{"success":true,"data":{"threats":[{"id":"18f7b965-d55f-47dc-be49-2a32767bdd78","slug":"cve-2026-107209","externalId":"CVE-2026-107209","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107209 — ImageMagick is free and open-source software used for editing and manipulating digital images.","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, when ImageMagick is built without Cairo support, a crafted RSVG image that reaches a resource limit can cause the RSVG decoder to free image state twice and then use freed memory, crashing the process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55.","cveId":"CVE-2026-107209","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-415","CWE-416"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ImageMagick/ImageMagick/commit/326451aae51ac2dabc99fe66e063de6ec14cf8c8","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-30","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-f2r2-qw7g-3c8x","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick6/commit/04a4c5b89c034cf2c93bb0a10044332d941b4fa5","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-55","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00315,"epssPercentile":0.22457,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T16:17:45.940Z","addedAt":"2026-10-07T16:39:32.713Z","updatedAt":"2026-10-08T21:05:42.327Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107209","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107209","note":"authoritative record"}]},{"id":"982bc602-3e6b-4756-a88d-35ee3db0bad6","slug":"cve-2026-20532","externalId":"CVE-2026-20532","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-20532 — In apu, there is a possible application crash due to double free.","description":"In apu, there is a possible application crash due to double free. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249024; Issue ID: MSV-9168.","cveId":"CVE-2026-20532","cvssScore":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-415"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.mediatek.com/product-security-bulletin/October-2026","type":"advisory","title":"security@mediatek.com"}],"epssScore":0.00114,"epssPercentile":0.01384,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T02:16:52.033Z","addedAt":"2026-10-05T03:50:40.229Z","updatedAt":"2026-10-06T15:50:56.926Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-20532","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-20532","note":"authoritative record"}]},{"id":"76fd4333-42fb-4140-a2d7-74d1b1d8f00e","slug":"cve-2026-47558","externalId":"CVE-2026-47558","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-47558 — NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause a double-free of impor…","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause a double-free of imported memory state. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cveId":"CVE-2026-47558","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-415"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/NVIDIA/product-security/tree/main/2026/5861","type":"advisory","title":"psirt@nvidia.com"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47558","type":"advisory","title":"psirt@nvidia.com"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-47558","type":"advisory","title":"psirt@nvidia.com"}],"epssScore":0.00136,"epssPercentile":0.02615,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T16:17:24.227Z","addedAt":"2026-09-30T17:50:48.146Z","updatedAt":"2026-10-01T05:50:42.885Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47558","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-47558","note":"authoritative record"}]},{"id":"b6cdcae5-4767-4587-816c-8be552661eae","slug":"cve-2026-89078","externalId":"CVE-2026-89078","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-89078 — GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that unde…","description":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to a double free issue when parsing a specially crafted regular expression in a CI/CD configuration.","cveId":"CVE-2026-89078","cvssScore":9.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L","severity":"critical","vendor":"gitlab","product":"gitlab","affectedVersions":[">= 19.2.0, < 19.2.7",">= 19.3.0, < 19.3.3","19.4.0"],"cwes":["CWE-415"],"tags":["nvd","status:received","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/","type":"vendor","title":"Release Notes"},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/628577","type":"advisory","title":"Issue Tracking"},{"url":"https://hackerone.com/reports/4019059","type":"advisory","title":"Permissions Required"}],"epssScore":0.0044,"epssPercentile":0.36209,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-24T00:17:22.060Z","addedAt":"2026-09-24T01:50:37.041Z","updatedAt":"2026-09-28T15:50:44.209Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89078","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-89078","note":"authoritative record"}]},{"id":"5426939d-76fd-44ed-9923-1182567e8685","slug":"cve-2026-6794","externalId":"CVE-2026-6794","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-6794 — IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that exists due to incorrect memory management.","description":"IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that exists due to incorrect memory management. A local attacker can exploit this flaw to corrupt heap memory and execute arbitrary code in the context of the affected process.","cveId":"CVE-2026-6794","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"ibm","product":"concert","affectedVersions":[">= 1.0.0, <= 