CVE-2026-4747PoC(freebsd / freebsd)

CRITICALCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 35 mentions and remains active

Immediate actions

  • Patch freebsd freebsd systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Each RPCSEC_GSS data packet is validated by a routine which checks a signature in the packet. This routine copies a portion of the packet into a stack buffer, but fails to ensure that the buffer is sufficiently large, and a malicious client can trigger a stack overflow. Notably, this does not require the client to authenticate itself first. As kgssapi.ko's RPCSEC_GSS implementation is vulnerable, remote code execution in the kernel is possible by an authenticated user that is able to send packets to the kernel's NFS server while kgssapi.ko is loaded into the kernel. In userspace, applications which have librpcgss_sec loaded and run an RPC server are vulnerable to remote code execution from any client able to send it packets. We are not aware of any such applications in the FreeBSD base system.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freebsd

Threat summary

  • Active exploitation appears in 23 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 152 mentions across 42 observed days

What's happening

  • Active exploitation reported across 23 signals
  • Exploit tool or code specified in 38 signals
  • PoC mentioned or linked in 72 signals
  • Patch or workaround mentioned in 12 signals
  • Technical details provided in 102 signals
  • General: 33 classified signals
  • Peaked 38d ago at 35 mentions (2026-04-01); latest day: 2
  • 152 total mentions across 42 days

