CVE-2024-1086Active Exploitation(debian / 500f)

CRITICALCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for debian 500f systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT. We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660.

8.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-06-20. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-416

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 500f
  • 500f_firmware
  • a250
  • a250_firmware

Threat summary

  • Active exploitation appears in 6 classified signals
  • Public PoC and exploit tooling are both present
  • 17 mentions across 12 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 6 signals
  • Exploit tool or code specified in 7 signals
  • PoC mentioned or linked in 7 signals
  • Technical details provided in 11 signals
  • General: 4 classified signals
  • Peaked 11d ago at 2 mentions (2026-02-15); latest day: 1
  • 17 total mentions across 12 days

Affected systems

Products
500f500f_firmwarea250a250_firmwarebootstrap_osc250c250_firmwaredebian_linuxenterprise_linux_desktopenterprise_linux_for_ibm_z_systems

8 versions affected across 27 products

Deep dive

Activity timeline17 mentions / 12d
01122Mentions · 2026-02-15: 2Mentions · 2026-03-09: 2Mentions · 2026-03-14: 1Mentions · 2026-04-15: 2Mentions · 2026-05-01: 2Mentions · 2026-05-11: 1Mentions · 2026-05-29: 1Mentions · 2026-06-13: 2Mentions · 2026-06-26: 1Mentions · 2026-09-08: 1Mentions · 2026-09-14: 1Mentions · 2026-09-25: 1PoC Mentioned / Linked · 2026-02-15: 2PoC Mentioned / Linked · 2026-04-15: 1PoC Mentioned / Linked · 2026-05-01: 1PoC Mentioned / Linked · 2026-05-11: 1PoC Mentioned / Linked · 2026-06-13: 2Exploit Tool / Code · 2026-02-15: 2Exploit Tool / Code · 2026-05-01: 1Exploit Tool / Code · 2026-05-11: 1Exploit Tool / Code · 2026-06-13: 2Exploit Tool / Code · 2026-09-25: 1Active Exploitation · 2026-03-09: 1Active Exploitation · 2026-03-14: 1Active Exploitation · 2026-04-15: 1Active Exploitation · 2026-05-01: 1Active Exploitation · 2026-05-29: 1Active Exploitation · 2026-09-25: 1Technical Details · 2026-02-15: 1Technical Details · 2026-03-09: 1Technical Details · 2026-04-15: 2Technical Details · 2026-05-01: 2Technical Details · 2026-05-11: 1Technical Details · 2026-05-29: 1Technical Details · 2026-06-13: 1Technical Details · 2026-09-14: 1Technical Details · 2026-09-25: 102-1503-0903-1404-1505-0105-1105-2906-1306-2609-0809-1409-25
Signal classification5 categories
Active Exploitation
635.3%
General
423.5%
Exploit
317.6%
PoC
211.8%
Disclosure
211.8%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-152
Exploit1PoC1
2026-03-092
Active Exploitation1General1
2026-03-141
Active Exploitation1
2026-04-152
Active Exploitation1General1
2026-05-012
Active Exploitation1Disclosure1
2026-05-111
Exploit1
2026-05-291
Active Exploitation1
2026-06-132
Exploit1PoC1
2026-06-261
General1
2026-09-081
General1
2026-09-141
Disclosure1
2026-09-251
Active Exploitation1
Full discourse17 posts
  • Manuel Martinez (Curiosidades De Hackers)@HackersCuriosos
    Active Exploitation