3.0.0"],"cwes":["CWE-415"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7288830","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00113,"epssPercentile":0.0134,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-23T21:17:02.177Z","addedAt":"2026-09-23T21:50:38.927Z","updatedAt":"2026-09-28T21:50:38.528Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6794","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-6794","note":"authoritative record"}]},{"id":"96bbbace-447a-4d2a-8731-97041f2d2a6a","slug":"cve-2026-91018","externalId":"CVE-2026-91018","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-91018 — lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the…","description":"lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system.","cveId":"CVE-2026-91018","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-415"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://cgit.git.savannah.gnu.org/cgit/lwip.git","type":"advisory","title":"ics-cert@hq.dhs.gov"},{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-265-02.json","type":"advisory","title":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-02","type":"advisory","title":"ics-cert@hq.dhs.gov"}],"epssScore":0.00241,"epssPercentile":0.13938,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-22T21:17:33.290Z","addedAt":"2026-09-22T21:50:41.542Z","updatedAt":"2026-09-23T19:50:40.257Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91018","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-91018","note":"authoritative record"}]},{"id":"9a1565d1-588d-46e6-97c8-bbb8853b7eb0","slug":"cve-2026-11388","externalId":"CVE-2026-11388","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-11388 — Double Free vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation.","description":"Double Free vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.1.0 before 7.3.1.6.","cveId":"CVE-2026-11388","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-415"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.rti.com/vulnerabilities/#cve-2026-11388","type":"advisory","title":"3f572a00-62e2-4423-959a-7ea25eff1638"}],"epssScore":0.00104,"epssPercentile":0.0096,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-22T18:17:10.520Z","addedAt":"2026-09-22T19:50:41.598Z","updatedAt":"2026-09-22T19:50:41.598Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-11388","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-11388","note":"authoritative record"}]},{"id":"d4587108-de2b-46f8-afdb-6ef9444df2cd","slug":"cve-2026-17050","externalId":"CVE-2026-17050","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-17050 — The experimental USB host stack allocates a per-device configuration-descriptor buffer, udev->cfg_desc, from the dedicated usb_device_heap in usbh_…","description":"The experimental USB host stack allocates a per-device configuration-descriptor buffer, udev->cfg_desc, from the dedicated usb_device_heap in usbh_device_set_configuration() (subsys/usb/host/usbh_device.c). On three failure paths — a failed full-length GET_DESCRIPTOR(CONFIGURATION) read, a mismatch between the short and full descriptor reads, and a rejected descriptor in parse_configuration_descriptor() — the buffer was released with k_heap_free() but the pointer was left dangling. The cleanup in usbh_device_free() is guarded only by if (udev->cfg_desc != NULL), so it frees the same block a second time.\n\nThe path is driven entirely by the attached peripheral: usbh_device_connect() calls usbh_device_init(), which ends in usbh_device_set_configuration(), and on failure usbh_device_connect() calls usbh_device_free(). On v4.4.x this happens during the same enumeration, with no unplug required; on v4.1.0–v4.3.x the second free instead arrives via dev_removed_handler()/dev_connected_handler() in subsys/usb/host/usbh_core.c, so it requires a removal or duplicate-connect event after the failed enumeration — a sequence the attached device fully controls. A malicious or malformed USB device only has to answer the first 9-byte configuration-descriptor request with a well-formed header and then fail any of the three checks, for example by returning a full descriptor whose interface count disagrees with bNumInterfaces, or by answering the second read with different bytes.\n\nThe result is a double free on usb_device_heap. On builds where lib/heap hardening is active (the current default CONFIG_SYS_HEAP_HARDENING_BASIC), sys_heap_free() detects the already-free chunk and calls k_panic(), giving a deterministic, peripheral-triggered denial of service of the USB host. On builds without that detection — earlier releases, or CONFIG_SYS_HEAP_HARDENING_NONE — the second free manipulates a chunk already on the free list, corrupting the heap's free list so that later allocations can return overlapping or invalid blocks.\n\nExploitation beyond denial of service is bounded by the fact that usb_device_heap is a small dedicated heap (CONFIG_USBH_USB_DEVICE_HEAP, default 1024 bytes) whose only client is this descriptor buffer, and by CONFIG_USB_HOST_STACK being marked experimental and disabled by default. The fix sets udev->cfg_desc = NULL after every k_heap_free(), making the cleanup guard sound.","cveId":"CVE-2026-17050","cvssScore":5.7,"cvssVector":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-415"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/zephyrproject-rtos/zephyr/commit/d46a8c1f8fb65e1f80b44bd651a6dafea747602e","type":"advisory","title":"vulnerabilities@zephyrproject.org"},{"url":"https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-r7xw-9jhg-88cm","type":"advisory","title":"vulnerabilities@zephyrproject.org"}],"epssScore":0.00157,"epssPercentile":0.04238,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-21T17:17:34.020Z","addedAt":"2026-09-21T17:50:42.308Z","updatedAt":"2026-09-22T19:50:40.604Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-17050","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-17050","note":"authoritative record"}]},{"id":"21078659-2199-46fd-9cbc-8dd1650ccd23","slug":"cve-2026-20135","externalId":"CVE-2026-20135","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-20135 — A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacke…","description":"A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.