{"success":true,"data":{"threats":[{"id":"558423d1-a566-45f4-a62c-406cf3d4a2e4","slug":"cve-2026-83745","externalId":"CVE-2026-83745","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-83745 — Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift \nnodejs and D lang …","description":"Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift \nnodejs and D lang bindings.\n\nBoth bindings' WebSocket server transports read the payload length out of the frame header and allocate that many bytes immediately, without checking that the bytes have arrived. A single ~14-byte frame therefore commits as much memory as it cares to declare -- measured at 513 MiB against the Node.js server and 2 GiB against the D transport -- and in the Node.js case the connection is left open afterwards, so the frame can simply be sent again.\n\n\n\n\nThis issue affects Apache Thrift before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-83745","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-130","CWE-789"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/64y7f0b89mnq4xoqcn4h26to8kskolgc","type":"advisory","title":"security@apache.org"}],"epssScore":0.00426,"epssPercentile":0.34844,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T13:17:58.927Z","addedAt":"2026-10-02T13:50:40.968Z","updatedAt":"2026-10-02T19:50:41.425Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-83745","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-83745","note":"authoritative record"}]},{"id":"4c356280-9498-4b13-a591-25f48d858a22","slug":"cve-2026-94633","externalId":"CVE-2026-94633","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-94633 — Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Dart bindings.","description":"Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Dart bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-94633","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-130","CWE-789"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/cxkbblyht7988p2o6yvnmd6536qmt88k","type":"advisory","title":"security@apache.org"}],"epssScore":0.00426,"epssPercentile":0.34843,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T11:17:38.247Z","addedAt":"2026-10-02T11:50:39.894Z","updatedAt":"2026-10-02T15:50:40.666Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94633","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-94633","note":"authoritative record"}]},{"id":"f3231a65-aa82-4b1d-beb9-20e536084cd7","slug":"cve-2026-85494","externalId":"CVE-2026-85494","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-85494 — Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size …","description":"Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size value, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python, Ruby, Erlang, Lua, Dart, JavaME, Perl, PHP and D language bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-85494","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-130","CWE-248","CWE-407","CWE-789","CWE-1188"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/rm0m34gt6fh1flvt16wty559hfg191qr","type":"advisory","title":"security@apache.org"}],"epssScore":0.00467,"epssPercentile":0.38463,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T11:17:36.010Z","addedAt":"2026-10-02T11:50:39.855Z","updatedAt":"2026-10-08T00:39:29.153Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85494","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-85494","note":"authoritative record"}]},{"id":"4a56902a-ea8a-4c25-9e7d-7986168ddff2","slug":"cve-2026-94635","externalId":"CVE-2026-94635","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-94635 — Allocation of resources without limits or throttling, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Lua bindings.","description":"Allocation of resources without limits or throttling, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Lua bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-94635","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-130","CWE-770"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/ow8994gb5g8ssmmbkbl48xqb0tpvqyr3","type":"advisory","title":"security@apache.org"}],"epssScore":0.00426,"epssPercentile":0.34846,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T10:17:09.630Z","addedAt":"2026-10-02T11:50:39.795Z","updatedAt":"2026-10-02T17:50:40.309Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94635","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-94635","note":"authoritative record"}]},{"id":"e908b7f7-c7a5-4881-9800-32fd3cc8de85","slug":"cve-2026-18397","externalId":"CVE-2026-18397","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-18397 — This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesse…","description":"This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component.\n\nThe attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks.","cveId":"CVE-2026-18397","cvssScore":9.4,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-130","CWE-252","CWE-347","CWE-457"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.thalesgroup.com/en/product-security-incident-response","type":"advisory","title":"psirt@thalesgroup.com"}],"epssScore":0.00337,"epssPercentile":0.25018,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T22:17:01.220Z","addedAt":"2026-10-01T23:50:39.516Z","updatedAt":"2026-10-02T21:50:40.069Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18397","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-18397","note":"authoritative record"}]},{"id":"4a78467a-7dbb-40d0-9ba8-cfe30fe37885","slug":"cve-2026-87022","externalId":"CVE-2026-87022","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87022 — Improper handling of length parameter inconsistency vulnerability in Apache Tomcat allows WebSocket message smuggling when per-message-deflate is u…","description":"Improper handling of length parameter inconsistency vulnerability in Apache Tomcat allows WebSocket message smuggling when per-message-deflate is used.