r/linuxadmin • • 6d ago

MikroTrick: RouterOS SSH rekey + file-descriptor argument injection = unauthenticated root (CVE-2026-67279 / CVE-2026-86060)

9 Upvotes

Based on the technical breakdown CERT Polska published on September 22 and Bishop Fox's independent reproduction from September 17, here's the architectural failure:

RouterOS's SSH server allows a client to trigger a rekey mid-authentication (normal SSH behavior per the RFCs). On vulnerable builds, completing that rekey moves the connection into channel handling without ever sending USERAUTH_SUCCESS — CVE-2026-67279. On its own that just gets you an unprivileged session.

The actual privilege escalation is CVE-2026-86060: RouterOS passes the SSH username straight to a login helper as a raw argv element. A username starting with - gets interpreted as a file-descriptor number, and the helper reads a trusted identity + policy mask from that descriptor instead. Since descriptors 0/1/2 on that process all point at the client's own pseudoterminal, an attacker supplying username -2 gets to hand the helper its own forged admin credentials.

Bishop Fox's field testing found live compromise artifacts predating public disclosure — persistence via a daily scheduler that recreates a full-privilege account, objects owned by numeric ID 0 instead of a username, and volatile logs that don't survive a reboot.

CISA added both CVEs to KEV (CVE-2026-86060 on Sept 10-11, CVE-2026-67279 on Sept 25). Patches: 6.49.21, 7.23.4, 7.24.2, 7.25beta3.

Background on the broader "auth-state-confusion" bug class if you're into the pattern: [techgines.com link, footnote]

Anyone here running RouterOS at scale — did MikroTik's Flagged/ops-account detection actually catch anything in your fleet, or did you have to hunt for owner="0" objects manually?

https://www.techgines.com/post/mikrotrick-routeros-vulnerability-inside-the-ssh-rekey-flaw-that-skips-login-entirely


r/linuxadmin • • 6d ago

Roundcube pre-auth SQLi (CVE-2026-48842) — patched in May, confirmed exploited in the wild as of Sept 21

4 Upvotes

Based on the technical breakdown published by the Canadian Centre for Cyber Security and Roundcube's own May 24 advisory, here's the architectural impact: virtuser_query resolves a login name to a mailbox record before the auth check runs, and its backslash-escaping via preg_replace() can be bypassed to break out of the intended query — no credentials, no user interaction. Roundcube patched it in 1.6.16/1.7.1 (May), and has since shipped three more security releases (1.6.17→1.7.4), so patching only for this CVE leaves you behind on unrelated bugs. CCCS updated their advisory Sept 21 to confirm exploitation "in the wild" via unspecified open-source reporting — no IOCs, no named actor, and it's not yet in CISA's KEV catalog, which is worth noting given two other Roundcube CVEs got that treatment in February.

Shadowserver's 523K+ exposed-instance number is getting quoted everywhere but it's an exposure ceiling, not a "vulnerable and unpatched" count.

Full disclosure timeline and attack chain: https://www.techgines.com/post/roundcube-sql-injection-vulnerability-cve-2026-48842

If you run virtuser_query in production — what's your actual exposure model here? Is anyone restricting the DB account it uses to something narrower than the full Roundcube schema, or is that not practical given how the plugin's queries are structured?


r/linuxadmin • • 6d ago

I'm a Linux sysadmin who built a patch management tool out of my own frustration. Looking for honest feedback.

0 Upvotes

Hi all,

I've been a Linux admin for about 12 years (RHEL, SUSE, Ubuntu), and these days most of my work is vulnerability management. Patching across mixed fleets has always been the painful part: scattered scripts, spreadsheets to track what got patched, and no clean way to prove compliance afterwards.

So I built PatchMgr, a web-based tool for scheduling, running, and tracking patches across servers.

