USN-8626-1: systemd vulnerabilities
It was discovered that systemd-homed did not properly verify the signature of home records. A local attacker could possibly use this issue to add arbitrary system groups to a logged-in user and gain elevated privileges. (CVE-2026-16742) It was discovered that systemd-machined incorrectly handled certain polkit authorization checks. A local attacker could possibly use this issue to terminate arbitrary processes, including privileged ones. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-15060) It was discovered that systemd-oomd did not properly validate certain IPC requests. A local attacker could possibly use this issue to terminate arbitrary processes. (CVE-2026-15059)
CSIRTS triage
- What
- systemd contains three local privilege escalation vulnerabilities: systemd-homed fails to verify home record signatures (CVE-2026-16742), systemd-machined incorrectly handles polkit authorization (CVE-2026-15060), and systemd-oomd fails to validate IPC requests (CVE-2026-15059).
- Who is affected
- Ubuntu 26.04 LTS and other Linux systems running vulnerable systemd versions where local attackers have access.
- Urgency
- High; all three vulnerabilities enable local privilege escalation from unprivileged accounts to root or system privileges.
- Action
- Apply Ubuntu security update USN-8626-1 or equivalent systemd patches from your distribution.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch systemd
Get an email when a new systemd advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8626-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-167420.06% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 0% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-150600.08% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 0% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-150590.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-16742 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15060 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15059 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] systemd: Multiple vulnerabilitiescert-bund
- mediumCVE-2026-15059: systemd-oomd: unprivileged users can terminate arbitrary processesmsrc
- mediumCVE-2026-16742: systemd-homed contains a local privilege escalation bug via arbitrary system group addition to…nvd
- mediumCVE-2026-15060: When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-mac…nvd
- mediumCVE-2026-15059: Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API du…nvd
More from Ubuntu Security Notices
- unknownUSN-8724-1: rabbitmq-c vulnerabilities2026-09-03
- unknownUSN-8720-1: GnuPG vulnerability2026-09-03
- unknownUSN-8723-1: SPICE vdagent vulnerabilities2026-09-03
- unknownUSN-8722-1: libssh2 vulnerabilities2026-09-03
- unknownUSN-8719-1: APR-util vulnerabilities2026-09-03