CVE-2026-35535Disclosure(siemens / ruggedcom_rst2428p)

MEDIUMCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch siemens ruggedcom_rst2428p systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-271CWE-272

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ruggedcom_rst2428p
  • sinec_os
  • sudo

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 2 mentions (2026-04-03); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Products
ruggedcom_rst2428psinec_ossudo

2 versions affected across 3 products

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-04-03: 2Mentions · 2026-04-06: 1Mentions · 2026-04-25: 2Mentions · 2026-04-26: 1Mentions · 2026-05-03: 1PoC Mentioned / Linked · 2026-04-25: 2Exploit Tool / Code · 2026-04-25: 1Patch / Workaround · 2026-04-25: 2Patch / Workaround · 2026-05-03: 1Technical Details · 2026-04-03: 1Technical Details · 2026-05-03: 104-0304-0604-2504-2605-03
Signal classification4 categories
Disclosure
228.6%
General
228.6%
Patch
228.6%
PoC
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-032
Disclosure1General1
2026-04-061
Disclosure1
2026-04-252
Patch1PoC1
2026-04-261
General1
2026-05-031
Patch1
Full discourse7 posts
  • Kazuki Omo@omokazuki
    Disclosure

    SIOSセキュリティブログを更新しました。 sudoの脆弱性(High: CVE-2026-35535) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #sudo https://security.sios.jp/vulnerability/sudo-security-vulnerability-20260407/

    Post summary

    The post announces the discovery of a high‑severity CVE‑2026-35535 affecting sudo, without providing further technical details, PoC, or mitigation information.

    00030156
    370 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    #Fedora just patched sudo (CVE-2026-35535). You updated. Great. Now learn how that patch works -> https://tinyurl.com/48jmxp7m https://t.co/m5kUDG3oNs

    Post summary

    The tweet announces that Fedora has patched sudo for CVE-2026-35535 and includes a link for readers to review how the patch addresses the issue.

    1001065
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    A sudo vulnerability (CVE-2026-35535) could let any local user gain root on Rocky Linux. Here's how to check, patch, and automate updates: Read more -> https://tinyurl.com/2kd8ztbp #Security https://t.co/DLuGKrRLmk

    Post summary

    The tweet highlights the sudo local privilege escalation vulnerability CVE-2026-35535 on Rocky Linux and directs readers to resources for checking and applying patches, with no PoC, exploit, or active exploitation claims.

    0000167
    1.5K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2014-6271 2 - CVE-2026-35535 3 - CVE-2024-7399 4 - CVE-2025-29635 5 - CVE-2026-0628 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The tweet simply lists five trending CVEs with a link to a dashboard, offering no further technical details, exploits, or remediation information.

    00010768
    1.7K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    PoC

    How to check CVE-2026-35535 on Fedora: $ sudo -u '#-1' id If it prints uid=0(root) → VULNERABLE. Update sudo to 1.9.17-8.p2.fc44 or use the iptables block. Read more-> https://tinyurl.com/bbfzmmph https://t.co/YwreJ7elam

    Post summary

    The post describes a method to verify CVE-2026-35535 on Fedora by running a sudo command that triggers privilege escalation, and offers mitigation steps via an updated sudo package or iptables block.

    1000045
    1.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35535 In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and… https://www.cve.org/CVERecord?id=CVE-2026-35535

    Post summary

    The post references CVE-2026-35535, detailing a non-fatal failure of setuid/setgid/setgroups during privilege drop in sudo, with a link to the CVE record.

    00010116
    56.9K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-35535 📊 Severity: 7.4 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-35535 #CVE-2026-35535 #CVE #High #CyberSecurity #InfoSec https://t.co/C6NLZ4sa02

    Post summary

    The tweet announces CVE-2026-35535 with a 7.4 severity score and high risk level but offers no further technical details, exploitation evidence, or remediation information.

    0000057
    123 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
HWsiemensruggedcom_rst2428p---
OSsiemenssinec_os---
Appsudo_projectsudo---
Appsudo_projectsudo1.9.17--
Appsudo_projectsudo1.9.17--
Appsudo_projectsudo1.9.17--

Explore more