Canonical has patched CVE-2026-11386, a critical vulnerability in Ubuntu Pro Client / ubuntu-advantage-tools that can allow arbitrary code execution as root. The flaw stems from unsafe handling of contract server response data when the client writes APT source files, using untrusted fields such as directives.suites[] and directives.aptURL without proper escaping or newline filtering. Researchers reported that an attacker able to spoof or tamper with the contract response could inject malicious APT configuration entries and abuse the unvalidated additionalPackages[] field passed to a root-executed package installation process.
Canonical addressed the issue in USN-8555-1, assigning the bug a CVSS 3.1 score of 9.0 and releasing fixes for supported Ubuntu LTS versions in ubuntu-pro-client versions 37.3 and later. The exposure is notable because Ubuntu Pro Client is preinstalled on supported Ubuntu Server releases and auto-attaches by default on some cloud-provider Ubuntu Pro images, potentially widening impact across servers and cloud instances. Canonical said Ubuntu 25.10 was not patched because it is end of life, and advised administrators to update immediately, inspect APT source files for unauthorized entries, verify contract response integrity, and disable the client where patching is not possible.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
Canonical released fixes in USN-8555-1 on July 16, 2026 for CVE-2026-11386, a critical Ubuntu Pro Client / ubuntu-advantage-tools vulnerability that could allow arbitrary code execution as root via malicious APT directive and package injection. The fixes covered supported Ubuntu LTS releases, while Ubuntu 25.10 was not patched because it was end of life.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.