Affected systems

Vendors
Products
freebsd

4 versions affected across 1 product

Deep dive

Activity timeline152 mentions / 42d
09182635Mentions · 2026-03-26: 3Mentions · 2026-03-27: 1Mentions · 2026-03-31: 5Mentions · 2026-04-01: 35Mentions · 2026-04-02: 7Mentions · 2026-04-03: 5Mentions · 2026-04-04: 9Mentions · 2026-04-05: 8Mentions · 2026-04-06: 2Mentions · 2026-04-07: 5Mentions · 2026-04-08: 9Mentions · 2026-04-09: 3Mentions · 2026-04-10: 5Mentions · 2026-04-11: 1Mentions · 2026-04-12: 4Mentions · 2026-04-14: 1Mentions · 2026-04-15: 4Mentions · 2026-04-16: 3Mentions · 2026-04-19: 1Mentions · 2026-04-20: 1Mentions · 2026-04-21: 3Mentions · 2026-04-22: 1Mentions · 2026-05-03: 2Mentions · 2026-05-08: 1Mentions · 2026-05-09: 3Mentions · 2026-05-11: 1Mentions · 2026-05-12: 5Mentions · 2026-05-13: 2Mentions · 2026-05-16: 1Mentions · 2026-05-23: 1Mentions · 2026-05-24: 1Mentions · 2026-05-26: 1Mentions · 2026-05-27: 2Mentions · 2026-05-30: 1Mentions · 2026-06-04: 2Mentions · 2026-06-06: 1Mentions · 2026-07-13: 2Mentions · 2026-07-29: 1Mentions · 2026-07-30: 2Mentions · 2026-08-19: 4Mentions · 2026-09-06: 1Mentions · 2026-09-29: 2PoC Mentioned / Linked · 2026-03-31: 3PoC Mentioned / Linked · 2026-04-01: 30PoC Mentioned / Linked · 2026-04-02: 6PoC Mentioned / Linked · 2026-04-03: 3PoC Mentioned / Linked · 2026-04-04: 7PoC Mentioned / Linked · 2026-04-05: 5PoC Mentioned / Linked · 2026-04-07: 2PoC Mentioned / Linked · 2026-04-08: 1PoC Mentioned / Linked · 2026-04-09: 1PoC Mentioned / Linked · 2026-04-10: 2PoC Mentioned / Linked · 2026-04-11: 1PoC Mentioned / Linked · 2026-05-03: 2PoC Mentioned / Linked · 2026-05-12: 1PoC Mentioned / Linked · 2026-05-13: 1PoC Mentioned / Linked · 2026-05-23: 1PoC Mentioned / Linked · 2026-05-26: 1PoC Mentioned / Linked · 2026-05-27: 1PoC Mentioned / Linked · 2026-06-04: 1PoC Mentioned / Linked · 2026-07-13: 1PoC Mentioned / Linked · 2026-08-19: 2Exploit Tool / Code · 2026-03-31: 1Exploit Tool / Code · 2026-04-01: 21Exploit Tool / Code · 2026-04-02: 3Exploit Tool / Code · 2026-04-04: 4Exploit Tool / Code · 2026-04-05: 4Exploit Tool / Code · 2026-04-07: 1Exploit Tool / Code · 2026-04-11: 1Exploit Tool / Code · 2026-05-23: 1Exploit Tool / Code · 2026-08-19: 2Active Exploitation · 2026-03-27: 1Active Exploitation · 2026-03-31: 1Active Exploitation · 2026-04-01: 4Active Exploitation · 2026-04-03: 2Active Exploitation · 2026-04-04: 2Active Exploitation · 2026-04-05: 2Active Exploitation · 2026-04-07: 1Active Exploitation · 2026-04-09: 1Active Exploitation · 2026-04-10: 1Active Exploitation · 2026-05-11: 1Active Exploitation · 2026-05-12: 2Active Exploitation · 2026-05-23: 1Active Exploitation · 2026-07-30: 2Active Exploitation · 2026-08-19: 2Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-04-01: 6Patch / Workaround · 2026-04-04: 1Patch / Workaround · 2026-04-08: 1Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-04-15: 1Patch / Workaround · 2026-07-30: 1Technical Details · 2026-03-26: 2Technical Details · 2026-03-31: 5Technical Details · 2026-04-01: 30Technical Details · 2026-04-02: 5Technical Details · 2026-04-03: 3Technical Details · 2026-04-04: 7Technical Details · 2026-04-05: 4Technical Details · 2026-04-06: 1Technical Details · 2026-04-07: 4Technical Details · 2026-04-08: 4Technical Details · 2026-04-09: 3Technical Details · 2026-04-10: 4Technical Details · 2026-04-11: 1Technical Details · 2026-04-12: 2Technical Details · 2026-04-15: 1Technical Details · 2026-04-16: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-20: 1Technical Details · 2026-04-21: 1Technical Details · 2026-05-03: 2Technical Details · 2026-05-09: 2Technical Details · 2026-05-12: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-16: 1Technical Details · 2026-05-23: 1Technical Details · 2026-05-24: 1Technical Details · 2026-05-26: 1Technical Details · 2026-05-27: 2Technical Details · 2026-06-04: 1Technical Details · 2026-07-13: 2Technical Details · 2026-07-29: 1Technical Details · 2026-07-30: 2Technical Details · 2026-08-19: 403-2604-0204-0604-1004-1504-2105-0905-1605-2707-1309-0609-29
Signal classification7 categories
PoC
3624.0%
General
3322.0%
Exploit
3120.7%
Disclosure
2617.3%
Active Exploitation
1812.0%
False Positive
42.7%
Referenced assets47 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-263
Disclosure2General1
2026-03-271
Active Exploitation1
2026-03-315
Disclosure1Exploit1Patch1PoC2
2026-04-0135
Active Exploitation2Disclosure4Exploit14General1PoC14
2026-04-027
Exploit2General1PoC4
2026-04-035
Active Exploitation2Disclosure2PoC1
2026-04-049
Active Exploitation2Exploit4PoC3
2026-04-058
Active Exploitation1Disclosure1Exploit3PoC3
2026-04-062
Disclosure1General1
2026-04-075
Active Exploitation1Disclosure1Exploit2General1
2026-04-089
Disclosure2False Positive1General5PoC1
2026-04-093
Active Exploitation1General1Patch1
2026-04-105
Active Exploitation1Disclosure1Exploit2General1
2026-04-111
Exploit1
2026-04-124
Disclosure1General3
2026-04-141
Disclosure1
2026-04-154
General4
2026-04-163
Disclosure1General2
2026-04-191
General1
2026-04-201
Disclosure1
2026-04-213
Disclosure1False Positive2
2026-04-221
General1
2026-05-032
PoC2
2026-05-081
General1
2026-05-093
Disclosure1General1PoC1
2026-05-111
Active Exploitation1
2026-05-125
Active Exploitation2Disclosure1False Positive1General1
2026-05-132
General1PoC1
2026-05-161
Disclosure1
2026-05-231
Exploit1
2026-05-241
Disclosure1
2026-05-261
PoC1
2026-05-272
Disclosure1PoC1
2026-05-301
General1
2026-06-042
General2
2026-06-061
General1
2026-07-132
Disclosure1PoC1
2026-07-291
General1
2026-07-302
Active Exploitation2
2026-08-194
Active Exploitation2Exploit1PoC1
2026-09-061
General1
Full discourse20 posts
  • Calif@calif_io
    PoC

    MAD Bugs: Claude Wrote a Full FreeBSD Remote Kernel RCE with Root Shell (CVE-2026-4747) To our knowledge, this is the first remote kernel exploit both discovered and exploited by an AI. https://blog.calif.io/p/mad-bugs-claude-wrote-a-full-freebsd

    Post summary

    A blog post announces an AI‑generated Proof of Concept for a FreeBSD kernel remote code execution vulnerability (CVE‑2026‑4747), describing the exploit as a root‑shell capable RCE, but without reporting real‑world exploitation or available patches.