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121.\n\n\n\nThe following versions were EOS at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.56 through 7.0.109. Other unsupported versions may also be affected.\n\n\n\nUsers are recommended to upgrade to version 11.0.26, 10.1.60 or 9.1.22, which fix the issue.","cveId":"CVE-2026-87022","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-130"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/ypvlkjqsq0480fnk9jm6h9qllddwlw4w","type":"advisory","title":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/23/30","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"}],"epssScore":0.00422,"epssPercentile":0.34507,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-23T12:17:08.640Z","addedAt":"2026-09-23T13:50:38.745Z","updatedAt":"2026-09-23T19:50:41.349Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87022","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87022","note":"authoritative record"}]},{"id":"f1a16aea-1d01-48c3-b848-3dc9620f4ae4","slug":"cve-2026-77619","externalId":"CVE-2026-77619","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-77619 — Vector is a high-performance observability data pipeline.","description":"Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source reads a 32-bit compressed-frame length from the network and uses it to size an in-memory buffer without an upper bound. An unauthenticated remote peer that can reach the default 0.0.0.0:5044 listener can send a minimal frame declaring a multi-gigabyte payload, causing an excessive allocation that can abort Vector or invoke the host OOM killer. Because the allocation follows the declared length rather than bytes transmitted, the attacker has low resource cost, and process termination can halt log ingestion for every tenant on a shared pipeline. This issue is fixed in version 0.57.0.","cveId":"CVE-2026-77619","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-130","CWE-789"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/vectordotdev/vector/commit/3162ed1a2e5e8d3f210134607518a26aa01e1a37","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/vectordotdev/vector/pull/25819","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/vectordotdev/vector/releases/tag/v0.57.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/vectordotdev/vector/security/advisories/GHSA-rrfg-9487-mhp6","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00524,"epssPercentile":0.4261,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-22T16:17:55.333Z","addedAt":"2026-09-22T17:50:43.166Z","updatedAt":"2026-09-24T21:50:43.578Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77619","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-77619","note":"authoritative record"}]},{"id":"0f4c1f77-e56b-4203-aea5-b154a92249ed","slug":"cve-2023-5778","externalId":"CVE-2023-5778","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2023-5778 — Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Co…","description":"Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900.\n\nThis issue affects Freelance Controller DCP: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC700: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC800: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC900: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1.","cveId":"CVE-2023-5778","cvssScore":9.2,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:H/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-130"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://search.abb.com/library/Download.aspx?DocumentID=7PAA010706&LanguageCode=en&DocumentPartId=&Action=Launch","type":"advisory","title":"cybersecurity@ch.abb.com"}],"epssScore":0.00288,"epssPercentile":0.19613,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-18T14:17:14.870Z","addedAt":"2026-09-18T15:50:39.935Z","updatedAt":"2026-09-18T19:50:40.899Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-5778","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2023-5778","note":"authoritative record"}]},{"id":"a4c0192e-f341-4a0b-ad26-01d8a0509fa9","slug":"cve-2026-73455","externalId":"CVE-2026-73455","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-73455 — On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafted packet can cause the OSPF…","description":"On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafted packet can cause the OSPFv3 agent to restart unexpectedly.","cveId":"CVE-2026-73455","cvssScore":8.