Advisory ID: ngCERT-2026-090002
Damage: Critical
Probability: High
Platform(s): Kaspersky Endpoint Security version 14.0.0.504; Windows 11 Version 25H2
SUMMARY
ngCERT has observed the public release of HardBreacher, a proof-of-concept (PoC) that claims to exploit a Local Privilege Escalation (LPE) vulnerability in Kaspersky Endpoint Security for Windows. The PoC was tested on a fully patched Windows 11 Version 25H2 system running Kaspersky Endpoint Security Version 14.0.0.504 and may allow a low-privileged user to write a DLL to the protected C:\Windows\System32 directory. The vulnerability has not been assigned a CVE, and the publicly available PoC is unstable and has not been independently verified to provide reliable SYSTEM-level code execution. Kaspersky has addressed the underlying issue. Organisations using Kaspersky Endpoint Security are advised to verify the affected versions in their environments and ensure that the applicable vendor remediation has been applied.
DESCRIPTION
HardBreacher is a PoC that targets a LPE vulnerability in Kaspersky Endpoint Security for Windows. The PoC demonstrates the interaction between a standard Windows user and a privileged process, which may allow unauthorised file operations within the protected C:\Windows\System32 directory, including the creation of MY_SNAKE_IS_SOLID.dll with permissions accessible to the initiating user. The PoC was demonstrated on Windows 11 Version 25H2 with Kaspersky Endpoint Security Version 14.0.0.504 and requires local access or prior code execution on the endpoint. The exploit is unreliable and may require multiple attempts or a system reboot, while current analysis does not independently confirm dependable SYSTEM-level code execution, all affected product versions, or a CVE assignment. Public availability of the PoC could enable attackers to improve its reliability or combine the technique with other methods to achieve further privilege escalation, modify protected resources, disrupt endpoint security controls, or establish persistence. Organisations are advised to verify applicable vendor remediation and monitor for unauthorized DLL creation or modification, abnormal Kaspersky process activity, security-service disruptions, and suspicious privilege changes.
CONSEQUENCES
Successful exploitation could result in:
- Escalation of privileges from a standard user to SYSTEM-level access.
- Unauthorised modification of protected Windows system resources.
- Execution of malicious code with elevated privileges.
- Disruption or bypass of Kaspersky Endpoint Security controls.
- Establishment of persistence on affected endpoints.
- Exposure of sensitive data, credentials, and system resources.
- Potential lateral movement and further compromise of other organisational systems.
SOLUTION/MITIGATION
ngCERT recommends the following:
- Verify all endpoints running Kaspersky Endpoint Security and apply the applicable Kaspersky vendor remediation or security update, particularly Version 14.0.0.504.
- Keep Windows and Kaspersky Endpoint Security fully updated.
- Enforce least-privilege access and restrict unnecessary administrative privileges.
- Monitor C:\Windows\System32 for suspicious DLL creation or modification.
- Review EDR, SIEM, and Windows logs for abnormal activity and privilege changes.
- Do not execute the HardBreacher PoC on production systems.
- Isolate and investigate affected endpoints where exploitation is suspected.
HYPERLINK
- https://cyberpress.org/hardbreacher-poc-targets-kaspersky-endpoint-security-zero-day/
- https://gbhackers.com/hardbreacher-exploit-targets-kaspersky-endpoint-security/
- https://securityaffairs.com/198214/hacking/chaotic-eclipse-releases-kaspersky-zero-day-hardbreacher.html
- https://www.linkedin.com/pulse/hardbreacher-exploit-targets-kaspersky-endpoint-h5opc/
Advisory ID: ngCERT-2026-090003
Damage: Critical (CVSS Score: 9.8)
Probability: High
Platform(s): cPanel & WHM and WP Squared
SUMMARY
ngCERT is alerting organisations, businesses, government agencies, website administrators and hosting providers to a critical security vulnerability in cPanel & WHM and WP Squared. The vulnerability, tracked as (CVE-2026-65643), can allow an authenticated hosting customer who can add parked or add-on domains to create arbitrary files on the server. Successful exploitation could lead to code execution as the root user, giving an attacker full control of the server and every account, website and database hosted on it. The vulnerability is rated Critical with a CVSS Score of 9.8 and affects all supported versions of cPanel & WHM. Although patches have been released to fix the flaw, organisations and hosting providers are advised to treat this vulnerability as a high-priority patching requirement.
