CVE-2026-43074PoC(linux / linux_kernel)

HIGHCVSS 7.8 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: eventpoll: defer struct eventpoll free to RCU grace period In certain situations, ep_free() in eventpoll.c will kfree the epi->ep eventpoll struct while it still being used by another concurrent thread. Defer the kfree() to an RCU callback to prevent UAF.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-401

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 11 mentions across 9 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 7 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 2 classified signals
  • Peaked 5d ago at 3 mentions (2026-08-10); latest day: 1
  • 11 total mentions across 9 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline11 mentions / 9d
01223Mentions · 2026-07-06: 1Mentions · 2026-07-12: 1Mentions · 2026-08-03: 1Mentions · 2026-08-10: 3Mentions · 2026-08-12: 1Mentions · 2026-08-14: 1Mentions · 2026-08-15: 1Mentions · 2026-09-12: 1Mentions · 2026-09-15: 1PoC Mentioned / Linked · 2026-08-03: 1PoC Mentioned / Linked · 2026-08-10: 2PoC Mentioned / Linked · 2026-08-12: 1PoC Mentioned / Linked · 2026-08-14: 1PoC Mentioned / Linked · 2026-08-15: 1PoC Mentioned / Linked · 2026-09-12: 1Exploit Tool / Code · 2026-08-03: 1Exploit Tool / Code · 2026-08-10: 2Exploit Tool / Code · 2026-08-12: 1Exploit Tool / Code · 2026-08-14: 1Exploit Tool / Code · 2026-08-15: 1Active Exploitation · 2026-09-12: 1Patch / Workaround · 2026-09-15: 1Technical Details · 2026-07-06: 1Technical Details · 2026-08-10: 3Technical Details · 2026-08-14: 1Technical Details · 2026-08-15: 1Technical Details · 2026-09-15: 107-0607-1208-0308-1008-1208-1408-1509-1209-15
Signal classification6 categories
PoC
436.4%
Disclosure
218.2%
Exploit
218.2%
General
19.1%
Active Exploitation
19.1%
Patch
19.1%
Referenced assets16 URLs
Classification over time
DateTotalLabels
2026-07-061
Disclosure1
2026-07-121
General1
2026-08-031
Exploit1
2026-08-103
Disclosure1Exploit1PoC1
2026-08-121
PoC1
2026-08-141
PoC1
2026-08-151
PoC1
2026-09-121
Active Exploitation1
2026-09-151
Patch1
Full discourse11 posts
  • moton@moton
    Disclosure

    CVE-2026-43074: Linux Kernel Bug Gives Root Shell - https://securityonline.info/linux-kernel-eventpoll-flaw/

    Post summary

    CVE‑2026‑43074 is a Linux kernel vulnerability that can grant a root shell; an online article provides the initial disclosure details.

    015053223.6K
    756 followersView on X
  • Nebula Security@nebusecurity
    Exploit

    We've also open-sourced two more LPE exploits for the latest Android on CyberMeowfia, Have fun! CVE-2026-43074: https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Ndays/Android-CVE-2026-43074 CVE-2026-64560: https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Ndays/Android-CVE-2026-64560 And we'll be giving two talks at Black Hat USA 2026 this week, come say hi in Vegas!

    Post summary

    The authors have released full exploit code for two Android LPE CVEs on GitHub and will present their findings at Black Hat USA 2026.

    16141194.0K
    7.2K followersView on X
  • ThreatWire@ThreatWire_
    Exploit

    🚨 PoC RELEASED: CVE-2026-43074, a CVSS 7.3 Linux kernel vulnerability affecting the eventpoll subsystem, has public exploit code. The flaw is a use-after-free caused by concurrent access to an eventpoll structure, potentially allowing a local attacker to corrupt kernel memory and escalate privileges. The public research targets Android, including the Pixel 10 Pro. 🔗 https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Ndays/Android-CVE-2026-43074 #Android #Pixel10Pro #Linux #Kernel #CVE #PoC #CyberSecurity #Infosec

    Post summary

    Public PoC and exploit code for CVE‑2026‑43074, a CVSS 7.3 use‑after‑free in Linux eventpoll, are available on GitHub and target Android systems such as the Pixel 10 Pro.

