← Carolina Clear Tech

Cyber Threat Brief

2026-05-31

Listen to this brief (13:11)

Download MP3
Show Notes

Show Notes - 2026-05-31

Stories Covered

CVEs Referenced

CVE-2024-22018, CVE-2024-36137, CVE-2025-15649, CVE-2025-23167, CVE-2026-0257, CVE-2026-40034, CVE-2026-40510, CVE-2026-40528, CVE-2026-40933, CVE-2026-42012, CVE-2026-42013, CVE-2026-42015, CVE-2026-42789, CVE-2026-42790, CVE-2026-44839, CVE-2026-46242, CVE-2026-48864, CVE-2026-48962, CVE-2026-5260, CVE-2026-7374, CVE-2026-9804

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Security Brief - 2026-05-31

Today: Palo Alto GlobalProtect VPN suffers active exploitation of an authentication bypass (CVE-2026-0257, CISA KEV due June 1). A new Linux privilege escalation flaw dubbed CIFSwitch grants root on multiple distributions. Flowise AI platform ships a critical RCE vulnerability (CVE-2026-40933) with public exploit code.

Critical Alerts

Palo Alto GlobalProtect VPN Authentication Bypass (CVE-2026-0257)

Palo Alto Networks confirmed active exploitation of CVE-2026-0257, an authentication bypass in GlobalProtect VPN that allows attackers to establish unauthorized VPN connections using forged authentication override cookies. CISA added this flaw to the KEV catalog with a June 1, 2026 remediation deadline. EPSS score is 0.415 (97th percentile). Rapid7 observed exploitation across numerous customers beginning May 17, with attacks originating from Vultr and Dromatics Systems infrastructure. The flaw affects devices with authentication override cookies enabled and a specific certificate configuration where the same certificate is used for both HTTPS services and authentication override cookies. Attackers retrieve the public certificate via HTTPS, then forge authentication override cookies for arbitrary users. The vulnerability stems from PAN-OS validating authentication override cookies by decrypting them with a private key but not performing signature verification.

CIFSwitch Linux Privilege Escalation

A local privilege escalation vulnerability dubbed CIFSwitch in the Linux kernel allows attackers to forge CIFS authentication key descriptions, abuse the kernel's key request mechanism, and gain root privileges. The flaw impacts multiple distributions shipping vulnerable combinations of the kernel CIFS module and cifs-utils (versions 6.14 and higher, with some older variants also affected). The vulnerability was introduced 19 years ago in 2007. Confirmed vulnerable distributions include Linux Mint 21.3/22.3, CentOS Stream 9, Rocky Linux 9, AlmaLinux 9, Kali Linux 2021.4-2026.1, and SLES 15 SP7. Ubuntu, Debian, Pop!_OS, openSUSE, Oracle Linux, and Amazon Linux may be vulnerable if cifs-utils is installed. Some distributions like Ubuntu 26.04, Fedora 40-44, CentOS Stream 10, and AlmaLinux 10 have default SELinux/AppArmor settings that prevent exploitation. The flaw allows an unprivileged user to create a forged cifs.spnego request that triggers the normal authentication workflow, causing the root-privileged cifs.upcall helper to trust attacker-controlled fields. Attackers can force a namespace switch and trigger a Name Service Switch lookup before privileges are dropped, loading a malicious NSS module and achieving root code execution.

Flowise AI Platform RCE (CVE-2026-40933)

Flowise, an open source LLM flow builder with over 52,000 GitHub stars, contains a critical remote code execution vulnerability (CVE-2026-40933, CVSS 9.9) with public proof-of-concept exploit code. EPSS score is 0.001 (22nd percentile). The flaw stems from unsafe serialization of stdio commands in the MCP adapter. Flowise before version 3.1.0 allowed any user to add a new MCP and supply arbitrary commands, enabling code execution on the underlying OS. An attacker can include a malicious command in a Custom MCP Tool configuration, export the chatflow as JSON, and share it with a victim. The payload executes during the import process when the canvas loads the "Available Actions" dropdown, which triggers enumeration of the MCP server's tools. Successful exploitation leads to OS-level execution with the Flowise process's privileges (often root in containerized deployments), exposing all credentials stored in the platform and all connected services.

