Exploits and vulnerabilities in Q2 2026
Kaspersky's Q2 2026 report confirms that proof-of-concept exploits are now publicly available for critical weaknesses in Microsoft Windows Defender, BitLocker, and the Linux kernel. The release of functional code for issues like the "BlueHammer" TOCTOU vulnerability in Windows Defender and local privilege escalation bugs in the Linux page cache allows attackers to immediately target unpatched systems. Organizations should apply patches urgently to mitigate these newly exposed risks.
The vulnerability landscape shifted significantly in Q2 2026. First, the number of registered CVEs reached an unprecedented level. This is driven primarily by the widespread adoption of AI, both for application development and search for security flaws. This resulted in entire new classes of vulnerabilities emerging, particularly in the Linux networking subsystem.…