    🔎 Análisis forense de una escalada de privilegios en Linux mediante explotación de kernel (CVE-2024-1086) El análisis forense en sistemas Linux permite entender no solo qué ocurrió, sino cómo y en qué orden se desarrolló un ataque. A diferencia de otros entornos, aquí la clave está en correlacionar artefactos dispersos: procesos, binarios, rutas y contexto del sistema. En este escenario, se analiza un compromiso real donde un atacante, tras obtener acceso inicial limitado, despliega un exploit local para escalar privilegios y tomar el control del sistema. El acceso inicial marca el punto de entrada, pero es solo el comienzo. A partir de ahí, el atacante introduce un binario en una ruta temporal (`/tmp/exploit`), aprovechando un directorio comúnmente poco monitorizado para preparar la siguiente fase del ataque. Una vez dentro, el binario es ejecutado bajo un usuario sin privilegios. Este detalle es clave: no se trata de un proceso legítimo, sino de un intento claro de escalar privilegios desde un contexto restringido. El siguiente paso revela el núcleo del incidente. El artefacto analizado corresponde a un exploit público asociado a CVE-2024-1086, una vulnerabilidad del kernel Linux que permite elevación de privilegios mediante un fallo de tipo Use-After-Free en `nf_tables`. Finalmente, el exploit cumple su objetivo: aprovechar un kernel vulnerable para escalar privilegios y comprometer completamente el sistema. Gracias al análisis de artefactos recolectados con UAC, es posible correlacionar la presencia del binario, su ejecución en memoria y el contexto del sistema, reconstruyendo con precisión toda la línea temporal del ataque. Cadena de ataque inferida: • Acceso inicial al sistema • Transferencia del binario `/tmp/exploit` • Ejecución bajo usuario sin privilegios • Explotación de CVE-2024-1086 • Escalada de privilegios Este caso demuestra cómo un atacante puede comprometer un sistema sin necesidad de técnicas especialmente sofisticadas, y cómo la falta de parcheo en el kernel puede ser el factor decisivo en el éxito del ataque. Articulo completo en el primer comentario #DFIR #DigitalForensics #CyberSecurity #IncidentResponse #WindowsForensics #ThreatHunting #ThreatIntelligence #BlueTeam #SOC #SOCAnalyst #ThreatDetection #CyberDefense #SecurityOperations #ForensicAnalysis #DFIRCommunity #Infosec #CyberThreats #LogAnalysis #ThreatInvestigation #SecurityMonitoring #MalwareAnalysis #LivingOffTheLand #TeamViewer #WindowsSecurity #ThreatAnalysis #CyberIncident

    Post summary

    This post details a forensic investigation of a real Linux kernel privilege‑escalation exploit (CVE‑2024‑1086) used in an attacker’s workflow, highlighting the use of a local binary, the exploitation of a use‑after‑free in nf_tables, and the absence of a kernel patch.

    152029315314.5K
    2.1K followersView on X
  • Manuel Martinez (Curiosidades De Hackers)@HackersCuriosos
    General

    Análisis forense de una escalada de privilegios en Linux mediante explotación de kernel (CVE-2024-1086) https://curiosidadesdehackers.com/analisis-forense-de-una-escalada-de-privilegios-en-linux-mediante-explotacion-de-kernel-cve-2024-1086/

    Post summary

    The post references a forensic analysis of the Linux kernel privilege‑escalation vulnerability CVE‑2024‑1086, mentioning its nature but providing no PoC, exploit code, or patch details.

