2026-02-13: 1Mentions · 2026-02-25: 1Mentions · 2026-03-10: 1Exploit Tool / Code · 2026-02-25: 1Active Exploitation · 2026-01-28: 1Active Exploitation · 2026-01-29: 1Active Exploitation · 2026-02-02: 1Active Exploitation · 2026-02-03: 1Active Exploitation · 2026-02-04: 1Active Exploitation · 2026-02-25: 1Active Exploitation · 2026-03-10: 1Patch / Workaround · 2026-01-28: 1Patch / Workaround · 2026-01-29: 1Patch / Workaround · 2026-02-03: 1Patch / Workaround · 2026-02-13: 1Technical Details · 2026-01-28: 1Technical Details · 2026-01-29: 1Technical Details · 2026-02-03: 2Technical Details · 2026-02-04: 1Technical Details · 2026-02-13: 1Technical Details · 2026-02-25: 101-2801-2902-0202-0302-0402-1302-2503-10
Signal classification3 categories
Active Exploitation
666.7%
Patch
222.2%
Disclo
111.1%
Referenced assets32 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-281
Patch1
2026-01-291
Active Exploitation1
2026-02-021
Active Exploitation1
2026-02-032
Active Exploitation1Disclo1
2026-02-041
Active Exploitation1
2026-02-131
Patch1
2026-02-251
Active Exploitation1
2026-03-101
Active Exploitation1
Full discourse9 posts
  • DIN⏳@din_lol_
    Patch

    The CISA has set a deadline of Feb 16 (Monday!) to patch a critical Linux Kernel vulnerability (CVE-2018-14634). Why does this matter for AI? Because 99% of AI infrastructure runs on Linux.From local agents like OpenClaw to massive training clusters, the physical infrastructure is vulnerable to privilege escalation. Stop trusting the machine. Trust the math.DIN’s decentralized architecture means we don't rely on a single central server that can be rooted. Our data validation happens on-chain, cryptographically secured against infrastructure failure. Secure your data supply chain before the weekend starts. 🛡️💻 Source: https://thehackernews.com/2026/01/threatsday-bulletin-new-rces-darknet.html #InfoSec #Linux #CyberSecurity #DIN #Web3 #PatchTuesday

    Post summary

    CISA has set a patch deadline for CVE‑2018‑14634, a privilege‑escalation bug in the Linux kernel, urging timely updates to protect AI infrastructure.

    00060723
    307.4K followersView on X
  • Shah Sheikh@shah_sheikh
    Active Exploitation

    Mutagen Astronomy: From Discovery to CISA Recognition—A Seven-Year Journey: Introduction On January 26, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2018-14634 to its Known Exploited Vulnerabilities (KEV) catalog. The same… https://blog.qualys.com/vulnerabilities-threat-research/2026/02/02/mutagen-astronomy-discovery-to-kev?utm_source=dlvr.it&utm_medium=twitter https://t.co/KRdO96gbjD

    Post summary

    CISA identified CVE‑2018‑14634 as a known exploited vulnerability, indicating that it is being abused in the wild.

