CVE-2026-74480Exploit

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 7 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: net: bridge: stop fast-leave after deleting a port group br_multicast_leave_group() iterates mp->ports with pp = &p->next in its fast-leave path. After br_multicast_del_pg() removes p, continuing the loop advances pp through the deleted entry. If multicast-to-unicast was enabled, the bridge can hold multiple port groups for the same port and group with different source MAC addresses. Once multicast-to-unicast is disabled, br_port_group_equal() matches those entries by port only. A fast leave can then delete one entry and continue from its stale next pointer, leaving mp->ports pointing at a deleted port group. Fast leave only needs to remove one matching port group. Break after br_multicast_del_pg() so the loop stops before dereferencing the removed entry.

7.5/ 10 priority

Sources & remediation

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 11 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 9 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 7 mentions (2026-08-24); latest day: 1
  • 11 total mentions across 5 days

Deep dive

Activity timeline11 mentions / 5d
02457Mentions · 2026-08-24: 7Mentions · 2026-08-25: 1Mentions · 2026-08-31: 1Mentions · 2026-09-12: 1Mentions · 2026-09-15: 1PoC Mentioned / Linked · 2026-08-24: 4PoC Mentioned / Linked · 2026-08-25: 1PoC Mentioned / Linked · 2026-08-31: 1Exploit Tool / Code · 2026-08-24: 4Exploit Tool / Code · 2026-08-25: 1Exploit Tool / Code · 2026-08-31: 1Active Exploitation · 2026-09-12: 1Patch / Workaround · 2026-08-24: 2Patch / Workaround · 2026-09-15: 1Technical Details · 2026-08-24: 6Technical Details · 2026-08-25: 1Technical Details · 2026-08-31: 1Technical Details · 2026-09-15: 108-2408-2508-3109-1209-15
Signal classification5 categories
Exploit
327.3%
Disclosure
218.2%
General
218.2%
Patch
218.2%
PoC
218.2%
Referenced assets18 URLs
Classification over time
DateTotalLabels
2026-08-247
Disclosure2Exploit3General1Patch1
2026-08-251
PoC1
2026-08-311
PoC1
2026-09-121
General1
2026-09-151
Patch1
Full discourse11 posts
  • Nebula Security@nebusecurity
    Exploit

    Today's exploit is for the latest Red Hat Enterprise Linux 10.2, a UAF in net bridge, CVE-2026-74480. It was introduced in Jan 2017 and fixed upstream in Jul 2026. Discovered and exploited by the NebuSec security pipeline. Exp source code: https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-74480-RHEL-10.2 https://t.co/XXSIDNtalX

    Post summary

    The tweet announces a functional exploit for CVE‑2026‑74480, a UAF in RHEL 10.2’s net bridge, and links directly to the source code repository, with no evidence of wild exploitation or vendor mitigation.

    2152103328.4K
    6.9K followersView on X
  • yousukezan@yousukezan
    Disclosure

    Linuxカーネルのネットワークブリッジ機能に、ローカル権限昇格につながるuse-after-free脆弱性「CVE-2026-74480」が見つかった。Nebula Securityはroot権限取得を実証するPoCとデモ動画を公開している。 問題はマルチキャストのfast-leave処理にあり、ポートグループを削除した後も同じオブジェクトへアクセスできることでuse-after-freeが発生する。multicast-to-unicastを有効化後に無効化すると、ポートだけが一致する重複したポートグループが残る場合があり、メモリ破壊やシステムクラッシュ、権限昇格につながるという。 脆弱性は2017年1月までさかのぼり、多くの長期サポート系カーネルが影響を受ける可能性がある。上流では2026年7月に修正され、該当ポートグループを削除した後にループを終了する変更が加えられた。Nebula SecurityはRHEL 10.2を対象としたPoCをGitHubで公開している。記事によると、現時点で実際の攻撃で悪用された事例は確認されていない。 https://securityonline.info/linux-cve-2026-74480/

    Post summary

    The article announces CVE‑2026‑74480, a local privilege‑escalation use‑after‑free in the Linux kernel network bridge, shares PoC and patch details, and notes no active exploitation to date.