    02033534
    2.1K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Operation Master exposed: a single Brazilian 🇧🇷 threat actor ran a full intrusion-to-fraud pipeline, exploiting CVE-2026-0257 across 7 GlobalProtect gateways in four countries, stealing 600+ companies' data, then weaponizing it inside an automated multi-tenant invoice fraud platform that generated 2.4M+ messages and R$150.4M in attempted PIX fraud. - CVE-2026-0257 (GlobalProtect authentication bypass) was the primary at-scale access vector. The actor forged auth cookies from target certificate context and fed candidates through a 30-worker automated exploit loop driven by continuous masscan output across 277.5M scanned hosts. The same CVE is being exploited separately by ransomware actors including Qilin, making it a high-priority patch target. Beyond VPN access, parallel campaigns hit SQLi targets via sqlmap and xp_cmdshell chains to pivot from database access to host execution, with DNS subdomain tunneling (470,268 queries from a single compromised host, structured as task.row.chunk.base64.x.random.victim-hostname) as the primary exfil rail, and rclone syncing to MEGA as a redundant second channel. Staged webshells (beacon.dll, wmsvc.dll, gopher_new.exe) and AdaptixC2 on 91.92.241[.]187 (ports 8443/4444/4321) provided C2 over HTTP and raw TCP. Additional techniques: SAM/SYSTEM/SECURITY hive theft (T1003.002), ntds.dit recovery (T1003.003), GodPotato token impersonation, PwnKit (CVE-2021-4034), CVE-2024-1086, and CVE-2023-7028 (CVSS 10.0 GitLab dual-email reset) hardcoding cyberkill2025[@]http://gmail.com as the attacker-controlled recovery address. - The fraud monetization layer is a Node.js multi-tenant "master-panel" at /opt/master-panel/, running under PM2, backed by PostgreSQL and SQLite, and exposed externally on yzs[.]fi. Lookalike domains igreenfaturas[.]to, wattiofaturas[.]com, and nuvfaturas[.]com hosted per-victim invoice pages with URL parameters embedding the victim's real name, due date, consumption, and billing amount pulled from stolen utility databases. Email delivery routed through 12 hijacked M365 mailboxes (retail, healthcare, education) to inherit sender reputation. SMS ran across 8 SMPP gateways. PIX payments routed through a serverless Vercel proxy at pix-proxy-sable.vercel[.]app. The lead source was 1.8M records scraped via a passwordless JWT flaw in iGreen Energia's API. The fraud engine logged 622,666 personalized links, 317,696 click events, and R$38.9M in fraudulent invoices opened by victims. - Attribution converges on forum persona masterblack and primary email cyberkill2025[@]http://gmail.com, which appears across: 34 fraud panel lead test records, the GitLab CVE-2023-7028 exploit hardcoding, OSINT API registrations (Shodan, VirusTotal, SecurityTrails, WPScan, AlienVault OTX), a recovered pentest report listing the operator, and a leaked hacker forum database record directly linking the email to the masterblack account that sold stolen iGreen and Wattio data weeks before the fraud campaigns began. The two-stage strategy, sell the data first, then phish the same victims with their own billing records, is confirmed by the 9 to 14 week gap between forum sale listings and bulk tenant seeding. The operator's AI agent workspace (36+ offensive subagents, ~45 persistent memory files) was exposed via a misconfigured cloud backup reachable from the first exploitation server at 85.120.216[.]8. - Key detection opportunities from the article: sqlservr.exe spawning cmd.exe or PowerShell is a high-fidelity signal for the xp_cmdshell chain. High-entropy DNS queries from database service identities indicate active tunneling. rclone or unauthorized cloud-sync binaries on servers warrant immediate investigation. OAuth device-code grants without corresponding enrollment events indicate T1598 phishing. Unauthorized reads of SAM, SYSTEM, SECURITY hives or ntds.dit by service accounts are critical alerts. For the fraud infrastructure specifically, URL parameters matching the schema ?ref=, venc=, v=, v0=, kwh= on lookalike utility domains are a structural indicator of the invoice fraud platform's output. Full IOC table (IPs, domains, SHA-256 hashes for all beacon and agent variants, qTox IDs) and the complete MITRE ATT&CK mapping are in the SOCRadar report. Prioritize hunting for AdaptixC2 gopher agent artifacts (gopher_new.exe SHA-256 54caa256483876debd21c264bfc31bd96f925b2167f6d9358ab7ee0c87e6e37b, beacon.dll SHA-256 d566ccdd099b0decb7e7288c20097f34da2613e3ffe8c5acbc1a1d01b6fe217c) and block the four operation server IPs: 85.120.216[.]8, 91.92.241[.]187, 91.92.241[.]184, and 185.242.3[.]14. #DFIR_Radar

    Post summary

    The text reports active, in-the-wild exploitation of CVE-2026-0257, including use by a Brazilian threat actor and separately by ransomware actors such as Qilin. It also details exploitation techniques, related tooling, and downstream fraud infrastructure.

    20120638
    2.0K followersView on X
  • Jeremy / SG@shaogens
    Active Exploitation

    @Adriksh People who believe the whole security through open source remind me of little things like this: https://www.sysdig.com/blog/detecting-cve-2024-1086-the-decade-old-linux-kernel-vulnerability-thats-being-actively-exploited-in-ransomware-campaigns

    Post summary

    The tweet links to a blog post asserting that CVE‑2024‑1086 is being actively exploited in ransomware campaigns, but it provides no direct PoC, patch, or technical details.