DESCRIPTION
CVE-2026-65643 is a critical vulnerability in the domain parking and add-on domain functionality of cPanel & WHM. An authenticated cPanel account holder who has permission to add parked or addon domains can exploit the flaw to create arbitrary files anywhere on the underlying server. This capability can be leveraged to achieve code execution as the root user. Domain parking is a routine feature enabled by default for most shared-hosting customers, meaning the attack surface is present on virtually every multi-tenant cPanel environment. Successful exploitation gives the attacker unrestricted control over the entire machine, including every other customer account, website, database and email service hosted on the same server. Affected products are all currently supported versions of cPanel & WHM below. However, the vendor has released security fixes in builds 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2 and later, and WP Squared 11.138.1.7 or later.
CONSEQUENCES
Successful exploitation could result to the following:
- Access to, modification and removal data belonging to every hosted account, website, application, and database.
- Deployment persistent backdoors and malware across all tenants.
- Theft of credentials, TLS certificates, and configuration secrets.
- Alteration of website content, server configurations, and service settings.
- Use of compromised server as a pivot point for further attack.
SOLUTION/MITIGATION
ngCERT recommends that organisations:
- Immediately update all affected systems to a patched build of cPanel & WHM (11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2 or later) or WP Squared (11.138.1.7 or later) using /scripts/upcp --force or the WHM upgrade interface.
- Prioritise multi-tenant shared and reseller servers for patching due to the elevated risk of cross-account compromise.
- Temporarily disable the Parked Domains and Addon Domains features in customer feature lists through WHM where immediate patching is not feasible.
- Verify the installed cPanel build on every server after updating and confirm it matches a patched version.
- Audit servers for signs of prior exploitation, including unexpected files outside home directories, unauthorised root processes, new privileged accounts, and anomalous network activity.
- Isolate any system showing indicators of compromise, preserve forensic evidence, and restore from known-good backups after removing malicious artefacts.
- Reset credentials for root, WHM, and all administrative accounts on systems that may have been exposed.
- Enforce least-privilege feature lists so that ordinary customer accounts cannot manage parked or addon domains unless operationally required.
- Enable automatic daily updates for cPanel where compatible with change-management processes to reduce exposure to future similar flaws.
- Maintain a current inventory of all cPanel and WP Squared instances, retain tested backups, and continuously monitor multi-tenant hosts for suspicious behaviour.
HYPERLINK
Advisory ID: ngCERT-2026-090005
Damage: Critical
Probability: High
Platform(s): CrowdStrike Falcon Sensor for Windows
SUMMARY
ngCERT has identified FalconFlank, a project that claims to exploit a local privilege escalation vulnerability in the CrowdStrike Falcon Sensor for Windows. The alleged flaw reportedly abuses the sensor’s Microsoft Office malicious macro remediation process and may allow a low-privileged local user to gain elevated privileges. Organisations using the affected functionality are advised to review their configurations and apply available mitigations.
DESCRIPTION
FalconFlank is a proof-of-concept released by security researcher Chaotic Eclipse, also known as Nightmare-Eclipse, MSNightmare and INFINITE NIGHTMARE, which reportedly targets the Microsoft Office file malicious macro removal functionality of CrowdStrike Falcon Sensor for Windows. According to the researcher, the technique abuses the Falcon Sensor’s privileged remediation process for Office files containing malicious macros, potentially allowing a low-privileged local user to escalate privileges to a higher-privileged context. The researcher claims the PoC works on fully updated Windows 11 version 25H2 and Windows Server 2025 systems running CrowdStrike Falcon with Phase 3 – Optimal Protection and the Microsoft Office file malicious macro removal feature enabled. CrowdStrike has stated that it is actively investigating the claims and has advised customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting, while noting that customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. The alleged vulnerability has not been independently verified, and no CVE identifier or CVSS score has been assigned at the time of this advisory.