    01102452.7K
    1.5K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    PoC

    PoC exploit code is public for CVE-2026-43074, a Linux kernel eventpoll flaw that gives a root shell on Pixel 10 Pro. CVSS 7.3. Details inside. #Linux #Android #Pixel #CVE #CyberSecurity http://securityonline.info/linux-kernel-eventpoll-flaw/

    Post summary

    A publicly available PoC exploit for CVE-2026-43074 is disclosed, showing a Linux kernel eventpoll flaw that gives a root shell on the Pixel 10 Pro, along with CVSS details.

    12061582
    13.0K followersView on X
  • Mr. OS@ksg93rd
    Active Exploitation

    #Analytics #Threat_Research An analytical review of the main cybersecurity events (Sep 05-12, 2026) 1⃣ Sonicwall SMA1000 Attack https://hunt.io/blog/sonicwall-sma1000-uk-council-attack // CVE-2026-15409 2⃣ Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://hunt.io/blog/sonicwall-sma1000-uk-council-attack 3⃣ Next Nightmare Eclipse Vulnerability https://github.com/MSNightmare/ShieldCrash/blob/main/README.md // Microsoft has failed to properly patch ShieldBreak CVE-2026-69414.. 4⃣ FortiPAM Vulnerability https://amibeingpwned.com/blog/fortinet-pam-vuln // CVE-2026-84388 5⃣ Researchers from Nebula Security have disclosed 18 vulnerabilities in the Linux kernel https://www.openwall.com/lists/oss-security/2026/09/08/1 // CVE-2026-80714, CVE-2026-74597, CVE-2026-74581, CVE-2026-74480, CVE-2026-72255, CVE-2026-72137, CVE-2026-68376, CVE-2026-68162, CVE-2026-64560,  CVE-2026-63834, CVE-2026-52933, CVE-2026-52929, CVE-2026-52924, CVE-2026-52923, CVE-2026-52912, CVE-2026-43501, CVE-2026-43502, CVE-2026-43074, CVE-2026-43042, CVE-2026-31678, CVE-2026-31659, CVE-2026-23274 6⃣ Netscaler ADC Exploit 7⃣ Critical vulnerabilities in MikroTik RouterOS https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/ 8⃣ GRAYRABBIT One-click backdoor // One click. Three critical failures. One backdoor https://www.gendigital.com/blog/insights/research/one-click-backdoor-sogou 9⃣ Attacks using browser-in-browser (BiTB) phishing techniques https://www.huntress.com/blog/phishing-bitb-rmm-attacks 🔟 Beltdown: Escaping the Claude Code sandbox https://www.accomplish.ai/blog/beltdown-escaping-the-claude-code-sandbox/ // An untrusted repository opened in Claude Code can escape the macOS sandbox and run commands on your computer as your privileged user http://www.Geniebot.pro http://www.cyberpocket.org

    Post summary

    The tweet lists several CVEs with links to blogs and GitHub, indicating evidence of active exploitation but providing neither detailed technical info nor patch guidance.

    01052600
    3.4K followersView on X
  • Threat Landscape@LandscapeThreat
    Patch

    Researchers disclosed CVE-2026-43502, a Linux kernel local privilege-escalation vulnerability in the RDS zerocopy send path, alongside 20 additional exploitable Linux bugs. - An unprivileged local user can obtain root privileges without Linux capabilities or user namespaces when required networking, asynchronous I/O, and RDS components are enabled. - The vulnerability affects kernels from Linux v4.17 and was demonstrated on openSUSE with kernel 6.4.0-150600.23.100. - The issue was fixed by commit 44b550d88b26, first included in Linux v7.1-rc3; public exploits for the listed vulnerabilities are available. VULNERABILITY CVE-2026-23274 CVE-2026-31659 CVE-2026-31678 CVE-2026-43042 CVE-2026-43074 CVE-2026-43501 CVE-2026-43502 CVE-2026-52912 CVE-2026-52923 CVE-2026-52924 CVE-2026-52929 CVE-2026-52933 CVE-2026-63834 CVE-2026-64560 CVE-2026-68162 CVE-2026-68376 CVE-2026-72137 CVE-2026-72255 CVE-2026-74480 CVE-2026-74581 CVE-2026-74597 CVE-2026-80714