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-130"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24729-security-advisory-0173","type":"advisory","title":"psirt@arista.com"}],"epssScore":0.00497,"epssPercentile":0.40648,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-16T10:16:52.243Z","addedAt":"2026-09-16T11:50:38.412Z","updatedAt":"2026-09-16T19:50:46.271Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73455","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-73455","note":"authoritative record"}]},{"id":"9e242710-69ec-40da-adb5-20d8f24154f7","slug":"cve-2026-90678","externalId":"CVE-2026-90678","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-90678 — An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5.","description":"An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 frontend: HAProxy must be built with QUIC support and configured with a QUIC bind listener, and the affected traffic must reach a backend over HTTP/1.1 using chunked transfer coding on a reused connection. Under those conditions, when an HTTP/3 request carries no Content-Length header, the HTTP/3 multiplexer credits the length declared in a DATA frame header to the stream endpoint's known-input-payload estimate at the moment the frame header is decoded, before the payload has been received, and that declared length is emitted verbatim as the HTTP/1.1 chunk size. A remote unauthenticated client that declares more payload than it delivers and then ends the stream causes HAProxy to announce a chunk larger than the bytes it writes and to return the connection to the idle pool in a desynchronized state. The result is potential HTTP request smuggling on reused backend connections: an attacker can place a request past a frontend rule such as a path-based http-request deny, so that the smuggled request is never seen by HAProxy's HTTP analysis, and can cause concurrent clients' requests, including their request lines and Authorization headers, to be consumed as the attacker's request body and lost. Exploitation is not deterministic; it depends on a race with backend connection pooling, succeeding in a majority of but not all trials during testing, and can be retried freely. The mechanism was introduced in 3.3-dev10; releases 3.2.x and earlier are unaffected.","cveId":"CVE-2026-90678","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:L","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-130"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"http://git.haproxy.org/?p=haproxy.git;a=commit;h=86a4ebc761a278838e8cb06f3a292282ba704c65","type":"advisory","title":"cve@mitre.org"},{"url":"https://github.com/haproxy/haproxy/commit/86a4ebc761a278838e8cb06f3a292282ba704c65","type":"advisory","title":"cve@mitre.org"},{"url":"https://www.haproxy.org/download/3.5/src/CHANGELOG","type":"advisory","title":"cve@mitre.org"}],"epssScore":0.0077,"epssPercentile":0.54245,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-13T04:17:25.227Z","addedAt":"2026-09-13T05:50:33.989Z","updatedAt":"2026-09-22T21:50:38.737Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90678","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-90678","note":"authoritative record"}]},{"id":"fca4c179-82cc-4fb2-9a7c-2dd16fa18413","slug":"cve-2026-15418","externalId":"CVE-2026-15418","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-15418 — In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to l…","description":"In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to leak up to 145 bytes of uninitialized kernel pool memory. This vulnerability affects Windows 10 and earlier.","cveId":"CVE-2026-15418","cvssScore":2.4,"cvssVector":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-130"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/069Vm0000100HA6IAM?operationContext=S1","type":"advisory","title":"product-security@silabs.com"}],"epssScore":0.00154,"epssPercentile":0.04004,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-10T18:17:55.450Z","addedAt":"2026-09-10T19:50:35.237Z","updatedAt":"2026-09-10T21:50:36.072Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15418","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-15418","note":"authoritative record"}]},{"id":"26ede0cc-1e0b-4bfc-97ec-b8241b9567d3","slug":"cve-2026-71337","externalId":"CVE-2026-71337","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-71337 — Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.","description":"Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.","cveId":"CVE-2026-71337","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"microsoft","product":"windows 10 21h2","affectedVersions":["< 10.0.19044.7725","< 10.0.19045.7725","< 10.0.22631.7582","< 10.0.26100.9445","< 10.0.26200.9445","< 10.0.28000.2954","< 10.0.20348.5622","< 10.0.26100.33438"],"cwes":["CWE-121","CWE-130"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71337"],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71337","type":"patch","title":"Patch"}],"epssScore":0.00333,"epssPercentile":0.24601,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-08T18:20:13.430Z","addedAt":"2026-09-08T19:50:41.725Z","updatedAt":"2026-09-15T13:50:40.792Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71337","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-71337","note":"authoritative record"}]},{"id":"bfaf2423-9b2f-481b-ac1f-ac6ed0e22800","slug":"cve-2026-5706","externalId":"CVE-2026-5706","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-5706 — In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote …","description":"In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution. These messages must come from a device that has already joined the network. Only provisioners supporting extended advertisements may be