Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-8933 is a local privilege escalation vulnerability in snap-confine, a core component used by Canonical snapd to create secure execution environments for snap applications. The flaw affects versions of snap-confine configured with set-capabilities rather than set-uid-root. An unprivileged local attacker can exploit this vulnerability to bypass security restrictions and execute arbitrary code with full root privileges. The vulnerability has a high severity score of 7.8 and impacts version 2.75.0. No official patch or remediation guidance is currently available. Join the discussion | CVE Database V5 | 07/21/2026, 14:02:19 UTC Added: 07/21/2026, 14:42:54 UTC |
CVE-2026-15226 is a high-severity vulnerability in Canonical snapd's snap-confine component that allows sandbox confinement bypass. The issue arises because the seccomp security templates do not block operations that create or manipulate set-user-ID (setuid) executables. This enables a confined snap application to compile or drop binaries with setuid attributes, potentially allowing privilege escalation within the container namespace. The vulnerability has been addressed by hardening the seccomp template engine to block such actions. Versions prior to 2.76.1 are affected. Join the discussion | CVE Database V5 | 07/21/2026, 14:02:04 UTC Added: 07/21/2026, 14:42:53 UTC |
0 An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd (inherited via ) inadvertently permit strictly confined snap applications, which lack the privileged account-control interface, to interact directly with the io.systemd.Multiplexer and io.systemd.NameServiceSwitch UNIX domain sockets under /run/systemd/userdb/. On systems where the systemd-userdbd service is installed and operational, the service fails to distinguish between an unconfined root user on the host system and a restricted root user running within a snap application's sandbox (such as a daemon or configuration hook). Because systemd-userdbd returns "complete" user records—including sensitive hashed user passwords from /etc/shadow—when queried by a process running as root, a compromised or malicious strictly confined snap executing code as root can successfully query the Varlink interface to retrieve all system password hashes, bypassing intended snap sandbox restrictions. This issue is mitigated by the fact that systemd-userdbd is not installed by default on standard Ubuntu deployments. Join the discussion | CVE Database V5 | 07/21/2026, 14:00:51 UTC Added: 07/21/2026, 14:42:53 UTC |
0 CVE-2026-3888 is a local privilege escalation vulnerability in snapd on Linux systems, specifically affecting multiple Ubuntu LTS versions from 16.04 through 24.04. The flaw arises when systemd-tmpfiles is configured to automatically clean snap's private /tmp directory, allowing a local attacker to re-create this directory and escalate privileges to root. The vulnerability has a high severity score of 7.8, reflecting its potential to compromise confidentiality, integrity, and availability. Exploitation requires local access and elevated privileges but no user interaction. No known exploits are currently reported in the wild. Organizations running affected Ubuntu LTS versions with snapd and systemd-tmpfiles configured as described should prioritize patching or mitigating this issue to prevent privilege chaining attacks. Join the discussion | CVE Database V5 | 03/17/2026, 14:02:08 UTC Added: 03/17/2026, 14:13:22 UTC |
Showing 1 to 4 of 4 results