Qualys has announced the discovery of CVE-2026-64600, dubbed “RefluXFS,” a critical Linux kernel vulnerability uncovered through a structured research initiative between the Qualys Threat Research Unit (TRU) and Anthropic’s Claude Mythos Preview. The vulnerability is a race condition in the Linux kernel’s XFS filesystem copy-on-write path that allows an attacker with an ordinary local account to overwrite protected files on disk and gain host root privileges on affected systems, including deployments running SELinux in Enforcing mode.
According to Qualys’ analysis, the vulnerability has existed since Linux kernel version 4.11 (2017) and potentially affects more than 16.4 million systems worldwide, including deployments running Red Hat Enterprise Linux (RHEL), Oracle Linux, Amazon Linux and Fedora.
“This discovery emerged from a structured research initiative between Qualys and Anthropic, where we integrated Claude Mythos Preview into our manual audit workflow to accelerate our research while maintaining strict human oversight,” said Saeed Abbasi, Head of the Qualys Threat Research Unit (TRU). “This human-validated, AI-accelerated approach let us surface a complex kernel race condition while holding to the strict accuracy and responsible-disclosure standards expected; every finding here cleared the same evidence bar we apply to any Qualys security advisory.”
Qualys said RefluXFS enables an unprivileged local user to overwrite the on-disk contents of any readable file on a reflink-enabled XFS volume, a capability that “converts directly into host root privileges.” The company added that exploitation is highly reliable, leaves no kernel log output and that on-disk modifications survive a system reboot.
“We rate RefluXFS as an emergency priority because exploitation could begin from ordinary local privileges. The vulnerability is present in standard enterprise kernel builds, and a successful exploitation provides host root. The exploitation works under common kernel hardening settings, and fixed kernels are available,” Abbasi added.
Qualys recommends organizations apply vendor-supplied kernel updates as soon as they become available and reboot affected systems after patching to ensure protected workloads start on the updated kernel. The company also advises prioritizing exposed and multi-tenant systems for remediation. Vendor-fixed kernels are now available and are being backported to enterprise Linux distributions.
According to Qualys, there are currently no reliable or practical mitigations or temporary configuration changes available.
