Artificial Intelligence

OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems

CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.

Linux vulnerability

Around the time some OpenAI models escaped their testing environment and hacked Hugging Face, some agents exploited a Linux kernel vulnerability to escalate privileges on OpenAI’s own systems.

This was mentioned in a report published by OpenAI this week to detail the incident in which its models hacked Hugging Face in July. The AI giant’s investigation found that agents used an unauthorized makeshift message board to communicate and plan their actions, including encouraging one another to hack what they correctly guessed were real systems rather than test environments. 

Rogue agents went beyond Hugging Face, hacking other organizations as well. However, OpenAI’s new report also details unauthorized actions conducted within its own network.

Shortly after the Hugging Face incident came to light, OpenAI revealed that its models had discovered and exploited a zero-day vulnerability in JFrog’s Artifactory package registry manager.

In addition, the new report reveals that on July 19, unrelated to the Hugging Face hack, some agents exploited a known Linux kernel vulnerability, CVE-2026-53362, to escalate privileges within an OpenAI environment.

Agents identified that the Linux kernel version on their underlying machine included a recent, public common vulnerability and exposure (CVE). The agents retrieved the exploit for that CVE (CVE-2026-53362), customized it to succeed on their underlying machine, and leveraged the exploit to escalate privilege. This allowed the agents to act outside one Artifactory container and to obtain root access on the underlying worker node. This then allowed the agents to move laterally throughout the connected environment.

CISA on Thursday added both the JFrog flaw, tracked as CVE-2026-66384, and the Linux kernel bug to its Known Exploited Vulnerabilities (KEV) catalog. 

Advertisement. Scroll to continue reading.

The JFrog product weakness should be patched by federal agencies by September 10, but CISA recommends that organizations patch CVE-2026-53362 by August 30.

There do not appear to be any other reports describing exploitation of the Linux kernel vulnerability in the wild. However, the OpenAI incident demonstrates its potential value to attackers, which may be why CISA has decided to add it to its KEV catalog. 

CISA’s KEV list currently includes more than two dozen Linux kernel vulnerabilities.

Related: Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says

Related: PaperCut Releases Emergency Patch for Exploited Zero-Day

Related: Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge

Related: Recent Citrix NetScaler Vulnerability Exploited in the Wild

Related Content

Artificial Intelligence

Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated. 

Artificial Intelligence

New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.

Vulnerabilities

A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.

Artificial Intelligence

New training environments will teach AI models to distrust instructions arriving from other agents outside sanctioned channels.

Artificial Intelligence

For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality.

Vulnerabilities

CISA is urging government agencies to immediately patch the Citrix NetScaler vulnerability tracked as CVE-2026-8452.

Artificial Intelligence

Palo Alto Networks Unit 42 analyzed 405 AI-linked malware samples and found only 12 reached production endpoints.

Vulnerabilities

Adobe and Nvidia each published several advisories, including ones that address critical vulnerabilities in their products.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version