CONSEQUENCES
Successful exploitation of the alleged vulnerability could allow an attacker to:
- Escalate from low-privileged user access to SYSTEM-level privileges.
- Execute unauthorised commands or applications with elevated privileges.
- Modify protected system files and resources.
- Bypass security restrictions applicable to standard user accounts.
- Establish persistence and conduct further malicious activities on affected endpoints.
SOLUTION/MITIGATION
Organisations using CrowdStrike Falcon Sensor on Windows systems are advised to:
- Temporarily disable the Microsoft Office File Suspicious Macro Removal Windows policy setting, where operationally feasible, in accordance with current CrowdStrike guidance.
- Maintain Cloud Anti-malware for Microsoft Office Files protection as recommended by CrowdStrike.
- Monitor official CrowdStrike security communications for further technical details, patches and confirmed remediation.
- Ensure CrowdStrike Falcon Sensor and Windows systems are maintained with the latest available updates.
- Monitor endpoints for unusual privilege-escalation activities, suspicious process execution and unexpected modifications to protected system locations.
- Review Falcon telemetry and endpoint security logs for indicators associated with the FalconFlank PoC.
- Apply the principle of least privilege and restrict unnecessary local administrative access.
- Conduct threat hunting on affected Windows endpoints, particularly systems where the Microsoft Office malicious macro removal functionality is enabled.
HYPERLINK
- https://cybersecuritynews.com/crowdstrike-falcon-0-day/
- https://thehackernews.com/2026/09/researcher-releases-falconflank-poc.html
- https://blog.rankiteo.com/cro1788416624-crowdstrike-vulnerability-september-2026/
- https://securityaffairs.com/198342/hacking/chaotic-eclipse-releases-crowdstrike-falcon-zeroday-falconflank.html
Advisory ID: ngCERT-2026-080009
Damage: Critical
Probability: High
Platform(s): Apache Tomcat 9.x, 10.1.x and 11.x
SUMMARY
ngCERT is aware of multiple vulnerabilities in Apache Tomcat affecting security-constraint processing, authentication, URL rewriting, HTTP/2, WebSocket sessions, and Unix Domain Socket permissions. The flaws include security-control bypasses and denial-of-service conditions, with significant vulnerabilities enabling security-constraint bypass, Rewrite-Valve access-control bypass, authentication fail-open behaviour, and HTTP/2 resource exhaustion. Accordingly, ngCERT strongly recommends that organisations identify affected Tomcat installations, assess their configurations, and upgrade to the latest supported releases,
Tomcat 11.0.25, 10.1.59, or 9.0.121, as applicable.
DESCRIPTION
The vulnerabilities affect multiple Apache Tomcat security mechanisms, including security constraints, authentication, URL rewriting, role authorisation, HTTP/2, WebSocket sessions and Unix Domain Sockets. They may allow attackers to bypass access controls, circumvent HTTP-method restrictions, exploit authentication fail-open conditions, replay DIGEST-authenticated requests, or gain unauthorised access to protected resources. Key flaws include CVE-2026-65182 and CVE-2026-65927 affecting security constraints and RewriteValve rules; CVE-2026-68569, CVE-2026-68525 and CVE-2026-66422 affecting authentication and authorisation; and CVE-2026-68763 and CVE-2026-65637 affecting HTTP/2 processing.
CVE-2026-65183 introduces a Unix Domain Socket race condition, while CVE-2026-73180 may allow authenticated WebSocket sessions to persist beyond their associated HTTP sessions. Apache has released fixes in Tomcat 11.0.25, 10.1.59 and 9.0.121. Organizations should review affected configurations, monitor for exploitation, and promptly upgrade vulnerable deployments to the appropriate fixed versions.