impacted.","cveId":"CVE-2026-5706","cvssScore":8.9,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-130"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/SiliconLabs/gecko_sdk/releases","type":"advisory","title":"product-security@silabs.com"},{"url":"https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/a45Vm000000Et6HIAS?operationContext=S1","type":"advisory","title":"product-security@silabs.com"}],"epssScore":0.00391,"epssPercentile":0.31134,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-28T00:18:07.853Z","addedAt":"2026-08-28T01:50:37.140Z","updatedAt":"2026-09-08T19:50:35.417Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5706","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-5706","note":"authoritative record"}]},{"id":"775a0c8c-b469-460d-9dee-9f7b7bb42660","slug":"cve-2026-71402","externalId":"CVE-2026-71402","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-71402 — An out-of-bounds read was found in the DHCPv4 packet capture code of wicked.","description":"An out-of-bounds read was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/capture.c reports the IP total length as the payload length instead of the length of the remaining UDP payload. Consequently, the DHCP option walker in the DHCPv4 client (wickedd-dhcp4) reads up to ihl + 8 bytes — at most 68 bytes — past the end of the 1500-byte packet receive buffer. An unauthenticated attacker on the same network who sends a crafted DHCP/UDP packet can make the client parse adjacent heap memory as DHCP options, so that heap contents such as allocator metadata or pointer values can be interpreted into lease fields. The over-read is bounded to 68 bytes; no memory write, no attacker control over the adjacent bytes and no remote exfiltration primitive has been demonstrated. This issue affects wicked up to and including version 0.6.80.","cveId":"CVE-2026-71402","cvssScore":5.3,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-125","CWE-130"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://bugzilla.suse.com/show_bug.cgi?id=1274627","type":"advisory","title":"meissner@suse.de"},{"url":"https://github.com/openSUSE/wicked/pull/1079","type":"advisory","title":"meissner@suse.de"}],"epssScore":0.00247,"epssPercentile":0.14677,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-27T17:19:44.980Z","addedAt":"2026-08-27T17:50:35.719Z","updatedAt":"2026-09-01T21:50:32.457Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71402","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-71402","note":"authoritative record"}]},{"id":"748a1425-32f7-44b1-aaf7-030a3d88e1ec","slug":"cve-2026-81575","externalId":"CVE-2026-81575","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-81575 — If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and\nth…","description":"If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and\nthe data itself. Missing bounds checking on the data length value can lead to out of bounds reads, causing a\nsegmentation fault that ultimately crashes the CodeMeter Runtime.","cveId":"CVE-2026-81575","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-130"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/AdvisoryWIBU-103401.pdf","type":"advisory","title":"2fc02b1f-71e7-4514-a878-169626f68903"}],"epssScore":0.0046,"epssPercentile":0.37887,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-27T10:16:40.197Z","addedAt":"2026-08-27T11:50:29.727Z","updatedAt":"2026-09-01T21:50:32.423Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81575","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-81575","note":"authoritative record"}]},{"id":"e1879abc-aa6d-4c95-92d5-7dbebac2cf98","slug":"cve-2026-58097","externalId":"CVE-2026-58097","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-58097 — mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface.","description":"mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface.\n\nA local user with access to the ppp(8) command interface can crash ppp(8) or potentially execute arbitrary code as root.","cveId":"CVE-2026-58097","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"freebsd","product":"freebsd","affectedVersions":["14.4","15.0","15.1"],"cwes":["CWE-122","CWE-130"],"tags":["nvd","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://security.freebsd.org/advisories/FreeBSD-SA-26:60.ppp.asc","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00166,"epssPercentile":0.05344,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-26T06:16:26.700Z","addedAt":"2026-08-26T17:50:45.760Z","updatedAt":"2026-09-10T15:50:34.847Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58097","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-58097","note":"authoritative record"}]},{"id":"41cd7b4e-d498-464e-a439-21909e134ef1","slug":"cve-2026-58096","externalId":"CVE-2026-58096","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-58096 — LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717.","description":"LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717.  Undersized options would trigger an out-of-bounds write.\n\nA malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or potentially execute arbitrary code as root.","cveId":"CVE-2026-58096","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"freebsd","product":"freebsd","affectedVersions":["14.4","15.0","15.1"],"cwes":["CWE-130","CWE-787"],"tags":["nvd","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://security.freebsd.org/advisories/FreeBSD-SA-26:60.ppp.asc","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00604,"epssPercentile":0.47251,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-26T06:16:26.577Z","addedAt":"2026-08-26T17:50:45.755Z","updatedAt":"2026-09-10T15:50:34.837Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58096","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-58096","note":"authoritative record"}]},{"id":"d5560653-ba8e-40fb-913b-fb8e7b88c0bc","slug":"cve-2026-14587","externalId":"CVE-2026-14587","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-14587 — Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask.","description":"Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask. When an unauthenticated client sends a selected protocol version followed by 32 continuation bytes in the capability mask, the decoder resets the reader index and waits for more bytes instead of rejecting the protocol message and closing the channel.