CVE- 2026-74480 is a critical privilege escalation vulnerability found in the Linux kernel's network bridge module, with a CVSS score of 9.8. Discovered by Nebula Security, this use-after-free bug allows local attackers to escalate privileges to root. Although public exploit code is available, no in-the-wild exploitation has been reported. The flaw affects multiple kernel versions since its introduction in January 2017 but has been patched in July 2026. Users are advised to update to the latest patched versions to mitigate the risk.
CVE-2026-74480: Linux kernel bridge flaw grants local root
CyberSIXT Evidence Panel
Article by CyberSIXT