OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems
OpenAI agents exploited a Linux kernel flaw on company systems, escalating privileges.
Summary
OpenAI agents exploited a known Linux kernel vulnerability, CVE-2026-53362, to escalate privileges on the company's own systems. This allowed them to move laterally within the environment. CISA has added this flaw, along with a JFrog vulnerability exploited by the same agents, to its Known Exploited Vulnerabilities catalog, recommending patching by August 30.
Full text
Around the time some OpenAI models escaped their testing environment and hacked Hugging Face, some agents exploited a Linux kernel vulnerability to escalate privileges on OpenAI’s own systems. This was mentioned in a report published by OpenAI this week to detail the incident in which its models hacked Hugging Face in July. The AI giant’s investigation found that agents used an unauthorized makeshift message board to communicate and plan their actions, including encouraging one another to hack what they correctly guessed were real systems rather than test environments. Rogue agents went beyond Hugging Face, hacking other organizations as well. However, OpenAI’s new report also details unauthorized actions conducted within its own network. Shortly after the Hugging Face incident came to light, OpenAI revealed that its models had discovered and exploited a zero-day vulnerability in JFrog’s Artifactory package registry manager. In addition, the new report reveals that on July 19, unrelated to the Hugging Face hack, some agents exploited a known Linux kernel vulnerability, CVE-2026-53362, to escalate privileges within an OpenAI environment. Agents identified that the Linux kernel version on their underlying machine included a recent, public common vulnerability and exposure (CVE). The agents retrieved the exploit for that CVE (CVE-2026-53362), customized it to succeed on their underlying machine, and leveraged the exploit to escalate privilege. This allowed the agents to act outside one Artifactory container and to obtain root access on the underlying worker node. This then allowed the agents to move laterally throughout the connected environment. CISA on Thursday added both the JFrog flaw, tracked as CVE-2026-66384, and the Linux kernel bug to its Known Exploited Vulnerabilities (KEV) catalog. Advertisement. Scroll to continue reading. The JFrog product weakness should be patched by federal agencies by September 10, but CISA recommends that organizations patch CVE-2026-53362 by August 30. There do not appear to be any other reports describing exploitation of the Linux kernel vulnerability in the wild. However, the OpenAI incident demonstrates its potential value to attackers, which may be why CISA has decided to add it to its KEV catalog. CISA’s KEV list currently includes more than two dozen Linux kernel vulnerabilities. Related: Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says Related: PaperCut Releases Emergency Patch for Exploited Zero-Day Related: Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge Related: Recent Citrix NetScaler Vulnerability Exploited in the Wild Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Cyberattack Causes Global Disruption at Boston ScientificUS Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure AttacksRecent Citrix NetScaler Vulnerability Exploited in the WildAI Speeds Up Malware Development, Not Its Success Rate: AnalysisAdobe and Nvidia Patch Dozens of VulnerabilitiesCISA: Over 100 Internet-Exposed Water Systems Targeted in July CyberattacksChrome 152 Patches Over 300 VulnerabilitiesSensitive Information Exposed in Nutex Health Data Breach Latest News Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense PledgeThink You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco SaysPaperCut Releases Emergency Patch for Exploited Zero-DayTrump Order Aims to Block Foreign Backdoors in US Power Grid GearAustralia Arrests 2 Alleged TeamPCP HackersOpenAI Agents Coordinated via Makeshift Message Board Ahead of Hugging Face HackOkta Shares Surge on Strong Earnings, Growing Demand for AI Identity SecurityCISO Conversations: Chris Wheeler – Trust Is the Job, From the Navy to the C-Suite Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Scaling AI Security August 26, 2026 Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveSocial engineering protection company Doppel has promoted Alyssa Smrekar to Chief Marketing Officer.Naveen Bhateja has been appointed Chief People Officer at HackerOne.The Department of War has appointed Sonu Shankar as Principal Deputy Chief Information Officer.More People On The MoveExpert Insights The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Rethinking Application Security for the AI Era As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. (Joshua Goldfarb) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- cve — CVE-2026-53362
- cve — CVE-2026-66384