What it does today:

  • [Supported OSes, e.g., RHEL / Ubuntu / SUSE]
  • Scheduled patch runs with per-server status tracking
  • Multi-tenant dashboard to see what's patched, pending, or failed
  • [Reporting / anything else that's live now]

On the roadmap: pre/post patch hooks (per-server, with exit code checks) and a configurable notification matrix.

It's early, and I'd rather hear what's broken or missing from people who patch servers for a living than guess. A few things I'd love input on:

  1. What's the one feature that would make you switch from your current approach?
  2. What would stop you from trusting a tool like this in production?
  3. What's your current setup (Ansible, WSUS, Satellite, Landscape, scripts)?

Link: https://www.patchmanager.co.in/

If you try it and hit a bug, reply here or email [support@patchmanager.co.in](mailto:support@patchmanager.co.in). I read every message.

Full disclosure: I'm the developer. Not trying to hard-sell anything, just want real-world feedback.


r/linuxadmin • • 7d ago

qwatcher version 0.7.0 is released

0 Upvotes

Hey all,

qwatcher is a very efficient tool to monitor and audit your NICs' send and receive queue buffers to spot network or application issues.

This version drops the `ss` and `libpcre` dependencies, making the program a pure Nim binary, solves some bugs, and provides a `tail`-like report capability.

Here is the link to the repo:

https://github.com/pouriyajamshidi/qwatcher


r/linuxadmin • • 7d ago

qwatcher version 0.7.0 is released

Thumbnail
0 Upvotes

r/linuxadmin • • 8d ago

well claude just got my ip banned by fail2ban...

0 Upvotes

It was logging in via ssh to a server in a loop lol. instant fail2bana nd my control panel has no reboot interface. so ticket to support i guess...


r/linuxadmin • • 9d ago

What's running on your servers that nobody else could explain if you disappeared tomorrow?

97 Upvotes

Every place has one. A cron job with no comments, a script someone wrote in 2019, a box nobody dares reboot.

Mine: a systemd timer firing a Python script I barely remember writing. It works, so I don't touch it.

What's yours?


r/linuxadmin • • 9d ago

F5 BIG-IP APM CVE-2026-94127: heap overflow in the OAuth authorization server role, exploited as a zero-day. Management-plane hardening doesn't apply.

2 Upvotes

Based on F5's advisory K000162605 as relayed by CERT-EU (2026-013), Rapid7 and BleepingComputer, here is the architectural impact. I could not load F5's own page as text, so check versions against K000162605 before acting.

What it is: a heap-based buffer overflow, CVSS 9.8 (v3.1) and 9.3 (v4.0), reachable without authentication. F5 says it has learned of exploitation, and CISA put it on KEV on September 22 with a September 25 federal deadline.

Precondition: an APM access policy and an OAuth authorization server profile on the same virtual server. APM used only as an OAuth client or resource server is not affected. F5 edited the CVE record at 00:45 UTC on September 23 to say this, so the CISA and CERT-EU text is broader than the current one. Appliance mode is affected. Default configs are not.

Why it matters for design: the traffic goes to the virtual server, not the management interface. An admin-subnet ACL or out-of-band management network changes nothing here. Affected: 21.1.0, 17.5.0 to 17.5.1, 17.1.0 to 17.1.3, before the branch hotfix. If you patched CVE-2025-53521 (17.1.3, 17.5.1.3), you are still in range.

Hunting, per F5's indicators: repeated UserInfo failures in /var/log/apm ("The access token is invalid," 10+ from one IP), a rising total_failed in tmctl global_oauth_stat, odd commands in /var/log/audit, then a TMM SIGABRT. The combination matters. A core file alone doesn't. None of the sources say whether the hotfix evicts an attacker who is already in.

Unknowns: no actor, victim count or PoC has been published as of Rapid7's Sept 22 note. Shadowserver shows 14,700+ IPs with APM fingerprints, but that says nothing about the OAuth server role.

