<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/bad-epoll-hits-99-reliability-sharepoint-rce-under-active-exploitation-zgp0yt8lh" -->

---
title: Bad Epoll hits 99% reliability, SharePoint RCE under...
description: CVE-2026-46242, a use-after-free in the Linux epoll subsystem, has a public exploit achieving root access 99% of the time on kernels 6.4 and later, including...
canonical: https://daily.dev/posts/bad-epoll-hits-99-reliability-sharepoint-rce-under-active-exploitation-zgp0yt8lh
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Bad Epoll hits 99% reliability, SharePoint RCE under active exploitation | daily.dev
og:description: CVE-2026-46242, a use-after-free in the Linux epoll subsystem, has a public exploit achieving root access 99% of the time on kernels 6.4 and later, including...
og:url: https://daily.dev/posts/bad-epoll-hits-99-reliability-sharepoint-rce-under-active-exploitation-zgp0yt8lh
og:image: https://api.daily.dev/og/posts/ZGP0yT8Lh.png
og:image:alt: Bad Epoll hits 99% reliability, SharePoint RCE under active exploitation
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Bad Epoll hits 99% reliability, SharePoint RCE under active exploitation

**[Security Digest](https://daily.dev/sources/security_digest)** · 5 min read · 0 upvotes · 0 comments

## Summary

CVE-2026-46242, a use-after-free in the Linux epoll subsystem, has a public exploit achieving root access 99% of the time on kernels 6.4 and later, including Android devices running 6.6-series kernels. CISA added a SharePoint deserialization RCE to its KEV catalog with a federal patch deadline of Saturday, and over 10,000 servers remain exposed. The FortiBleed credential theft campaign is now confirmed to be far larger than initially reported, with ties to Lynx ransomware and over 430,000 FortiGate firewalls targeted. A joint FBI and Google operation took down the NetNut residential proxy botnet, cutting off 2 million compromised Android devices used to launder malicious traffic.

## Content

**TLDR:** CVE-2026-46242, a use-after-free in the Linux epoll subsystem, has a public exploit achieving root access 99% of the time on kernels 6.4 and later, including Android devices running 6.6-series kernels. CISA added a SharePoint deserialization RCE to its KEV catalog with a federal patch deadline of Saturday, and over 10,000 servers remain exposed. The FortiBleed credential theft campaign is now confirmed to be far larger than initially reported, with ties to Lynx ransomware and over 430,000 FortiGate firewalls targeted. A joint FBI and Google operation took down the NetNut residential proxy botnet, cutting off 2 million compromised Android devices used to launder malicious traffic.

---

## CVE-2026-46242 Bad Epoll: reliable local privilege escalation on Linux 6.4+ and Android

The exploit chains a use-after-free write in the epoll subsystem into full kernel memory control via cross-cache attack, arbitrary read through /proc/self/fdinfo, and a ROP chain for a root shell. The race window is only about 6 instructions wide, but a retry loop widens it enough to hit 99% reliability. Kernels 6.4 through the fix date are affected; 6.1-based kernels are not. An Android exploit targeting Pixel 10 (kernel 6.6+) is in progress. The only fix is upstream commit a6dc643c6931 — there is no workaround since epoll is a core kernel feature. Distributions, cloud providers running shared hosts, and Android device vendors should treat this as urgent. [Read more](https://daily.dev/feed-by-ids?id=8ik6UsR3n&id=NFJaE30JD)

## CISA adds SharePoint RCE CVE-2026-45659 to KEV, federal patch deadline Saturday

The flaw is a deserialization of untrusted data bug that lets any authenticated attacker with Site Member permissions execute arbitrary code remotely, no user interaction required. Microsoft patched SharePoint Enterprise Server 2016, 2019, and Subscription Edition on May 21. Over 10,000 servers remain exposed online, and this is the 11th SharePoint vulnerability CISA has flagged since 2021, with seven linked to ransomware. Federal agencies are under Binding Operational Directive 26-04 with a Saturday deadline. [Read more](https://daily.dev/posts/5qwo6lfyk)

## FortiBleed campaign tied to Lynx ransomware, scope expands to 430,000 FortiGate firewalls

SOCRadar linked the FortiBleed credential theft operation to INC and Lynx ransomware-as-a-service by identifying a Windows server in the FortiBleed infrastructure that had accessed negotiation panels for both groups. The operation is now understood to have targeted over 430,000 FortiGate firewalls, deployed traffic sniffers on roughly 19,000 devices, and involved around 20 members with defined roles. Attackers also allegedly exploited a Nextcloud zero-day and planted persistent backdoor accounts using the username 'adminin'. A full technical white paper with indicators of compromise is forthcoming from SOCRadar. [Read more](https://daily.dev/posts/d4l4Igj1S)