    0100070
    2.2K followersView on X
  • Ostorlab@OstorlabSec
    Patch

    CVE-2018-14634 : MUTAGEN ASTRONOMY LPE ALERT @Linux  A critical Local Privilege Escalation (LPE) vulnerability has been identified in the Linux Kernel, allowing any unprivileged local user to gain complete root access via integer overflow in the ELF binary loader. Risk Severity: Critical (Public exploits available, listed in CISA KEV, active exploitation in multi-tenant environments) Impact:  Immediate elevation to Root privileges Full system compromise & container escape Bypass of user-space security controls (SELinux/AppArmor) Installation of persistent kernel-level rootkits Lateral movement from compromised low-privileged accounts Root Cause:  CWE-190 (Integer Overflow or Wraparound). The create_elf_tables() function in fs/binfmt_elf.c fails to correctly calculate stack size when handling massive environment variables. This overflow leads to memory corruption, overwriting the auxiliary vector and SUID execution paths. Attackers can:  Execute SUID-root binaries with crafted environment variables (approx 2^31 entries) Trigger stack overflow to overwrite execution flow Escalate from standard user to Root instantly Bypass sandboxing and container isolation Establish persistence deep within the kernel Are You Affected?  Vulnerable: Linux kernels 2.6.x, 3.10.x, and 4.14.x Scope: RHEL/CentOS 7, Ubuntu 16.04/18.04, Debian 9, and legacy enterprise infrastructure. Immediate Action Required:  Update: Upgrade to kernel 4.15+, or apply distro-specific security patches (e.g., RHEL 3.10.0-957.27.2.el7) Mitigation: Restrict stack size and process limits via /etc/security/limits.conf Audit: Monitor logs for SUID binary execution with abnormal environment variable counts (envc > 1000) Don't let a low-level shell become a root disaster. Patch your kernels now.🛡️ #linux #security #ostorlabCVE

    Post summary

    The advisory reports that CVE-2018‑14634, a critical LPE flaw in the Linux kernel, is actively exploited in the wild, and it provides detailed patch and mitigation instructions for affected systems.

    0001083
    581 followersView on X
  • B2B Cyber Security.de@B2bCyber
    Active Exploitation

    CISA nimmt nach 7 Jahren ausgenutzte Schwachstelle in KEV auf https://ift.tt/PVCYiS0 Am 26. Januar 2026 war es endlich soweit: Obwohl die Qualys-Experten seit 2018 auf die Schwachstelle CVE-2018-14634 in Red Hat Enterprise Linux und CentO immer wieder hingewiesen haben, land…

    Post summary

    CISA has added CVE-2018-14634 to the KEV after seven years of exploitation, underscoring its continued risk against Red Hat Enterprise Linux and CentOS.

    0000035
    1.7K followersView on X
  • RST Cloud@rst_cloud
    Active Exploitation