    141192053327786.9K
    5.0K followersView on X
  • payloadartist@payloadartist
    Disclosure

    Claude wrote a Full FreeBSD Remote Kernel RCE with Root Shell (CVE-2026-4747) https://blog.calif.io/p/mad-bugs-claude-wrote-a-full-freebsd (by Calif team) https://t.co/GZC78ShKJL

    Post summary

    The tweet announces the discovery of CVE‑2026‑4747, a FreeBSD kernel remote code execution that provides a root shell, and directs readers to a blog post that likely contains further details or a PoC.

    1190454226735.4K
    45.6K followersView on X
  • Stanislav Fort@stanislavfort
    Disclosure

    New post: We show that small, cheap models can detect the flagship Mythos FreeBSD zero-day (CVE-2026-4747) using a simple harness we call nano-analyzer Models down to 3.6B active params (including open-weights ones you can run locally) would have detected it 100-1000x cheaper https://t.co/vsfQDioAQu

    Post summary

    The post announces that small, open‑weight models can detect the Mythos FreeBSD zero‑day CVE‑2026‑4747 using a nano‑analyzer harness, with no evidence of exploitation or patch.

    20661634621398.6K
    16.7K followersView on X
  • thaidn@XorNinja
    PoC

    MAD Bugs: Claude Wrote a Full FreeBSD Remote Kernel RCE with Root Shell (CVE-2026-4747) To our knowledge, this is the first remote kernel exploit both discovered and exploited by an AI. https://blog.calif.io/p/mad-bugs-claude-wrote-a-full-freebsd

    Post summary

    The post announces that an AI has discovered and demonstratively exploited a Full FreeBSD Remote Kernel RCE (CVE‑2026‑4747), but it provides no explicit PoC code or patch information.

    537819911991.9K
    6.0K followersView on X
  • Intel@intel
    Active Exploitation

    Does the thought of AI finding and exploiting vulnerabilities that have been in the code for years keep you up at night? CVE-2026-4747, a 17-year-old remote code execution vulnerability in @FreeBSD, was autonomously exploited by Mythos. Here’s the good news to help you sleep better: Intel introduced Intel Control-Flow Enforcement Technology (Intel CET) into its platforms in 2020. Intel CET stops this and similar classes of exploit. After you ensure built-in platform protections are enabled, go and get some rest. Read the blog to understand Intel’s approach to a software robustness defense-in-depth stack: http://ms.spr.ly/6014a6WUK

    Post summary

    The post announces that CVE-2026-4747, an old RCE in FreeBSD, was actively exploited by Mythos, and recommends enabling Intel CET as a mitigation.

    124531491233.4K
    4.5M followersView on X
  • Seyfullah KILIÇ@s3yfullah
    Exploit

    http://Claude.ai tam 8 saatte FreeBSD kernel'inde remote RCE exploit'i yazdı ve root shell aldı! CVE-2026-4747 için hem vulnerability'yi exploit etti hem de çalışan Python script'ini çıkardı. İnsan müdahalesi neredeyse sıfır. AI'lerin exploit development'ta da insan seviyesine geldiğinin kanıtı. Okuması gereken herkes için: https://blog.calif.io/p/mad-bugs-claude-wrote-a-full-freebsd

    Post summary

    Claude.ai is claimed to have produced a functional remote RCE exploit for CVE‑2026‑4747, delivering a working Python script that grants a root shell on FreeBSD, as described in an online blog article.

    180789210.6K
    3.5K followersView on X
  • 探姬 | Hello-CTF 🚩@ProbiusOfficial
    General

    CVE-2026-4747 —— 人fuzz出来的都是垃圾洞,但这个不一样,这是高贵的AI大人fuzz出来的,你们这群人类不要不识好歹! https://t.co/NuMW2TLa92

    Post summary

    The tweet briefly mentions CVE-2026-4747 as discovered by AI fuzzing, without providing technical details, PoC, patches, or exploitation evidence.