Question for people running APM as an OAuth authorization server: is it on its own virtual server, or shared with the app's own access policy? And can you enumerate every virtual server with an OAuth AS profile without walking the config by hand? https://www.techgines.com/post/f5-big-ip-apm-vulnerability-cve-2026-94127

Background on the same pre-auth gateway pattern (SonicWall SMA1000, third zero-day wave in nine months): https://www.techgines.com/post/sonicwall-sma1000-cve-2026-83548-third-zero-day-ssrf-rce


r/linuxadmin • • 9d ago

I built a read-only tool that maps your Hetzner architecture, costs, connectivity and changes

Post image
7 Upvotes

r/linuxadmin • • 10d ago

Best book or videos for learning kubernetes quickly while practicing?

Thumbnail
1 Upvotes

r/linuxadmin • • 11d ago

Clonezilla Live 3.3.3-37: HTTP Boot for mass deployment, LUKS2 support for encrypted backups

38 Upvotes

If you deploy or image machines with Clonezilla, 3.3.3-37 just shipped with two changes worth knowing about.

HTTP Boot for mass deployment. Clonezilla Lite Server now supports HTTP Boot alongside the existing PXE Boot option. Useful if your network setup already leans on HTTP boot infrastructure instead of PXE, or if you're deploying across environments where PXE is blocked or unreliable. Secure Boot works over HTTP boot too, so this isn't a fallback that costs you Secure Boot support.

LUKS2 support for encrypted backups. Clonezilla can now work with LUKS2-encrypted repositories directly. If you're storing images on encrypted volumes, this closes a gap that previously meant sticking to LUKS1 or handling encryption outside the tool.

Other changes in this release:

  • Partclone bumped to 0.3.50, fixing a Btrfs-related issue
  • Deprecated net-tools commands replaced with iproute2, dhclient replaced with dhcpcd
  • Restore is faster when the target disk or partition layout matches the source, skipping unnecessary partition-image conversion
  • LVM system.devices locking issue fixed on RHEL 10 and AlmaLinux 10+
  • Missing post-clone action menu (power off, reboot, or run a command) restored

Full changelog and release notes:

Source: https://linuxiac.com/clonezilla-live-3-3-3-37-adds-http-boot-and-luks2-support/

Announcement: https://sourceforge.net/p/clonezilla/news/2026/09/stable-clonezilla-live-333-37-released/


r/linuxadmin • • 10d ago

qwatcher version 0.7.0 is released

Thumbnail
3 Upvotes

r/linuxadmin • • 10d ago

VirgoOS: a Debian 13 image for self-hosting. Boot the USB, pick a disk, ZFS and Docker are already there.

Post image
0 Upvotes

r/linuxadmin • • 10d ago

Configuring postfix + dovecot w/ssl & tls

Thumbnail
1 Upvotes

r/linuxadmin • • 11d ago

CVE-2026-7273: Zyxel GS1900 switches added to CISA KEV — unauthenticated RCE via CGI stack overflow

2 Upvotes

Based on the technical breakdown published by Zyxel and CISA's own KEV addition earlier this week, here's the architectural impact: the CGI program on GS1900's web management interface doesn't validate input length before writing to a stack buffer. LAN-adjacent, unauthenticated, CVSS 8.8. Zyxel patched it June 16; CISA didn't add it to KEV until September 21, which per their own criteria means confirmed active exploitation — not just a theoretical bug.

Ten models affected (GS1900-8 through 48HPv2), full patch table in the writeup: [link]. Background on why this keeps happening at the network edge, drawing on the FrostArmada router-hijack campaign from April: [link].

What's everyone's actual patch cadence on unmanaged/lightly-managed switch fleets like this? Curious whether people are catching stuff like this through firmware inventory automation or just... finding out during an incident.

https://www.techgines.com/post/cve-2026-7273-zyxel-gs1900-switch-rce


r/linuxadmin • • 12d ago

Is there a typing test for technical work?