    #threatreport #MediumCompleteness January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day | 24-02-2026 Source: https://www.recordedfuture.com/blog/january-2026-cve-landscape Key details below ↓ 🧑‍💻Actors/Campaigns: Fancy_bear Neusploit 💀Threats: Nuclei_tool, Minidoor, Pixynetloader, Covenant_c2_tool, Grunt, Com_hijacking_technique, Supply_chain_technique, 🎯Victims: Enterprise communication platforms, Enterprise management platforms, Government users, Business users, Wordpress sites, Email systems 🏭Industry: Government 🌐Geo: Russian 🔓CVEs: CVE-2026-23760 \[[Vulners](https://vulners.com/cve/CVE-2026-23760)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - smartertools smartermail (<100.0.9511) CVE-2025-34026 \[[Vulners](https://vulners.com/cve/CVE-2025-34026)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - versa-networks concerto (<12.1.2, 12.2.0) CVE-2009-0556 \[[Vulners](https://vulners.com/cve/CVE-2009-0556)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - microsoft office_powerpoint (2004) - microsoft powerpoint (2000, 2002, 2003) CVE-2025-8110 \[[Vulners](https://vulners.com/cve/CVE-2025-8110)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - gogs (le0.13.3) CVE-2026-24423 \[[Vulners](https://vulners.com/cve/CVE-2026-24423)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - smartertools smartermail (<100.0.9511) CVE-2025-68645 \[[Vulners](https://vulners.com/cve/CVE-2025-68645)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - synacor zimbra_collaboration_suite (<10.0.18, <10.1.13) CVE-2018-14634 \[[Vulners](https://vulners.com/cve/CVE-2018-14634)] - CVSS V3.1: *7.8*, - Vulners: Exploitation: True Soft: - paloaltonetworks pan-os (<7.1.23, <8.0.16, <8.1.7) CVE-2026-21509 \[[Vulners](https://vulners.com/cve/CVE-2026-21509)] - CVSS V3.1: *7.8*, - Vulners: Exploitation: True Soft: - microsoft 365_apps (-) - microsoft office (2016, 2019) - microsoft office_long_term_servicing_channel (2021, 2024) CVE-2025-37164 \[[Vulners](https://vulners.com/cve/CVE-2025-37164)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: True Soft: - hpe oneview (le10.20.00) CVE-2026-1340 \[[Vulners](https://vulners.com/cve/CVE-2026-1340)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - ivanti endpoint_manager_mobile (le12.7.0.0) CVE-2026-1281 \[[Vulners](https://vulners.com/cve/CVE-2026-1281)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - ivanti endpoint_manager_mobile (le12.5.0.0, 12.5.1.0, 12.6.0.0, 12.6.1.0, 12.7.0.0) CVE-2026-20045 \[[Vulners](https://vulners.com/cve/CVE-2026-20045)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - cisco unified_communications_manager (<14su5, le15su3a) - cisco unified_communications_manager_im_and_presence_service (<14su5, le15su3a) - cisco unity_connection (<14su5, le15su3) CVE-2026-20931 \[[Vulners](https://vulners.com/cve/CVE-2026-20931)] - CVSS V3.1: *8.0*, - Vulners: Exploitation: Unknown Soft: - microsoft windows_10_1607 (<10.0.14393.8783) - microsoft windows_10_1809 (<10.0.17763.8276) - microsoft windows_10_21h2 (<10.0.19044.6809) - microsoft windows_10_22h2 (<10.0.19045.6809) ... CVE-2026-20805 \[[Vulners](https://vulners.com/cve/CVE-2026-20805)] - CVSS V3.1: *5.5*, - Vulners: Exploitation: True Soft: - microsoft windows_10_1607 (<10.0.14393.8783) - microsoft windows_10_1809 (<10.0.17763.8276) - microsoft windows_10_21h2 (<10.0.19044.6809) - microsoft windows_10_22h2 (<10.0.19045.6809) ... CVE-2025-52691 \[[Vulners](https://vulners.com/cve/CVE-2025-52691)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: True Soft: - smartertools smartermail (<100.0.9413) CVE-2025-31125 \[[Vulners](https://vulners.com/cve/CVE-2025-31125)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - vitejs vite (<4.5.11, <5.4.16, <6.0.13, <6.1.3, <6.2.4) CVE-2026-24858 \[[Vulners](https://vulners.com/cve/CVE-2026-24858)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - fortinet fortianalyzer (le7.0.15, le7.2.11, <7.4.10, <7.6.6) - fortinet fortimanager (le7.0.15, le7.2.11, <7.4.10, <7.6.6) - fortinet fortiproxy (le7.0.22, le7.2.15, le7.4.12, le7.6.4) - fortinet fortiweb (le7.4.11, le7.6.6, le8.0.3) ... CVE-2025-54313 \[[Vulners](https://vulners.com/cve/CVE-2025-54313)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - prettier eslint-config-prettier (8.10.1, 9.1.1, 10.1.6, 10.1.7) CVE-2025-40551 \[[Vulners](https://vulners.com/cve/CVE-2025-40551)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - solarwinds web_help_desk (<2026.1) CVE-2026-20029 \[[Vulners](https://vulners.com/cve/CVE-2026-20029)] - CVSS V3.1: *4.9*, - Vulners: Exploitation: Unknown CVE-2026-23550 \[[Vulners](https://vulners.com/cve/CVE-2026-23550)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: Unknown CVE-2026-23800 \[[Vulners](https://vulners.com/cve/CVE-2026-23800)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: Unknown CVE-2024-37079 \[[Vulners](https://vulners.com/cve/CVE-2024-37079)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - vmware cloud_foundation (<5.2) CVE-2026-24061 \[[Vulners](https://vulners.com/cve/CVE-2026-24061)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - gnu inetutils (le2.7) 🤖LLM extracted TTPs:` T1005, T1027, T1053.005, T1071.001, T1078, T1090, T1098, T1112, T1114.003, T1133, ... 🧨IOCs: - Path: 2 - Registry: 1 - IP: 6 - Email: 4 - File: 2 💽Software: Microsoft Office, Ivanti, Linux, Zimbra Collaboration Suite, WordPress, Outlook, Ivanti EPMM 🔢Algorithms: xor 📜Programming Languages: php #threatreport: In January 2026, there was a noted 5% increase in critical vulnerabilities, with 23 high-impact issues identified. Among these, the exploitation of a significant Microsoft Office zero-day vulnerability (CVE-2026-21509) by Russian state-sponsored group APT28 highlighted ongoing threats to enterprise technologies. This vulnerability, which relates to the reliance on untrusted inputs in security decisions, enabled APT28 to utilize weaponized Rich Text Format (RTF) files to deliver various malicious implants, including MiniDoor, PixyNetLoader, and Covenant Grunt. The exploitation chain initiated with an RTF file that bypassed Office OLE mitigations. The attackers deployed MiniDoor as an Outlook VBA script for email collection, while PixyNetLoader, which created a mutex for persistence, allowed further attacks. A notable aspect of this operation was the use of geography-based evasion to limit the delivery of the malicious payloads, demonstrating the sophistication of the APT28 attacks. In addition to Microsoft, other vendors such as SmarterTools and Ivanti were significantly affected, with SmarterTools reporting multiple critical vulnerabilities allowing authentication bypass and remote code execution (RCE). Specifically, CVE-2026-23760 identified a privilege escalation flaw in SmarterMail, permitting unauthenticated users to reset passwords, demonstrating serious flaws in expected security protocols. Furthermore, the Modular DS WordPress plugin was found to have multiple vulnerabilities, CVE-2026-23550 and CVE-2026-23800, that allowed attackers to gain administrator access without authentication. These vulnerabilities emphasize the risk of widespread exploitation due to the centralized management of multiple WordPress sites.

