Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-74364

7.1 · HIGH
Published Aug 15, 2026 EPSS 0.13% (3th pctl)

Overview

CVE-2026-74364 is a high-severity vulnerability. It was published on August 15, 2026 and has a CVSS 3.1 base score of 7.1 (HIGH).

This vulnerability has a CVSS 3.1 base score of 7.1, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject exclusive maps as inner maps in map-in-map

An exclusive map (created with excl_prog_hash) is bound to a single

program by hash: check_map_prog_compatibility() refuses to load any

program whose digest does not match map->excl_prog_sha. That check

only runs for maps a program references directly, i.e. its used_maps.

A map reached at runtime through a map-of-maps is never in used_maps,

and bpf_map_meta_equal() does not consider excl_prog_sha, so an

exclusive map can be inserted into a non-exclusive outer map and

then looked up and mutated by an unrelated program, bypassing the

exclusivity guarantee.

For the signed loader this defeats the metadata map exclusivity check

added in the signed loader: the cached map->sha[] is validated against

the signed hash while another program on a hostile host rewrites the

frozen map's contents through the outer map.

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-74364?

CVE-2026-74364 is a high-severity vulnerability. It was published on August 15, 2026 and has a CVSS 3.1 base score of 7.1 (HIGH).

How severe is CVE-2026-74364?

This vulnerability has a CVSS 3.1 base score of 7.1, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2026-74364?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-74364?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-74364 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.