    8621332727.2K
    9.5K followersView on X
  • 13.02 JB Countdown ⌛@dieramires
    Disclosure

    FreeBSD just got hit with a 17-year-old RCE bug (CVE-2026-4747), found and exploited autonomously by an AI. PS4 runs on a customized FreeBSD kernel. Nobody's confirmed a PS4 exploit chain from this - but we might be in for some big surprises soon. ps4 13.02 jb hen homebrew https://t.co/dznR6EEFbi

    Post summary

    A 17‑year‑old RCE vulnerability (CVE-2026-4747) in FreeBSD was discovered and autonomously exploited by an AI, potentially impacting PS4 systems, but no confirmed exploit chain, patch, or PoC details are provided.

    171791012.0K
    756 followersView on X
  • 13.02 JB Countdown ⌛@dieramires
    PoC

    Anthropic's Mythos Preview found a previously undiscovered 27-year-old OpenBSD flaw and wrote a full RCE exploit for FreeBSD's NFS server (CVE-2026-4747). PS4 runs on FreeBSD — no confirmed exploit link yet, but the jailbreak scene is watching. tickets: ps4 13.02 13.04 jb hen https://t.co/F2jTAJPR7d

    Post summary

    Anthropic’s Mythos Preview uncovered a decades‑old OpenBSD flaw and claims to have written a full RCE exploit for FreeBSD’s NFS server (CVE‑2026‑4747), yet no public exploit link has been released and the jailbreak community is keeping an eye on the situation.

    92077915.3K
    756 followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    MAD Bugs: Claude Wrote a Full FreeBSD Remote Kernel RCE with Root Shell (CVE-2026-4747) https://github.com/califio/publications/blob/main/MADBugs/CVE-2026-4747/write-up.md

    Post summary

    Claude released a full remote kernel RCE proof‑of‑concept for FreeBSD (CVE‑2026‑4747) that delivers a root shell, with details available on GitHub; no evidence of active exploitation or patching is noted.

    011042214.2K
    157.2K followersView on X
  • yousukezan@yousukezan
    Exploit

    FreeBSDにおけるカーネル脆弱性(CVE-2026-4747)を悪用し、リモートからroot権限を奪取することができた。 原因は、RPCSEC_GSS認証処理で使用される固定長バッファに対し、入力サイズの検証がなく、スタックオーバーフローが発生する点にある。 これによりリターンアドレスを書き換え、カーネル内で任意コード実行が可能となる。 攻撃にはKerberos認証が必要で、正規ユーザ権限でも悪用できる。エクスプロイトは複数回のリクエストで構成され、ROPチェーンを使ってカーネルメモリにシェルコードを書き込み、最終的に実行する。シェルコードは新たなプロセスを生成し、/bin/shを実行することでrootのリバースシェルを取得する。 攻撃はNFSサービス(ポート2049)経由で成立し、複数スレッドを消費しながら段階的に進行する。最終的に完全なカーネルレベルのリモートコード実行が可能となる重大な脆弱性であり、修正は境界チェックの追加で対応されている。 https://github.com/califio/publications/blob/main/MADBugs/CVE-2026-4747/write-up.md

    Post summary

    The write‑up details how CVE-2026-4747 allows remote kernel‑level code execution on FreeBSD via a stack overflow in RPCSEC_GSS, includes PoC and exploit methodology, and notes a boundary‑check patch.

    01613553.2K
    14.3K followersView on X
  • hacker.house@hackerfantastic
    Exploit

    Ouch, Claude wrote (from a prompt) a complete FreeBSD kernel n-day RCE exploit from an advisory, stack overflow, best conditions for it - debugged and completed it in under a day. This is goated and we are cooked. https://github.com/califio/publications/blob/main/MADBugs/CVE-2026-4747/exploit.py

    Post summary

    A functional exploit for FreeBSD kernel CVE-2026-4747 has been coded, debugged, and made publicly available on GitHub, indicating readiness for use, but there is no evidence of current in‑the‑wild exploitation or a vendor patch.

    0201981.7K
    105.4K followersView on X
  • clearbluejar@clearbluejar
    General

    Latest post showing once again the power of system over model 👀 See how Gemma 4 31b performs trying to find CVE-2026-4747 : the same FreeBSD RCE that Mythos found and AISLE rediscovered with local models https://t.co/GxIFxkEy8r

    Post summary

    The tweet references the FreeBSD RCE CVE-2026-4747 but offers no PoC, exploit, or mitigation details, merely noting the model’s detection of it.