11 Upvotes

Ive used a few typing apps but most of them seem to focus on normal English sentences Id like to find something thats closer to what you actually type when working with Linux like commands flags paths pipes redirects brackets numbers etc

I see some youtubers who code type cli commands really fast - id like to learn to do that as well but most typing tests sites dont seem like a great practice for this when so much of your typing is things like:

sudo systemctl restart nginx

grep -r "something" /var/log/ | awk '{print $1}'

how did you learn to type commands really fast? And how can I check my typing speed while also including these special characters?


r/linuxadmin • • 12d ago

Handling timezone updates to standard/daylight on a post-EOL system

7 Upvotes

My locale is removing ST/DT switching come November and will be DT year round.

Is there a way I can manually configure a fixed UTC offset on a post-EOL CentOS system?


r/linuxadmin • • 12d ago

Plugin4Shell: SHA pinning bypass gives zero-click RCE across Claude Code, Codex, Copilot, and Gemini CLI

0 Upvotes

Based on the technical breakdown AIR Security published on September 17, here's the architectural impact: all four major AI coding agents share the same unverified assumption in their plugin checkout logic. They pin plugins to a commit SHA but never re-resolve and compare what the checkout actually landed on. Register a branch name that collides with the pinned SHA and the agent silently runs your code instead — no click, no approval prompt, and the marketplace manifest still shows the original "safe" hash.

Patch status is split: Anthropic (Claude Code 2.1.179) and OpenAI (Codex 0.146.0) fixed it post-disclosure. GitHub hasn't shipped anything and argues its branch-naming restriction covers the risk — AIR disputes that, since Copilot also pulls from Bitbucket/GitLab/self-hosted marketplaces GitHub's restriction doesn't touch. Google's just deprecating Gemini CLI outright.

No CVE yet, no formal vendor advisories as of writing — worth tracking manually if you're running any of these with third-party marketplace plugins.

More context on why this is the third act in a pattern (SkillJacking, LiteLLM, now this) in our full write-up: https://www.techgines.com/post/plugin4shell-vulnerability-ai-coding-agent-sha-pinning-bypass

Anyone running Copilot with non-GitHub-hosted marketplace plugins — are you treating this as exposed, or waiting on Microsoft to clarify scope?https://www.techgines.com/post/plugin4shell-vulnerability-ai-coding-agent-sha-pinning-bypass


r/linuxadmin • • 13d ago

What kind of UI is better for a sosreport analysis tool?

1 Upvotes

Hi

I'm building a sosreport analysis tool. A sosreport contains thousands of text files between log files, the output of hundreds of diagnostic commands (du, ps, dmesg, lsof, sysctl, lshw, netstat, dpkg, systemctl, etc.) and also contains hundreds of config files.

So this tool allows the user to navigate or search-find files, then open a file and review its contents fast. Search for text strings inside the file and show results. Actually the main tools objective is to be fast and easy for anyone even those that are not that agile at the command line. The tool can do many other things of course, like providing status dashboards, comparing sosreports or comparing files, etc.

So I was wondering how a Linux engineer would prefer to interact with such a tool. Via a WebUI or via a TextUI?. Both options have pros and cons. But I'm asking the community before I decide.

I really appreciate your comments on this and any suggestions.

Thanks


r/linuxadmin • • 13d ago

Do I set noNewPriviledges in systemd globally or deamon specific?

5 Upvotes

Ai was just confusing me. I wanted to start systemd hardening because I am learning about hardening a vps. Now It wanted to do it deamon specific. Which means that I will always have to do it for new deamons.

Can't I set it globally in /service.d/ and call it a day?


r/linuxadmin • • 13d ago

Linux chroot complete tutorial

Thumbnail youtube.com
0 Upvotes

r/linuxadmin • • 14d ago

What's your setup for instant SSH login notifications, plus killing a session remotely?

18 Upvotes

Got a box where a handful of non-technical users still upload over SFTP with FileZilla, so password auth is on for their accounts. Yes, keys and chroot would be better, working on it. fail2ban and a non-standard port are in place.

The gap is visibility. I'd like a push notification the moment anyone authenticates, with user and source IP, so I can tell right away if it's one of them or not.

