CVE-2026-40224: Systemd Project Systemd
High severity, CVSS 7.3. EPSS: 0.1% chance of exploitation in the next 30 days.
In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.
Affected products
- Systemd Project Systemd: from 259, before 259.3 (fixed in 259.3)
Published 2026-04-10. Last modified 2026-06-17.