
Can agents find and exploit a Linux kernel bug? Where does autonomy break down? XBOW uncovered what human researchers had largely missed: a vulnerability buried deep in the Linux kernel—and took it all the way to a working LPE exploit. CVE-2026-72018: an out-of-bounds write vulnerability in the Linux kernel that can be triggered by an unprivileged user with administrative network capabilities (CAP_NET_ADMIN), providing a primitive that can be leveraged for local privilege escalation to root. 🧵 1/ The exploit reaching a shell as root (uid=0).






