logo

CISA warns of critical Linux Sudo flaw exploited in attacks

ID: 83b4c9d3-126f-55c3-8311-1dfc89748c42

STIX ID: report--83b4c9d3-126f-55c3-8311-1dfc89748c42

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2025-09-30

Date Updated: 2026-07-19

Author: Ionut Ilascu

...
...

CVE-2025-32463 is a critical sudo vulnerability (CVSS 9.3) in versions 1.9.14–1.9.17 that allows local attackers to escalate to root using the -R (--chroot) option even if not listed in sudoers; proof-of-concept exploits have been released, CISA added it to its KEV catalog and warned of in-the-wild exploitation, and federal agencies were given a mitigation deadline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.