Qualys Discovers Critical Linux Kernel Vulnerability Affecting More Than 16 Million Systems

Qualys Discovers Critical Linux Kernel Vulnerability Affecting More Than 16 Million Systems

AI-assisted research with Anthropic’s Claude Mythos Preview uncovers “RefluXFS” flaw that enables attackers to gain root privileges on enterprise Linux environments

Qualys has announced the discovery of CVE-2026-64600, a critical Linux kernel vulnerability named “RefluXFS,” which could allow attackers with standard local user access to escalate privileges and gain full root control of affected systems.

The vulnerability was identified through a collaborative research initiative between the Qualys Threat Research Unit (TRU) and Anthropic’s Claude Mythos Preview, combining AI-assisted analysis with human-led security research. According to Qualys, the flaw exists within the Linux kernel’s XFS filesystem copy-on-write mechanism and has been present since Linux kernel version 4.11, released in 2017.

Qualys estimates that more than 16.4 million systems worldwide may be affected, including deployments running major enterprise Linux distributions such as Red Hat Enterprise Linux (RHEL), Oracle Linux, Amazon Linux, and Fedora.

“This discovery emerged from a structured research initiative between Qualys and Anthropic, where we integrated Claude Mythos Preview into our manual audit workflow to accelerate our research while maintaining strict human oversight.”

Saeed Abbasi, Head of Qualys Threat Research Unit (TRU)

The vulnerability stems from a race condition in the XFS filesystem that allows an unprivileged local user to overwrite protected files on disk. Researchers found that successful exploitation can lead directly to host-level root access, even on systems protected by common hardening mechanisms, including SELinux running in Enforcing mode.

According to Qualys, exploitation of RefluXFS is highly reliable and particularly concerning because it leaves no kernel log evidence while allowing malicious file modifications to persist even after a system reboot. This makes detection and forensic investigation significantly more difficult.

The company emphasized that the discovery highlights the growing role of AI-assisted security research. While Anthropic’s Claude Mythos Preview helped accelerate the identification of the complex kernel flaw, Qualys stressed that all findings underwent rigorous human validation and responsible disclosure processes before publication.

Given the severity of the issue, Qualys has classified RefluXFS as an emergency-priority vulnerability and is urging organizations to apply vendor-issued kernel updates immediately. Security teams are advised to prioritize remediation on internet-facing, shared, and multi-tenant systems where the impact of privilege escalation could be particularly severe.

Vendor-fixed kernels have already been released and are being backported across affected enterprise Linux distributions. Qualys noted that there are currently no practical workarounds or temporary mitigation measures, making patching the only reliable defense.

The discovery underscores the ongoing importance of Linux kernel security and highlights how AI-assisted research can help uncover sophisticated vulnerabilities that may otherwise remain hidden in critical infrastructure software for years.