    14011101.0K
    2.2K followersView on X
  • Pierre Beyssac 🏴‍☠️🇫🇷🇪🇺🇺🇦@pbeyssac
    General

    Let's temper the FreeBSD bit down a notch (CVE-2026-4747). It *is* remote code execution, it *is* really impressive and serious, but it won't work from "anywhere on the Internet": you would have to be batshit crazy to open an unfiltered NFS server over the Internet. https://t.co/44GxjEgjw7

    Post summary

    The text highlights the CVE-2026-4747 as a remote code execution flaw in FreeBSD, noting its practical limitation that it requires an unfiltered NFS server exposed to the Internet, and does not provide a PoC, exploit, patch, or live exploitation evidence.

    1501611.7K
    23.8K followersView on X
  • Swissky@pentest_swissky
    Exploit

    MAD Bugs: Claude Wrote a Full FreeBSD Remote Kernel RCE with Root Shell (CVE-2026-4747) - calif https://blog.calif.io/p/mad-bugs-claude-wrote-a-full-freebsd

    Post summary

    The content highlights that CVE‑2026‑4747 is a fully exploitable remote kernel RCE on FreeBSD, with a provided proof‑of‑concept code and root shell capabilities, but it does not mention active exploitation or a patch.

    0301191.7K
    21.6K followersView on X
  • Kelsey Piper@KelseyTuoc
    General

    @atoherbert @Underfox3 There's a CVE listed for the FreeBSD vuln: CVE-2026-4747. But my understanding is that these are assigned by project maintainers, not by Anthropic.

    Post summary

    The post only notes the existence of a CVE for a FreeBSD vulnerability, without providing any further technical details or context.

    100201679
    64.9K followersView on X
  • Clandestine@akaclandestine
    PoC

    MAD Bugs: Claude Wrote a Full FreeBSD Remote Kernel RCE with Root Shell (CVE-2026-4747) https://blog.calif.io/p/mad-bugs-claude-wrote-a-full-freebsd

    Post summary

    The blog announces that Claude authored a complete proof‑of‑concept demonstrating a FreeBSD kernel remote code execution that spawns a root shell, identified as CVE‑2026‑4747.

    0311441.9K
    61.1K followersView on X
  • Agus 🔸@austinc3301
    Exploit

    It also found a 17-year-old remote code execution bug in FreeBSD's NFS server (CVE-2026-4747). It gives full root access to any unauthenticated user on the network. Mythos found it and built a working exploit, fully autonomously. https://t.co/9Wba5z9YQo

    Post summary

    The tweet announces the discovery of CVE-2026-4747, a remote code execution flaw in FreeBSD’s NFS server, and notes that Mythos built and released a working exploit, though no evidence of wild exploitation or patching is provided.

    200161546
    6.9K followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    MAD Bugs: Claude Wrote a Full FreeBSD Remote Kernel RCE with Root Shell (CVE-2026-4747) https://blog.calif.io/p/mad-bugs-claude-wrote-a-full-freebsd

    Post summary

    The post announces CVE-2026‑4747, a Remote Kernel RCE in FreeBSD that grants a root shell, with a link to a blog that most likely includes PoC details, but does not mention active exploitation, patches, or debunking.

    010104877
    33.3K followersView on X
  • White Rabbitx@TheRabbitPy
    Exploit

    🚨 Anthropic's Claude AI cracks FreeBSD kernel in 4 hours: Researcher Nicholas Carlini used it to build full RCE exploit (CVE-2026-4747) from vuln desc. Stack buffer overflow in RPCSEC_GSS (Kerberos/NFS), ROP chain → root shell. Set up QEMU env, debugged offsets/registers autonomously! https://www.notebookcheck.com/Claude-code-knackt-FreeBSD-innerhalb-von-vier-Stunden.1265808.0.html

    Post summary

    A full RCE exploit for CVE-2026-4747 was built by researcher Nicholas Carlini using Anthropic's Claude AI, exploiting a stack buffer overflow in RPCSEC_GSS, achieving root shell in under four hours.

    04080192
    1.4K followersView on X
CPE platform detail29 entries

29 of 29 entries

PartVendorProductVersionTarget SWTarget HW
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--

Explore more