    Post summary

    The report highlights active exploitation of CVE-2026-21509 by APT28 using weaponized RTF files, detailing the tools and techniques employed, and also notes additional critical vulnerabilities in SmarterTools and WordPress plugins.

    0000074
    589 followersView on X
  • QualysNews@QualysNews
    Active Exploitation

    #CISA added CVE-2018-14634 (“#MutagenAstronomy”) to its Known Exploited Vulnerabilities (#KEV) catalog, marking the seventh Qualys #ThreatResearchUnit (TRU) discovery to join the list. This mandates federal action on the Local Privilege Escalation flaw. https://sprou.tt/1PoEKTVHtud

    Post summary

    CISA has listed CVE-2018-14634 in its Known Exploited Vulnerabilities catalog, indicating it is being exploited in the wild as a local privilege escalation flaw; no PoC, exploit code, or patch details are provided.

    0000031
    4 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 “Mutagen Astronomy” Linux LPE (CVE-2018-14634) Added to CISA KEV After 7-Year Trail Qualys explains how CVE-2018-14634 (a Linux local privilege escalation via integer overflow in create_elf_tables() when processing excessive args/env strings) was added to CISA’s KEV on Jan 26, 2026, confirming real-world exploitation. Prioritize patching multi-user and internet-facing systems with authenticated access, and update base images/templates/containers to prevent reintroducing the vulnerable build. 🎯 Target: Global/Linux (Enterprise distros incl. RHEL/CentOS) #️⃣ Category: #Vulnerability #BlueTeam #CyberIntel 🔗 URL: https://blog.qualys.com/vulnerabilities-threat-research/2026/02/02/mutagen-astronomy-discovery-to-kev

    Post summary

    The post confirms CVE‑2018‑14634 is actively exploited, as evidenced by its inclusion in the CISA KEV, and urges patching and image updates.

