Drooid Logo
Back to today’s briefing

Story perspectives

CISA Flags Critical Linux Root Flaw, Mandates May Patch

5/4/2026

45 10 Full Breakdown

1 of 1

Story summary
  • CISA added Linux flaw CVE-2026-31431 to its KEV catalog after confirming active exploitation.
  • The CVSS-7.8 bug, affecting Linux distributions since 2018 and stemming from bugs introduced in 2011, 2015 and 2017, lets an unprivileged user obtain root via a 732-byte Python payload that exploits it with system calls.
  • Patches for kernel versions 6.18.22, 6.19.12 and 7.0 are available, requiring agencies to patch by May 15 2026 or disable the feature per CISA.