    09027133.8K
    16.0K followersView on X
  • Frank Wu@FrankOverF1ow
    General

    9 (almost 10) year old LPE. CVSS scores it at 9.8, while RHEL rates it as “Moderate”... https://access.redhat.com/security/cve/cve-2026-74480

    Post summary

    The post highlights an older local privilege escalation vulnerability with a high CVSS score but offers no PoC, exploitation details, or remediation information, merely linking to a Red‑Hat advisory.

    0203262.6K
    1.8K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-74480 Vendor: Linux Product: Linux Kernel Description: A use-after-free issue exists in the net bridge component of the Linux kernel. The problem occurs in the br multicast leave group() function during the fast-leave path. When br multicast del pg() removes a port group, the loop continues to advance through the deleted entry using a stale next pointer. This is particularly relevant when multicast-to-unicast is disabled, as br port group equal() matches entries by port only, potentially leaving the mp->ports pointer referencing a deleted port group. This flaw can be exploited to achieve privilege escalation. Link: https://github.com/NebuSec/CyberMeowfia/blob/main/security-research/Linux-CVE-2026-74480-RHEL-10.2/exploit.c #dbugs_vuln

    Post summary

    The post announces a discovered PoC with a GitHub link for CVE-2026-74480, detailing a kernel use-after-free flaw that can lead to privilege escalation, but does not mention active attacks or patch status.

    010122858
    3.6K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Exploit

    CVE-2026-74480 (CVSS 9.8) enables Linux kernel privilege escalation via a bridge use-after-free. Exploit code and a demo are now public. #Linux #CVE202674480 #PrivilegeEscalation #KernelSecurity #CyberSecurity #InfoSec http://securityonline.info/linux-cve-2026-74480/

    Post summary

    CVE‑2026‑74480 is a Linux kernel privilege‑escalation flaw with a publicly released exploit and demo, highlighting its immediate exploitability.

    030101639
    13.0K followersView on X
  • Mr. OS@ksg93rd
    General

    #Analytics #Threat_Research An analytical review of the main cybersecurity events (Sep 05-12, 2026) 1⃣ Sonicwall SMA1000 Attack https://hunt.io/blog/sonicwall-sma1000-uk-council-attack // CVE-2026-15409 2⃣ Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://hunt.io/blog/sonicwall-sma1000-uk-council-attack 3⃣ Next Nightmare Eclipse Vulnerability https://github.com/MSNightmare/ShieldCrash/blob/main/README.md // Microsoft has failed to properly patch ShieldBreak CVE-2026-69414.. 4⃣ FortiPAM Vulnerability https://amibeingpwned.com/blog/fortinet-pam-vuln // CVE-2026-84388 5⃣ Researchers from Nebula Security have disclosed 18 vulnerabilities in the Linux kernel https://www.openwall.com/lists/oss-security/2026/09/08/1 // CVE-2026-80714, CVE-2026-74597, CVE-2026-74581, CVE-2026-74480, CVE-2026-72255, CVE-2026-72137, CVE-2026-68376, CVE-2026-68162, CVE-2026-64560,  CVE-2026-63834, CVE-2026-52933, CVE-2026-52929, CVE-2026-52924, CVE-2026-52923, CVE-2026-52912, CVE-2026-43501, CVE-2026-43502, CVE-2026-43074, CVE-2026-43042, CVE-2026-31678, CVE-2026-31659, CVE-2026-23274 6⃣ Netscaler ADC Exploit 7⃣ Critical vulnerabilities in MikroTik RouterOS https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/ 8⃣ GRAYRABBIT One-click backdoor // One click. Three critical failures. One backdoor https://www.gendigital.com/blog/insights/research/one-click-backdoor-sogou 9⃣ Attacks using browser-in-browser (BiTB) phishing techniques https://www.huntress.com/blog/phishing-bitb-rmm-attacks 🔟 Beltdown: Escaping the Claude Code sandbox https://www.accomplish.ai/blog/beltdown-escaping-the-claude-code-sandbox/ // An untrusted repository opened in Claude Code can escape the macOS sandbox and run commands on your computer as your privileged user http://www.Geniebot.pro http://www.cyberpocket.org

    Post summary

    The tweet is an analytic roundup of recent events, providing CVE IDs and links to coverage, with a single mention of active exploitation but lacking detailed PoCs, exploit code, patches, or vulnerability specifics.

