Impact
Medium
CVE
CVE-2026-64600
Version(s)
4.x
First published
Last updated

RefluXFS 

We are aware of the recent Local Privilege Escalations (LPEs) exploit RefluXFS. 

It is important to note that this exploit requires local access to a system to be exploited, something that would require an issue with the running micro-services or associated services to have been exposed and exploited in the first instance.

The recently released VQCM 4.9.0 (and all older versions) are impacted by this vulnerability, as such we have put together a playbook to apply the updated kernel version. This should be run on a VQCM 4.9.0 as this version also contains multiple other security fixes. 

Customers who are on 4.9.0 and wish to apply this patch should contact VQ Support. Please be aware that for the fix to take effect the VQCM instance will need to be rebooted, so this patch can not be run during operational hours. 

VQ’s Monthly News – Jul 2026

  • News

VQ Communications Secures Milestone U.S. Army Agreement for Sovereign Collaboration

  • News

VQ’s Monthly News – June 2026

  • News