    0000061
    192 followersView on X
  • Qualys@qualys
    Disclo

    CISA adds Mutagen Astronomy (CVE-2018-14634) to the KEV Catalog—validating a Qualys TRU discovery &amp; mandating federal action on this Linux privilege escalation flaw. Proof that old vulns still drive real risk. Details at https://bit.ly/3ZebKDa #CISA #KEV #ThreatResearch #TRU https://t.co/vwn6YqNbpv

    Post summary

    CISA has listed CVE‑2018‑14634 in its KEV catalog, highlighting a Linux privilege‑escalation flaw that still poses risk, but the tweet does not provide exploit code, patch details, or evidence of active exploitation.

    00000370
    34.2K followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 CISA Adds Exploited Microsoft Office, Linux Kernel, Telnetd, and SmarterMail Flaws to KEV — Feb 16 Patch Deadline CISA added five vulnerabilities (CVE-2026-21509, CVE-2018-14634, CVE-2026-24061, CVE-2025-52691, CVE-2026-23760) to the KEV catalog, requiring U.S. federal agencies to remediate by Feb 16, 2026—raising urgency for everyone because these bugs include actively exploited Office bypass, Linux privesc, telnetd argument injection, and unauth SmarterMail file-upload RCE. 🎯 Target: USA/Federal + Global (Microsoft Office, Linux, SmarterMail operators) #️⃣ Category: #Vulnerability #CyberLaw #BlueTeam 🔗 URL: https://www.scworld.com/brief/cisa-adds-critical-microsoft-office-linux-kernel-and-smartermail-vulnerabilities-to-kev-catalog

    Post summary

    CISA has added five actively exploited vulnerabilities to the KEV catalog, highlighting the urgency of patching by Feb 16, 2026 for U.S. federal agencies and the global community.

    00000232
    196 followersView on X
CPE platform detail39 entries

39 of 39 entries

PartVendorProductVersionTarget SWTarget HW
OScanonicalubuntu_linux12.04--
OScanonicalubuntu_linux14.04--
Appf5big-ip_access_policy_manager---
Appf5big-ip_advanced_firewall_manager---
Appf5big-ip_analytics---
Appf5big-ip_application_acceleration_manager---
Appf5big-ip_application_security_manager---
Appf5big-ip_domain_name_system---
Appf5big-ip_edge_gateway---
Appf5big-ip_fraud_protection_service---
Appf5big-ip_global_traffic_manager---
Appf5big-ip_link_controller---
Appf5big-ip_local_traffic_manager---
Appf5big-ip_policy_enforcement_manager---
Appf5big-ip_webaccelerator---
Appf5big-iq_centralized_management---
Appf5big-iq_centralized_management4.6.0--
Appf5big-iq_cloud_and_orchestration1.0.0--
Appf5enterprise_manager3.1.1--
Appf5iworkflow---
Appf5traffix_signaling_delivery_controller---
Appf5traffix_signaling_delivery_controller4.4.0--
OSlinuxlinux_kernel---
Appnetappsnapprotect---
OSpaloaltonetworkspan-os---
OSredhatenterprise_linux_desktop6.0--
OSredhatenterprise_linux_desktop7.0--
OSredhatenterprise_linux_server6.0--
OSredhatenterprise_linux_server7.0--
OSredhatenterprise_linux_server_aus6.5--
OSredhatenterprise_linux_server_aus6.6--
OSredhatenterprise_linux_server_aus7.6--
OSredhatenterprise_linux_server_eus6.7--
OSredhatenterprise_linux_server_eus7.5--
OSredhatenterprise_linux_server_eus7.6--
OSredhatenterprise_linux_server_tus6.6--
OSredhatenterprise_linux_server_tus7.6--
OSredhatenterprise_linux_workstation6.0--
OSredhatenterprise_linux_workstation7.0--

Explore more