    01052600
    3.4K followersView on X
  • Cyber Meowfia@cybermeowfia
    PoC

    Aug 23: Today's exploit is for the latest Red Hat Enterprise Linux 10.2, a UAF in net bridge, CVE-2026-74480. It was introduced in Jan 2017 and fixed upstream in Jul 2026. Discovered and exploited by the NebuSec security pipeline. Exp source code: https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-74480-RHEL-6.12.0-211.7.3.el10_2 https://t.co/tXF6Nt9lVa

    Post summary

    The tweet announces CVE-2026-74480, a UAF in net bridge for RHEL 10.2, and shares GitHub source code for a proof-of-concept exploit. It notes the vulnerability was introduced in Jan 2017 and fixed upstream in Jul 2026, but does not report active in-the-wild exploitation.

    00050499
    439 followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Exploit

    🔴 Nebula Security, RHEL 10.2'yi etkileyen CVE-2026-74480 için çalışan bir PoC exploit yayınladı. Linux kernel'in network bridge kodundaki UAF açığı, belirli koşullarda kernel belleğinin bozulmasına yol açabiliyor. PoC: https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-74480-RHEL-10.2 https://x.com/nebusecurity/status/2091786812981387550/video/1

    Post summary

    Nebula Security has released a working PoC exploit for CVE-2026-74480 that targets RHEL 10.2, demonstrating a use‑after‑free in the kernel’s network bridge code that can corrupt memory.

    00012269
    1.9K followersView on X
  • Threat Landscape@LandscapeThreat
    Patch

    Researchers disclosed CVE-2026-43502, a Linux kernel local privilege-escalation vulnerability in the RDS zerocopy send path, alongside 20 additional exploitable Linux bugs. - An unprivileged local user can obtain root privileges without Linux capabilities or user namespaces when required networking, asynchronous I/O, and RDS components are enabled. - The vulnerability affects kernels from Linux v4.17 and was demonstrated on openSUSE with kernel 6.4.0-150600.23.100. - The issue was fixed by commit 44b550d88b26, first included in Linux v7.1-rc3; public exploits for the listed vulnerabilities are available. VULNERABILITY CVE-2026-23274 CVE-2026-31659 CVE-2026-31678 CVE-2026-43042 CVE-2026-43074 CVE-2026-43501 CVE-2026-43502 CVE-2026-52912 CVE-2026-52923 CVE-2026-52924 CVE-2026-52929 CVE-2026-52933 CVE-2026-63834 CVE-2026-64560 CVE-2026-68162 CVE-2026-68376 CVE-2026-72137 CVE-2026-72255 CVE-2026-74480 CVE-2026-74581 CVE-2026-74597 CVE-2026-80714

    Post summary

    Researchers disclosed CVE‑2026‑43502 as a Linux kernel local privilege‑escalation bug in the RDS zerocopy path, describing its impact and confirming a fix in Linux v7.1‑rc3 (commit 44b550d88b26); a set of 20+ Linux vulnerabilities, including CVE‑2026‑43502, are noted to have public exploits available.

    0002055
    98 followersView on X
  • moton@moton
    Disclosure

    CVE-2026-74480 (CVSS 9.8): Linux Kernel Privesc - https://securityonline.info/linux-cve-2026-74480/

    Post summary

    The entry announces CVE‑2026‑74480, a high‑severity Linux kernel privilege escalation flaw, providing limited technical details and a link to further information.

    0000177
    753 followersView on X
  • OS開発者@hacker_infra
    Patch

    Red hat とAlmalinuxに報告 緩和策は echo 'install bridge /bin/false' > /etc/modprobe.d/disable-bridge.conf https://access.redhat.com/security/cve/cve-2026-74480 https://bugzilla.redhat.com/show_bug.cgi?id=2517046

    Post summary

    The post announces mitigation instructions for CVE‑2026‑74480 on Red Hat and AlmaLinux, offering a workaround via modprobe configuration, but gives no further technical details, PoC, or exploitation evidence.

    00010490
    2.9K followersView on X

Explore more