    10022749
    62 followersView on X
  • ToxSec@0xToxSec
    Active Exploitation

    why can’t docker hold a frontier model? shared kernel. the container gets its own pids, its own mounts, its own network stack, but the kernel is one big shared party. one use-after-free in netfilter and every container on the box is poppable. CVE-2024-1086 proved it, ransomhub shipped it. #docker #kernelexploit #cloudsecurity

    Post summary

    The post indicates that CVE‑2024‑1086’s kernel use‑after‑free has been used by ransomware (ransomhub), pointing to active exploitation.

    00020108
    154 followersView on X
  • c0deNinja@gotr00t0day
    Exploit

    kernelpwn: A lightweight, fast kernel exploit suggester written in C++ that automatically detects if your Linux kernel is vulnerable to known privilege escalation exploits. These are the vulnerabilities that kernelpwn can detect: 1. Dirty COW (CVE-2016-5195) 2. Dirty Pipe (CVE-2022-0847) 3. GameOver(lay) (CVE-2023-32629) 4. CVE-2024-1086 5. Copy Fail 6. Dirty Frag Github: https://github.com/gotr00t0day/kernelpwned #hacking #hacker #cybersecurity #cplusplus #coding #infosec #linux #linuxkernel #unix #pentesting #ethicalhacking #infosec #programming

    Post summary

    The announcement introduces kernelpwn, a C++ tool that auto-detects and suggests exploitation of known Linux kernel privilege escalation vulnerabilities, including several CVEs, and shares its source on GitHub.

    00020152
    555 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2024-1086 2 - CVE-2022-40982 3 - CVE-2025-24252 4 - CVE-2025-55182 5 - CVE-2026-21533 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists the top five trending CVEs with no additional technical context, exploit information, or mitigation details.

    00020213
    1.7K followersView on X
  • Slade 🛡️ LLM Hacker@llm_redteam
    General

    @lnxsec 72 seconds to chain primitives. wait till they feed it CVE-2024-1086.

    Post summary

    The tweet notes a 72‑second chain to exploit CVE‑2024‑1086 but offers no additional details or evidence of active use.

    0001044
    1.3K followersView on X
  • nksistemas@nksistemas
    General

    CVE-2024-1086: El Fallo Crítico del Kernel Linux que Conduce a la Escalada de Privilegios a Root https://nksistemas.com/cve-2024-1086-el-fallo-critico-del-kernel-linux-que-conduce-a-la-escalada-de-privilegios-a-root/

    Post summary

    The text announces a critical Linux kernel privilege‑escalation vulnerability (CVE‑2024‑1086) but contains no technical details, PoC, exploit, or patch information.

    01000160
    6.2K followersView on X
  • xymox@clxymox
    PoC

    📌 Universal local privilege escalation Proof-of-Concept exploit for CVE-2024-1086, working on most Linux kernels between v5.14 and v6.6, including Debian, Ubuntu, and KernelCTF. The success rate is 99.4% in KernelCTF images. 🔗 https://github.com/Notselwyn/CVE-2024-1086 #C

    Post summary

    The post announces a working local privilege escalation PoC for CVE‑2024‑1086, good success rate, and shares the exploit code on GitHub.

    00001102
    467 followersView on X
  • xymox@clxymox
    Exploit

    🔧 CVE-2024-1086 ⭐ 2,448 stars **"Exploit universel et ultra-efficace pour CVE-2024-1086 en Linux !"** #GitHub https://t.co/lbmSOwGnw1

    Post summary

    The tweet announces a universal, ultra‑effective exploit for CVE‑2024‑1086 on Linux, linking to a GitHub repository that presumably contains the functional exploit code.

    1000045
    467 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2024-1086: Linux kernel contains a use-after-free vulnerability in the netfilter: nftables component that allows an attacker to achieve local privilege escalation.

    Post summary

    The text announces a newly disclosed Linux kernel use‑after‑free vulnerability in nftables (CVE‑2024‑1086) that can be leveraged for local privilege escalation.

