
Ubuntu published security notice USN-8402-1 disclosing CVE-2026-40226 and CVE-2023-7008 in systemd affecting Ubuntu 22.04 LTS, 24.04 LTS and 25.10, allowing local escape from systemd-nspawn containers and DNS record manipulation, Ubuntu said. https://threatcluster.io/cluster/critical-systemd-vulnerabilities-affect-multiple-ubuntu-rele-390c275c
Post summary
The notice announces two CVEs in systemd and outlines their technical impact, but provides no PoC, exploit code, or patch details.

