Published on September 28, 2026, notice USN-8487-2 says that update USN-8487-1 included an incomplete fix for CVE-2026-8927, which this new update corrects. The text also lists curl flaws with possible effects including use of an unintended TLS configuration, unauthorized access to authenticated resources, exposure of cookies or credentials, denial of service, and, in some cases, code execution. Impacts depend on the flaw and Ubuntu release; the notice names, among others, LTS releases from 16.04 through 24.04, and releases 25.10 and 26.04 for specific vulnerabilities.
To check the scope, find notice USN-8487-2 in the official Ubuntu Security channel and verify the CVE identifiers, affected releases, and fixed packages. The supplied text is an automatic translation and is truncated, so it should not replace the original notice or be treated as a complete list. If using AI to study or apply the guidance, do not submit credentials, customer data, or internal configurations; verify recommendations and commands against official documentation before running them.