CONSEQUENCES
Successful exploitation of these vulnerabilities could lead to:
- Unauthorised Access
- Authentication Bypass
- Privilege Escalation
- Denial-of-Service
- Session Compromise
- Operational Disruption
SOLUTION/MITIGATION
ngCERT strongly advises the following actions:
- Upgrade affected Apache Tomcat installations to 11.0.25, 10.1.59 or 9.0.121, as applicable.
- Inventory all Tomcat deployments and identify vulnerable instances.
- Review security, authentication, authorisation, and RewriteValve configurations.
- Restrict unnecessary exposure to HTTP/2 and monitor abnormal activity.
- Remove unused Tomcat components and example applications.
- Secure Unix Domain Sockets and enforce least-privilege access.
- Monitor for suspicious activity and migrate unsupported Tomcat versions.
HYPERLINK
Advisory ID: ngCERT-2026-080005
Damage: Critical
Probability: High
Platform(s): Windows, Linux, and Kubernetes (Esri Portal for ArcGIS)
SUMMARY
ngCERT warns organisations using Esri Portal for ArcGIS of a critical authentication bypass vulnerability tracked as CVE-2026-13019. The flaw affects Portal for ArcGIS versions 12.1 and earlier running on Windows, Linux, and Kubernetes. A remote, unauthenticated attacker can access an unprotected API endpoint without any credentials or user interaction. The vulnerability carries a CVSS v3.1 score of 9.8 (Critical). Esri has released a security patch, and all affected organisations are strongly advised to apply it immediately.
DESCRIPTION
CVE-2026-13019 is a missing authentication for a critical function vulnerability (CWE-306 / CWE-640) in Esri Portal for ArcGIS. An API endpoint within the product lacks proper authentication controls, allowing a remote attacker to invoke it without providing valid credentials. Successful exploitation requires no privileges and user interaction. Since the vulnerable endpoint is network-accessible, attackers can exploit it remotely over the internet or internal networks. The vulnerability impacts confidentiality, integrity, and availability of the affected system. Esri published the fix in the Portal for ArcGIS Security 2026 Update 2 Patch (released June 2026).
CONSEQUENCES
Successful exploitation of CVE-2026-13019 may result in:
- Unauthorised access to critical API functions.
- Compromise of sensitive geospatial and organisational data.
- Potential modification or deletion of portal content and configurations.
- Full impact on system confidentiality, integrity, and availability.
- Possible further lateral movement within the network.
SOLUTION/MITIGATION
ngCERT recommends the following:
- Immediately apply the Portal for ArcGIS Security 2026 Update 2 Patch released by Esri.
- Upgrade to a fixed version of Portal for ArcGIS as advised by the vendor.
- Restrict network access to the Portal for ArcGIS management and API interfaces using firewalls or network segmentation.
- Monitor logs for any unauthenticated API access attempts.
- Conduct a security assessment of all ArcGIS Portal deployments.
- Implement the principle of least privilege and multi-factor authentication where possible.
- Report any confirmed exploitation or related incidents to ngCERT for further assistance and coordination.
HYPERLINK
- https://www.cve.org/CVERecord?id=CVE-2026-13019
- https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/june-2026-arcgis-security-bulletin
- https://www.ionix.io/threat-center/cve-2026-13019/
- https://www.sentinelone.com/vulnerability-database/cve-2026-13019/
- https://msftnewsnow.com/microsoft-code-of-conduct-phishing-aitm-token-thef/
- Reported Russian-Linked Disinformation Campaigns Targeting Africa’s Information Space
- Authorities Raise National Security Concerns Over BitChat Decentralized Messaging Application
- Fraudulent "Free Data and Airtime" Phishing Campaign Hosted on ibaidad.com
- Awareness Advisory on Reported China-Linked Cyber Espionage Campaign Targeting Research Institutions