CVE-2026-40572Disclosure(minecanton209 / novumos)

MEDIUMCVSS 9.0 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch minecanton209 novumos systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 15 (MemoryMapRange) allows Ring 3 user-mode processes to map arbitrary virtual address ranges into their address space without validating against forbidden regions, including critical kernel structures such as the IDT, GDT, TSS, and page tables. A local attacker can exploit this to modify kernel interrupt handlers, resulting in privilege escalation from user mode to kernel context. This issue has been fixed in version 0.24.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • novumos

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-18); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Products
novumos

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-18: 3Mentions · 2026-04-20: 1PoC Mentioned / Linked · 2026-04-20: 1Active Exploitation · 2026-04-18: 1Patch / Workaround · 2026-04-18: 1Technical Details · 2026-04-18: 3Technical Details · 2026-04-20: 104-1804-20
Signal classification2 categories
Disclosure
375.0%
Active Exploitation
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-183
Active Exploitation1Disclosure2
2026-04-201
Disclosure1
Full discourse4 posts
  • NerdieNews@NewsNerdie
    Active Exploitation

    NovumOS CVE-2026-40572 is under active exploitation—attackers can map arbitrary memory via Syscall 15, risking unauthorized access. Patch now to prevent potential breaches. #NerdieNews #CyberSecurity #InfoSec #Vulnerability #Phishing https://t.co/yrbOfdKMij

    Post summary

    The post alerts that CVE-2026-40572 is actively exploited by attackers mapping arbitrary memory via Syscall 15, and urges patching immediately to stop potential breaches.

    0002069
    68 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-40572: NovumOS has Arbitrary Memory Map... Ring 3 processes directly tampering with IDT/GDT through unvalidated syscall - kernel's front door left wide open for p... https://zerodaysignal.com/vulnerability/CVE-2026-40572 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑40572, outlining a kernel privilege‑escalation flaw via unvalidated syscalls that let user processes tamper with IDT/GDT, but it does not mention exploitation, patches, or false‑positive claims.

    0000065
    218 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40572 NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 15 (MemoryMapRange) allows Ring 3 user-mode processes … https://www.cve.org/CVERecord?id=CVE-2026-40572

    Post summary

    The excerpt announces a vulnerability in NovumOS (CVE‑2026‑40572) tied to Syscall 15 (MemoryMapRange) before version 0.24, providing initial technical details but no evidence of exploitation or patching.

    0000088
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40572 Arbitrary Memory Mapping Privilege Escalation in NovumOS Versions Prior to 0.24 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40572

    Post summary

    The post announces a privilege‑escalation vulnerability in NovumOS versions before 0.24, providing basic technical details but no evidence of exploitation, patches, or PoC.

    0000043
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSminecanton209novumos---

Explore more