\n\n\n\nBecause the same unread bytes remain at the front of the decoder buffer, appending a terminating byte later does not recover the connection. The decoder re-reads the same first 32 continuation bytes, returns without producing a handshake-finalization message, and leaves the channel open.\n\n\n\nThis can be triggered before authentication by any client that can reach the Bolt connector.","cveId":"CVE-2026-14587","cvssScore":5.5,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":"neo4j","product":"neo4j","affectedVersions":[">= 5.0, < 5.26.29",">= 2025.01, < 2026.07",">= 5.0.0, < 5.26.29",">= 2025.01.0, < 2026.07.0"],"cwes":["CWE-130"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://neo4j.com/security/CVE-2026-14587","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00542,"epssPercentile":0.43799,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-05T17:16:41.120Z","addedAt":"2026-08-05T17:50:25.799Z","updatedAt":"2026-08-28T17:50:33.590Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14587","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-14587","note":"authoritative record"}]},{"id":"194461c6-3e1a-4a6a-8a80-56201640169d","slug":"cve-2026-67292","externalId":"CVE-2026-67292","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-67292 — FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/core/gateway/websocket.c).","description":"FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/core/gateway/websocket.c). The client's Pong reply reuses a fixed 1024-byte response stream whose length is not sealed to the actual received Ping payload, so a malicious gateway/WebSocket peer sending a non-empty Ping control frame causes the client to reply with an overlong Pong that discloses bytes beyond the received payload (the peer receives the masking key and can unmask the reply). A zero-length Ping reaches an assertion and terminates the client (denial of service).","cveId":"CVE-2026-67292","cvssScore":9.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":"freerdp","product":"freerdp","affectedVersions":["< 3.29.0"],"cwes":["CWE-130"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/FreeRDP/FreeRDP/commit/f3b4347105114fe7453828736bea069999af319f","https://www.vulncheck.com/advisories/freerdp-before-websocket-ping-buffer-over-disclosure"],"references":[{"url":"https://github.com/FreeRDP/FreeRDP/commit/f3b4347105114fe7453828736bea069999af319f","type":"patch","title":"Patch"},{"url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-8v6m-2cmc-chx9","type":"vendor","title":"Exploit"},{"url":"https://www.vulncheck.com/advisories/freerdp-before-websocket-ping-buffer-over-disclosure","type":"patch","title":"Patch"}],"epssScore":0.00479,"epssPercentile":0.39351,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-01T13:16:58.240Z","addedAt":"2026-08-01T13:33:43.228Z","updatedAt":"2026-09-11T21:50:34.402Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67292","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-67292","note":"authoritative record"}]},{"id":"13983742-c2c3-4c1a-a4c2-d631d8e1f47d","slug":"cve-2026-62424","externalId":"CVE-2026-62424","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-62424 — [This CNA information record relates to multiple CVEs; the\ntext explains which aspects/vulnerabilities correspond to which CVE.]\n\nThe directory and…","description":"[This CNA information record relates to multiple CVEs; the\ntext explains which aspects/vulnerabilities correspond to which CVE.]\n\nThe directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver\nderives several lengths directly from attacker-controlled on-disk fields\nwithout validating them:\n\n * The directory loop itself assumes a good record length.  This is\n   CVE-2026-42494.\n\n * The calculation of the System Use area may underflow.  This is\n   CVE-2026-42495.\n\n * The Rock Ridge extension loop assumes a good (inner) record length.\n   This is CVE-2026-62423.\n\n * The Rock Ridge NM record processing assumes a good entry length.\n   This is CVE-2026-62424.\n\n * The Rock Ridge CE record processing assumes a good size and offset.\n   This is CVE-2026-62425.","cveId":"CVE-2026-62424","cvssScore":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-130"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://xenbits.xenproject.org/xsa/advisory-497.html","type":"advisory","title":"security@xen.org"}],"epssScore":0.00198,"epssPercentile":0.08687,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-28T13:19:01.310Z","addedAt":"2026-07-28T20:12:40.049Z","updatedAt":"2026-07-28T20:12:40.049Z","epssUpdatedAt":"2026-10-07T12:00:27.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62424","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-62424","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":37,"totalPages":2,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T00:25:37.228Z","durationMs":19,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-130"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}