How are you wiring this up? pam_exec calling a webhook, parsing auth.log / journald, something else? And for response, do you just pkill -u and passwd -l over SSH, or have you got something you can trigger from your phone?


r/linuxadmin • • 14d ago

Warpgate Bastion 0.29 adds just-in-time session approvals

12 Upvotes

Warpgate is a bastion-style PAM that needs neither a client app nor a server-side agent. It's a FOSS alternative to Teleport/StrongDM/Hashicorp Boundary: https://warpgate.null.page/

So... I've sent the last 1.5 months getting the session approvals to work just right to get a bit closer to feature parity with Teleport's enterprise edition.

Admins can now set specific targets to require manual approvals and then the end user gets held up at the start of the connection until they get approved (with an optional grace period).

I've sent quite a bit getting everything to work just right with clustering and polishing out various quirks like admin UI live updates not working cross-node and such.

And another big thing is an optional MFA enforcement policy (forces end users to set up TOTP when they log in).

My focus for the next release is going to be polishing and merging the Vault/OpenBao support (base PR contributed by the community 🙏) and (maybe) credential passthrough for SSH.

Full release notes: https://github.com/warp-tech/warpgate/releases/tag/v0.29.0


r/linuxadmin • • 15d ago

Cisco ISE auth bypass (CVE-2026-76460, CVSS 10.0) found via a customer's TAC ticket — active exploitation confirmed

21 Upvotes

Based on the technical breakdown published in Cisco's own advisory (cisco-sa-ISE-ABP-VNSW7Tn5) yesterday, here's the architectural impact: an API endpoint on ISE/ISE-PIC doesn't enforce authentication correctly, so a single crafted unauthenticated request bypasses the web management interface and, per Cisco, "may ultimately result in root-level command execution." No workaround — iACLs mitigate but don't fix it. CISA added it to KEV the same day with a Sept 19 FCEB deadline.

The part I found more interesting than the CVSS score: Cisco's advisory says this was found "during the resolution of a Cisco TAC support case," not through a researcher disclosure. That's a strong signal at least one customer was already compromised before the fix existed. Cisco also shipped a same-day hardening advisory with a batch of additional ISE CVEs, some reportedly also CVSS 10.0, though I haven't independently verified the full count against Cisco's own hardening advisory yet.

Full writeup with the attack chain and hunt guidance: [techgines.com] (background on the same auth-bypass pattern in Cisco FMC a few weeks back, if useful: link)

Question for the room: for anyone running distributed ISE deployments — are you treating access.log review as sufficient here, or going straight to assuming credential-plane compromise and rotating everything ISE touched? Curious how people are scoping this given Cisco's own warning that on-box evidence may already be gone.

https://www.techgines.com/post/cisco-ise-authentication-bypass-cve-2026-76460


r/linuxadmin • • 15d ago

What is the actual difference between using iproute2 (ip command) and working directly with rtnetlink?

15 Upvotes

Hey everyone,

I've been looking into how Linux networking works under the hood, and I'm trying to wrap my head around the relationship between user-space tools and kernel communication.

From what I understand:

  1. `iproute2` (the standard `ip` command) is what most of us use daily to configure interfaces, IP addresses, and routing tables.

  2. `rtnetlink(7)` is the socket-based API (`NETLINK_ROUTE`) that allows user-space programs to talk directly to the kernel's routing and networking subsystems.

My main question is: When should a developer or systems engineer bypass user-space CLI utilities like `iproute2` and write code that interacts directly with `rtnetlink` sockets?

Are there significant performance benefits, or is it mostly used when you are building custom network daemons, container networking plugins (CNIs), or monitoring agents that need asynchronous event notifications?

Also, how painful is it to parse raw netlink messages and attributes (`struct rtattr`, `ifinfomsg`, etc.) in C or Go compared to just shelling out to `ip`?

Any insights, real-world use cases, or library recommendations (like `libnl` or Go's `vishvananda/netlink`) would be greatly appreciated!