Canonical has recently addressed three critical vulnerabilities in snapd, a key component of the Ubuntu operating system. These vulnerabilities pose a significant risk, as they could allow local users to gain root access.
The vulnerabilities were patched on July 21, 2026, and users are strongly urged to update their systems without delay to mitigate potential exploitation.
This update is particularly crucial for those using default Ubuntu Desktop installations, where low-privilege accounts could exploit these flaws to gain full root access.
Updates
Update at 09:45 UTC on 2026-07-23
Wimantis blog - Ubuntu reported Canonical patched three snapd CVEs on July 21, including two high-severity privilege escalation flaws that hand a low-privilege account full root on default Ubuntu Desktop installs.
Sources: Wimantis blog - Ubuntu