## NetNut residential proxy botnet dismantled, 2 million Android devices cut off

A joint operation by Google, the FBI, Lumen Technologies, and Shadowserver disrupted NetNut, one of the largest residential proxy botnets, which ran on at least 2 million compromised Android devices including smart TVs and streaming boxes infected via trojanized apps and pre-installed malware. In a single week, 316 distinct threat clusters were observed routing traffic through its exit nodes. Google disabled the C2 infrastructure and pushed warnings via Play Protect; the FBI seized the netnut.com domain. Because NetNut ran a reseller program powering many downstream proxy services, the disruption is expected to ripple broadly across the residential proxy ecosystem. [Read more](https://daily.dev/posts/yWIBtnJA8)

---

## Also notable

- **Cisco confirms active exploitation of Unified CM SSRF CVE-2026-20230:** The flaw allows unauthenticated remote attackers to send file:// payloads to write files on targeted devices; Cisco urges upgrade to Unified CM 14SU6 or 15SU5, and Shadowserver is tracking over 200 exposed instances online, primarily in Asia and North America. [Read more](https://daily.dev/posts/RiSP0fMwT)
- **ARToken PhaaS exposes EvilTokens Microsoft 365 toolkit with 37-fold surge in device code phishing:** Cisco Talos reverse-engineered the React-based panel to expose over 80 API endpoints covering token theft, PRT persistence, and automated BEC workflows sold for a $1,500 setup fee plus $500/month — device code phishing attacks have surged 37-fold over the past year. [Read more](https://daily.dev/posts/ZGvr5nZAC)
- **Scattered Spider member Peter Stokes, 19, extradited to US after Finland arrest:** Stokes faces charges of fraud, conspiracy, and computer intrusion tied to at least four breaches including a May 2025 attack on a luxury retailer where the group demanded an $8 million ransom; Scattered Spider has been linked to over 100 intrusions and more than $100 million in ransom payments since 2022. [Read more](https://daily.dev/posts/IZA9zRLpm)
- **Attested TLS formally verified as broken, affecting WhatsApp Private Processing and CVE-2026-33697:** TU Dresden researchers used ProVerif to show all seven examined intra-handshake attestation binding mechanisms fail to prevent relay attacks, with CVE-2026-33697 (CVSS 7.5) affecting production systems including Meta's WhatsApp Private Processing and Edgeless Systems' Contrast — level-three binding that would protect actual application traffic may be architecturally impossible. [Read more](https://daily.dev/posts/kI6PoNzPx)
- **npm and Go packages hijacked to deploy infostealer via VS Code tasks:** This week's package management roundup flags an active campaign hijacking npm and Go packages to deliver an infostealer through VS Code tasks, alongside Composer path traversal and credential leakage CVEs and a python.org API authentication bypass. [Read more](https://daily.dev/posts/m4ec89Xlo)

## Similar posts on daily.dev

- [“Bad Epoll” Linux Kernel Bug Lets Any User Grab Root](https://daily.dev/posts/bad-epoll-linux-kernel-bug-lets-any-user-grab-root-nfjae30jd) · Latest Hacking News · 4 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#linux](https://daily.dev/tags/linux), [#ransomware](https://daily.dev/tags/ransomware)

[View this post on daily.dev](https://daily.dev/posts/bad-epoll-hits-99-reliability-sharepoint-rce-under-active-exploitation-zgp0yt8lh)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"DiscussionForumPosting","mainEntityOfPage":"https://daily.dev/posts/bad-epoll-hits-99-reliability-sharepoint-rce-under-active-exploitation-zgp0yt8lh","headline":"Bad Epoll hits 99% reliability, SharePoint RCE under active exploitation","text":"CVE-2026-46242, a use-after-free in the Linux epoll subsystem, has a public exploit achieving root access 99% of the time on kernels 6.4 and later, including Android devices running 6.6-series kernels. CISA added a SharePoint deserialization RCE to its KEV catalog with a federal patch deadline of Saturday, and over 10,000 servers remain exposed. The FortiBleed credential theft campaign is now confirmed to be far larger than initially reported, with ties to Lynx ransomware and over 430,000 FortiGate firewalls targeted. A joint FBI and Google operation took down the NetNut residential proxy botnet, cutting off 2 million compromised Android devices used to launder malicious traffic.","url":"https://daily.dev/posts/bad-epoll-hits-99-reliability-sharepoint-rce-under-active-exploitation-zgp0yt8lh","datePublished":"2026-07-05T04:18:35.418Z","dateModified":"2026-07-05T04:18:57.062Z","author":{"@type":"Organization","name":"Security Digest","logo":"https://media.daily.dev/image/upload/s--m4ZKB_C0--/f_auto,q_auto/v1779959612/logos/security_digest","url":"https://daily.dev/sources/security_digest"},"interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"isPartOf":{"@type":"WebPage","url":"https://daily.dev/sources/security_digest","name":"Security Digest"}}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Security Digest","item":"https://daily.dev/sources/security_digest"},{"@type":"ListItem","position":3,"name":"Bad Epoll hits 99% reliability, SharePoint RCE under active exploitation"}]}
```

