セキュリティ対策Lab[verified]@securityLab_jpDisclosure
The article announces CVE-2026-39118, a macOS XPC communication vulnerability that allows local users to disable security features of CrowdStrike and Kandji, without providing a PoC or evidence of exploitation.
ThreatCluster[verified]@threatclusterDisclosure
XM Cyber researchers have disclosed CVE‑2026‑39118, a macOS privilege‑escalation vulnerability that allows standard users to bypass privilege controls and compromise security solutions such as CrowdStrike Falcon and Kandji MDM.
IntegSec[verified]@integ_secGeneral
The snippet only provides a title and a link, offering minimal explicit information about the vulnerability beyond its type, so no definitive classification can be asserted.
Cyberdark Impact[verified]@kenebeiiPoC
The post announces a CVE-2026-39118 Mac XPC vulnerability and shares a proof‑of‑concept for an integer overflow in libssh2, but does not report active exploitation or patches.
كاسبر سكاي@KasperskyDevDisclosure
MacOS vulnerability CVE‑2026‑39118 enables regular users to disable protection agents; Kandji MDM (<4.7.5) users should immediately upgrade the agent.