    Post summary

    The tweet discloses CVE‑2026‑43502 as a Linux kernel local privilege‑escalation in the RDS zerocopy path, notes the fix via commit 44b550d88b26 (Linux v7.1‑rc3), and indicates that public exploits for the listed vulnerabilities are now available.

    0002055
    91 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    PoC

    Linuxカーネルのeventpollにroot権限奪取の脆弱性、Pixel 10 ProでのPoCエクスプロイトが公開(CVE-2026-43074) AnthropicのMythosが発見した脆弱性 https://rocket-boys.co.jp/security-measures-lab/linux-kernel-eventpoll-privilege-escalation-cve-2026-43074/ #セキュリティ対策Lab #security #securitynews #脆弱性

    Post summary

    CVE-2026-43074, a root privilege escalation flaw in Linux kernel eventpoll, has been disclosed and a PoC exploit for a Pixel 10 Pro has been published; no patch or evidence of active exploitation was noted.

    00010203
    548 followersView on X
  • Bhavik@bhavikdev
    General

    Anthropic's Mythos model found bug #1 earlier this year. Now tracked as CVE-2026-43074. Last week, researcher Jaeyoung Chung disclosed bug #2 — sitting in the exact same stretch of code. Called "Bad Epoll" — CVE-2026-46242.

    Post summary

    The post announces two CVEs (CVE-2026-43074 and CVE-2026-46242) related to Anthropic's Mythos model but provides no additional exploitation, patch, or technical details.

    1000053
    40 followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    PoC

    Linuxカーネルのeventpollにroot権限奪取の脆弱性、Pixel 10 ProでのPoCエクスプロイトが公開(CVE-2026-43074) AnthropicのMythosが発見した脆弱性|セキュリティ対策Lab https://rocket-boys.co.jp/security-measures-lab/linux-kernel-eventpoll-privilege-escalation-cve-2026-43074/ "実証コードで、Pixel 10 Pro上において80%を超える成功率でroot権限のシェルを取得できることを確認"

    Post summary

    The post announces CVE‑2026‑43074, a Linux kernel eventpoll privilege‑escalation flaw, and shares a publicly released PoC exploit that achieves root shell on a Pixel 10 Pro with over 80% success rate, though no live exploitation has been reported.

    00000250
    3.5K followersView on X
  • Mahmoud Jadaan@mjadaaan
    PoC

    CVE-2026-43074 PoC LPE exploit for blazer https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Ndays/Android-CVE-2026-43074

    Post summary

    The post announces a Proof of Concept for CVE-2026-43074, linking to a GitHub repository containing an LPE exploit, but contains no evidence of active exploitation or repairs.

    0000075
    42 followersView on X
  • Aseem Shrey@AseemShrey
    Disclosure

    The AI angle is the interesting part. Anthropic deployed Mythos under Project Glasswing to hunt kernel bugs. It found CVE-2026-43074, a related flaw in the same epoll code path. But Bad Epoll was the harder-to-spot sibling. Same 2023 commit introduced both. The AI caught one. A human caught the other. AI narrows the search space. It doesn't close it. https://thehackernews.com/2026/07/new-bad-epoll-linux-kernel-flaw-lets.html

    Post summary

    Anthropic identified a kernel flaw (CVE‑2026‑43074) in the epoll path, but no PoC, exploit, patch, or active exploitation details are provided.

    00000164
    8.7K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel6.4--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more