Business & Infrastructure Threats

Russian Intelligence Technology Procurement Escalation

European intelligence officials report that Russia's intelligence agencies have grown more aggressive in efforts to steal Western technology and defense secrets as sanctions squeeze the country's wartime economy. Moscow is building fake companies, recruiting middlemen, and deploying cyber spies and hackers. Russia is targeting advanced machine tools, factory equipment, research, dual-use technology, defense industry secrets, high-end research on advanced weaponry (such as Sweden's Gripen fighter jet), camera and laser technology that could be integrated into weapons systems, space technology, quantum technology, arctic technology, marine technology, sanctioned computer technology, and software updates for machine tools. About a third of Russia's GDP currently goes to the war effort. Intelligence officials note Russia is deploying cyberattacks against European firms and critical infrastructure to gather information for potential exploitation. Sweden experienced an attack on a power plant last year where Russia-linked actors attempted to destroy the plant but were detected and blocked. Officials note Russia is taking greater risks and caring less about potential attribution after their activities.

Patch Priority

Vulnerability Disclosures

GnuTLS Certificate Validation Bypass Flaws

Microsoft Security Update Guide published four GnuTLS vulnerabilities. CVE-2026-42012 (EPSS 0.000, 9th percentile) is a certificate validation bypass due to improper handling of URI and SRV SANs. CVE-2026-42013 (EPSS 0.000, 10th percentile) is a certificate validation bypass due to oversized subject alternative names. CVE-2026-5260 (EPSS 0.001, 34th percentile) is information disclosure via heap overread in RSA key exchange. CVE-2026-42015 (EPSS 0.001, 34th percentile) is memory corruption due to off-by-one error in PKCS#12 bag handling.

Additional Certificate Validation Flaws

CVE-2026-42790 (EPSS 0.000, 9th percentile) is a nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification. CVE-2026-42789 (EPSS 0.000, 9th percentile) allows non-CA certificates to be accepted as intermediate issuers in public_key path validation.

KubeVirt Security Flaws

CVE-2026-7374 (EPSS 0.001, 29th percentile) is a privilege escalation and node compromise via symlink following vulnerability in KubeVirt virt-handler. CVE-2026-9804 (EPSS 0.000, 8th percentile) is a vmexport directory symlink escape that enables exporter pod file read.

Node.js Permission Model Flaws

CVE-2024-36137 (EPSS 0.001, 27th percentile) affects Node.js experimental permission model when the --allow-fs-write flag is used. Operations such as fs.fchown or fs.fchmod can use a read-only file descriptor to change the owner and permissions of a file. CVE-2024-22018 (EPSS 0.002, 44th percentile) is an inadequate permission model that fails to restrict file stats through the fs.lstat API, allowing malicious actors to retrieve stats from files they do not have explicit read access to. CVE-2025-23167 (EPSS 0.001, 27th percentile) is a flaw in Node.js 20's HTTP parser that allows improper termination of HTTP/1 headers using \r\n\rX instead of the required \r\n\r\n, enabling request smuggling to bypass proxy-based access controls and submit unauthorized requests.

Other Disclosed Vulnerabilities

CVE-2026-46242 is an eventpoll struct eventpoll/struct file UAF. CVE-2026-48864 (EPSS 0.000, 1st percentile) is a heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data. CVE-2026-48962 (EPSS 0.001, 20th percentile) affects IO::Compress versions before 2.220 for Perl, allowing arbitrary code execution in File::GlobMapper via an attacker-controlled output glob. CVE-2026-40034 (EPSS 0.000, 5th percentile) is command injection via partial .gitmodules override in gix-submodule (gitoxide). CVE-2026-40528 (EPSS 0.000, 0th percentile) is a buffer overrun in OpenSC < 0.27.0 in do_key_value() via profile.c. CVE-2026-40510 (EPSS 0.000, 0th percentile) is a stack buffer overflow in OpenSC < 0.27.0-rc1 via piv_process_history() in card-piv.c. CVE-2025-15649 (EPSS 0.000, 2nd percentile) affects IO::Uncompress::Unzip versions before 2.215 for Perl, propagating uncaught exception when parsing zip header with malformed DOS date. CVE-2026-44839 (EPSS 0.000, 14th percentile) is unsanitized vhost names in RabbitMQ that allow for XSS in the management UI.

General Security News

Microsoft Incident Response Criticized

Microsoft faced criticism from researchers this week after claiming that those who dump proof-of-concept exploits for vulnerabilities they have not responsibly disclosed are enabling criminal activity, and that Microsoft will track them and bring cases against them. The statement drew backlash from the security research community.

Trends & Context

Three themes dominate today's threat landscape. First, authentication bypass and certificate validation flaws continue to provide low-complexity attack paths into enterprise networks. Second, privilege escalation vulnerabilities in foundational Linux components (CIFSwitch) and container platforms (KubeVirt) expose infrastructure that defenders assume to be hardened. Third, AI platform security is immature, with critical RCE flaws like Flowise's CVE-2026-40933 stemming from fundamental design assumptions that trust user-supplied configuration data.