    1000037
    152 followersView on X
  • Grok@grok
    Active Exploitation

    Containers share the host kernel, so breakouts include: - Kernel exploits (e.g. CVE-2024-1086 netfilter UAF, OverlayFS bugs, or 2025 variants) letting untrusted code gain host root. - Runtime escapes (runc/Docker: Nov 2025 CVEs via mount races or /dev/console abuse). - Misconfigs (privileged mode, host mounts, capability leaks). VMs use separate kernel + hypervisor; breakouts need rare hypervisor bugs (much harder, lower surface). For an AI agent with arbitrary code: possible in containers if vuln unpatched (low-moderate odds w/ seccomp/user namespaces; real exploits seen). VMs: near-impossible w/o 0-day hypervisor flaw. Stick to VM for creds/net as PSA says.

    Post summary

    The post alerts that container host‑kernel vulnerabilities, such as CVE-2024-1086, are being actively exploited, while similar attacks on VMs remain rare, underscoring the higher risk of container breakout for unpatched systems.

    1000053
    8.4M followersView on X
  • xymox@clxymox
    Exploit

    🔧 CVE-2024-1086 ⭐ 2,432 stars "Exploit ultra-efficace pour CVE-2024-1086 : 99,4% de réussite sur Linux !" #GitHub https://t.co/D9jwEOop2S

    Post summary

    A GitHub-hosted exploit for CVE‑2024‑1086 claims 99.4% success on Linux, indicating a working PoC is publicly available.

    1000068
    367 followersView on X
  • Merge News@mergenewsapp
    Disclosure

    A Linux Netfilter flaw (CVE-2024-1086) enables container escapes to root cloud nodes, demanding strict node-level kernel hardening. #cybersecurity #linux #vulnerability #kernel

    Post summary

    The tweet announces CVE-2024-1086, a Linux Netfilter vulnerability that enables container escapes to root cloud nodes, and recommends node-level kernel hardening. It serves as a vulnerability disclosure with technical impact details but no named patch, PoC, or exploit.

    0000032
    65 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2024-1086-kernel #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post announces that CVE‑2024‑1086, a kernel-based Linux vulnerability, is being actively exploited in the wild, providing exploit code and technical details while lacking any mention of patches or workarounds.

    0000026
    152 followersView on X
  • xymox@clxymox
    PoC

    📌 Universal local privilege escalation Proof-of-Concept exploit for CVE-2024-1086, working on most Linux kernels between v5.14 and v6.6, including Debian, Ubuntu, and KernelCTF. The success rate is 99.4% in KernelCTF images. 🔗 https://github.com/Notselwyn/CVE-2024-1086 #C

    Post summary

    A proof‑of‑concept local privilege escalation exploit for CVE‑2024‑1086 is available, targeting Linux kernels 5.14‑6.6 with a 99.4% success rate, as demonstrated by the linked GitHub repo.

    0000077
    367 followersView on X
CPE platform detail28 entries

28 of 28 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux10.0--
OSfedoraprojectfedora39--
OSlinuxlinux_kernel---
OSlinuxlinux_kernel6.8--
HWnetapp500f---
OSnetapp500f_firmware---
HWnetappa250---
OSnetappa250_firmware---
OSnetappbootstrap_os---
HWnetappc250---
OSnetappc250_firmware---
HWnetapph300s---
OSnetapph300s_firmware---
HWnetapph410c---
OSnetapph410c_firmware---
HWnetapph410s---
OSnetapph410s_firmware---
HWnetapph500s---
OSnetapph500s_firmware---
HWnetapph700s---
OSnetapph700s_firmware---
HWnetapphci_compute_node---
OSredhatenterprise_linux_desktop7.0--
OSredhatenterprise_linux_for_ibm_z_systems7.0_s390x--
OSredhatenterprise_linux_for_power_big_endian7.0_ppc64--
OSredhatenterprise_linux_for_power_little_endian7.0_ppc64le--
OSredhatenterprise_linux_server7.0--
OSredhatenterprise_linux_workstation7.0--

Explore more