CVE-2026-74581Patch

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: net: ipv6: clear suppressed fib6 rule result fib6_rule_suppress() drops a suppressed route with ip6_rt_put_flags(), but leaves res->rt6 pointing at the released rt6_info. If no later rule supplies a replacement, fib6_rule_lookup() still sees res.rt6 and returns that stale dst to its caller. A suppressing rule can therefore leak a released route back to rt6_lookup(), and the next put hits rcuref_put_slowpath() from dst_release(). Clear res->rt6 when suppressing the route so suppressed lookups fall through to the null dst instead of reusing the released one.

7.5/ 10 priority

Sources & remediation

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 9 mentions across 6 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 5d ago at 4 mentions (2026-08-21); latest day: 1
  • 9 total mentions across 6 days

Deep dive

Activity timeline9 mentions / 6d
01234Mentions · 2026-08-21: 4Mentions · 2026-08-22: 1Mentions · 2026-08-24: 1Mentions · 2026-08-31: 1Mentions · 2026-09-12: 1Mentions · 2026-09-15: 1PoC Mentioned / Linked · 2026-08-31: 1Exploit Tool / Code · 2026-08-31: 1Active Exploitation · 2026-09-12: 1Patch / Workaround · 2026-08-21: 2Patch / Workaround · 2026-08-22: 1Patch / Workaround · 2026-08-24: 1Patch / Workaround · 2026-08-31: 1Patch / Workaround · 2026-09-15: 1Technical Details · 2026-08-21: 2Technical Details · 2026-09-15: 108-2108-2208-2408-3109-1209-15
Signal classification5 categories
Patch
555.6%
Disclosure
111.1%
General
111.1%
Exploit
111.1%
Active Exploitation
111.1%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-08-214
Disclosure1General1Patch2
2026-08-221
Patch1
2026-08-241
Patch1
2026-08-311
Exploit1
2026-09-121
Active Exploitation1
2026-09-151
Patch1
Full discourse9 posts
  • OS開発者@hacker_infra
    Patch

    Hi OS開発者 Your technical point is correct. Blacklisting ipv6 is ineffective on all supported RHEL versions because IPv6 is compiled directly into the kernel (CONFIG_IPV6=y), not as a loadable module. The Red Hat CVE page will be updated to reflect the corrected mitigation guidance: https://access.redhat.com/security/cve/cve-2026-74581 Thanks, 俺がただしかったわけだ

    Post summary

    The post clarifies that blacklisting IPv6 does not mitigate CVE‑2026‑74581 on RHEL because IPv6 is built into the kernel, and Red Hat will update its mitigation guidance accordingly.

    0201682.8K
    2.9K followersView on X
  • Cyber Meowfia@cybermeowfia
    Exploit

    Aug 19: Exploit for the latest Debian 13 (6.12.101), CVE-2026-74581. It was fixed upstream and backported to 6.12.103 Discovered and exploited by the NebuSec security pipeline. Exploit source code: https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-74581-Debian-6.12.101 https://t.co/q2FuprsPeT

    Post summary

    A GitHub-hosted exploit for CVE-2026-74581 (Debian 13 kernel) is shared by NebuSec, with an upstream fix backported to 6.12.103; in-the-wild exploitation is not confirmed.

    040121906
    439 followersView on X
  • OS開発者@hacker_infra
    Patch

    jiraに報告したのがcve-2026-74581になった 緩和策がipv6の無効化。 grubby --update-kernel=ALL --args="ipv6.disable=1" reboot systctl でカーネルパラメーターを無効化する人おるけど、それインターフェースだけだからな。攻撃のベクトルが隣接ネットワークとかならいいけど 完全無効化じゃないからな。ローカルからは以前として攻撃を受ける https://access.redhat.com/security/cve/cve-2026-74581

    Post summary

    The post identifies CVE‑2026‑74581 and recommends disabling IPv6 as a mitigation, but offers no evidence of active exploitation, exploit tools, or detailed technical information.

    011711.7K
    2.9K followersView on X
  • Mr. OS@ksg93rd
    Active Exploitation

    #Analytics #Threat_Research An analytical review of the main cybersecurity events (Sep 05-12, 2026) 1⃣ Sonicwall SMA1000 Attack https://hunt.io/blog/sonicwall-sma1000-uk-council-attack // CVE-2026-15409 2⃣ Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://hunt.io/blog/sonicwall-sma1000-uk-council-attack 3⃣ Next Nightmare Eclipse Vulnerability https://github.com/MSNightmare/ShieldCrash/blob/main/README.md // Microsoft has failed to properly patch ShieldBreak CVE-2026-69414.. 4⃣ FortiPAM Vulnerability https://amibeingpwned.com/blog/fortinet-pam-vuln // CVE-2026-84388 5⃣ Researchers from Nebula Security have disclosed 18 vulnerabilities in the Linux kernel https://www.openwall.com/lists/oss-security/2026/09/08/1 // CVE-2026-80714, CVE-2026-74597, CVE-2026-74581, CVE-2026-74480, CVE-2026-72255, CVE-2026-72137, CVE-2026-68376, CVE-2026-68162, CVE-2026-64560,  CVE-2026-63834, CVE-2026-52933, CVE-2026-52929, CVE-2026-52924, CVE-2026-52923, CVE-2026-52912, CVE-2026-43501, CVE-2026-43502, CVE-2026-43074, CVE-2026-43042, CVE-2026-31678, CVE-2026-31659, CVE-2026-23274 6⃣ Netscaler ADC Exploit 7⃣ Critical vulnerabilities in MikroTik RouterOS https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/ 8⃣ GRAYRABBIT One-click backdoor // One click. Three critical failures. One backdoor https://www.gendigital.com/blog/insights/research/one-click-backdoor-sogou 9⃣ Attacks using browser-in-browser (BiTB) phishing techniques https://www.huntress.com/blog/phishing-bitb-rmm-attacks 🔟 Beltdown: Escaping the Claude Code sandbox https://www.accomplish.ai/blog/beltdown-escaping-the-claude-code-sandbox/ // An untrusted repository opened in Claude Code can escape the macOS sandbox and run commands on your computer as your privileged user http://www.Geniebot.pro http://www.cyberpocket.org

    Post summary

    The tweet catalogs several recent CVEs and incident reports, indicating ongoing exploitation for at least a few, but it lacks detailed technical or mitigation information.

    01052600
    3.4K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-74581 In the Linux kernel, the following vulnerability has been resolved: net: ipv6: clear suppressed fib6 rule result fib6_rule_suppress() drops a suppressed route with … https://www.cve.org/CVERecord?id=CVE-2026-74581

    Post summary

    The post informs that CVE-2026-74581 has been fixed in the Linux kernel, providing technical details about the affected code, but contains no evidence of exploitation or a publicly available PoC.

    000311.6K
    58.1K followersView on X
  • Threat Landscape@LandscapeThreat
    Patch

    Researchers disclosed CVE-2026-43502, a Linux kernel local privilege-escalation vulnerability in the RDS zerocopy send path, alongside 20 additional exploitable Linux bugs. - An unprivileged local user can obtain root privileges without Linux capabilities or user namespaces when required networking, asynchronous I/O, and RDS components are enabled. - The vulnerability affects kernels from Linux v4.17 and was demonstrated on openSUSE with kernel 6.4.0-150600.23.100. - The issue was fixed by commit 44b550d88b26, first included in Linux v7.1-rc3; public exploits for the listed vulnerabilities are available. VULNERABILITY CVE-2026-23274 CVE-2026-31659 CVE-2026-31678 CVE-2026-43042 CVE-2026-43074 CVE-2026-43501 CVE-2026-43502 CVE-2026-52912 CVE-2026-52923 CVE-2026-52924 CVE-2026-52929 CVE-2026-52933 CVE-2026-63834 CVE-2026-64560 CVE-2026-68162 CVE-2026-68376 CVE-2026-72137 CVE-2026-72255 CVE-2026-74480 CVE-2026-74581 CVE-2026-74597 CVE-2026-80714

    Post summary

    Researchers disclosed CVE-2026-43502, a Linux kernel local privilege-escalation flaw in the RDS zerocopy send path, and noted it is patched via commit 44b550d88b26 (Linux v7.1-rc3). Public exploits for this and 20 other vulnerabilities are reported as available.

    0002055
    91 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Linux Kernel (CVE-2026-74581) https://vuldb.com/vuln/394146

    Post summary

    A new critical Linux kernel vulnerability, CVE-2026-74581, has been announced, but no PoC, exploit, or patch information is provided.

    00000117
    2.3K followersView on X
  • OS開発者@hacker_infra
    General

    @aramosf assigned to CVE-2026-74581

    Post summary

    The tweet merely reports that a user has been assigned to CVE‑2026‑74581, with no additional details.

    0000033
    2.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-74581 In the Linux kernel, the following vulnerability has been resolved: net: ipv6: clear suppressed fib6 rule result fib6_rule_suppress() drops a suppressed route with … https://www.cve.org/CVERecord?id=CVE-2026-74581 ----- Traducción: CVE-2026-74581 En … http://infoflow.cloud`

    Post summary

    CVE-2026-74581, a Linux kernel weakness affecting IPv6 routing, has been fixed through a code change to fib6_rule_suppress; a patch is available.

    0000054
    102 followersView on X

Explore more