\r\n\r\nThis vulnerability is due to improper buffer management during the TLS 1.3 connection. An attacker could exploit this vulnerability by sending a crafted TLS 1.3 packet to an affected system through a TLS 1.3-enabled listening socket. A successful exploit could allow the attacker to cause the LINA process to crash, which would cause the device to reload. The reload can happen before or after authentication of the connection.Note:&nbsp;TLS 1.3 connections include both data traffic and user-management traffic.","cveId":"CVE-2026-20135","cvssScore":8.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-415"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-tls1.3-dos-dLxwFWgF","type":"advisory","title":"psirt@cisco.com"}],"epssScore":0.00457,"epssPercentile":0.3765,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-16T21:17:07.587Z","addedAt":"2026-09-16T21:50:38.994Z","updatedAt":"2026-09-18T13:50:50.496Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-20135","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-20135","note":"authoritative record"}]},{"id":"70b262de-d294-4918-b6a5-a95ab089952a","slug":"cve-2026-84561","externalId":"CVE-2026-84561","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84561 — A double free issue was addressed with improved memory management.","description":"A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory.","cveId":"CVE-2026-84561","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":"apple","product":"ipados","affectedVersions":["< 26.7",">= 15.0, < 15.8",">= 26.0, < 26.7","< 27.0"],"cwes":["CWE-415"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.apple.com/en-us/149034","type":"vendor","title":"Release Notes"},{"url":"https://support.apple.com/en-us/149035","type":"vendor","title":"Release Notes"},{"url":"https://support.apple.com/en-us/149036","type":"vendor","title":"Release Notes"},{"url":"https://support.apple.com/en-us/149037","type":"vendor","title":"Release Notes"},{"url":"https://support.apple.com/en-us/149038","type":"vendor","title":"Release Notes"},{"url":"https://support.apple.com/en-us/149041","type":"vendor","title":"Release Notes"},{"url":"https://support.apple.com/en-us/149042","type":"vendor","title":"Release Notes"},{"url":"https://support.apple.com/en-us/149043","type":"vendor","title":"Release Notes"}],"epssScore":0.0068,"epssPercentile":0.50928,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-14T21:17:32.173Z","addedAt":"2026-09-14T21:50:39.530Z","updatedAt":"2026-09-16T19:50:39.444Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84561","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84561","note":"authoritative record"}]},{"id":"89fe4c55-9398-44c4-8cbc-3f7f36bcf227","slug":"cve-2026-84558","externalId":"CVE-2026-84558","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84558 — A double free issue was addressed with improved memory management.","description":"A double free issue was addressed with improved memory management. This issue is fixed in macOS Golden Gate 27. An app may be able to cause unexpected system termination.","cveId":"CVE-2026-84558","cvssScore":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"apple","product":"macos","affectedVersions":["< 27.0"],"cwes":["CWE-415"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.apple.com/en-us/149035","type":"vendor","title":"Release Notes"}],"epssScore":0.00153,"epssPercentile":0.03869,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-14T21:17:31.863Z","addedAt":"2026-09-14T21:50:39.514Z","updatedAt":"2026-09-17T17:50:42.532Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84558","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84558","note":"authoritative record"}]},{"id":"5b21a5bd-ed9e-47f1-805c-8b204f3dd21d","slug":"cve-2026-85921","externalId":"CVE-2026-85921","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-85921 — Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.","description":"Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.","cveId":"CVE-2026-85921","cvssScore":8.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","severity":"high","vendor":"microsoft","product":"windows 11 26h1","affectedVersions":["< 10.0.28000.2956"],"cwes":["CWE-415"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85921"],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85921","type":"patch","title":"Patch"}],"epssScore":0.00348,"epssPercentile":0.26356,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-14T18:20:20.047Z","addedAt":"2026-09-14T19:50:36.024Z","updatedAt":"2026-09-29T19:50:40.148Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85921","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-85921","note":"authoritative record"}]},{"id":"953d72f7-b2d5-444c-ab61-89d9ca9d9fc8","slug":"cve-2026-23790","externalId":"CVE-2026-23790","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-23790 — An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600.","description":"An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A double-free vulnerability in the Samsung Exynos DPU driver (due to improper pointer management during DMA buffer reallocation) leads to kernel memory corruption and a potential use-after-free.","cveId":"CVE-2026-23790","cvssScore":4.2,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:L","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-415"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://semiconductor.samsung.com/support/quality-support/product-security-updates/","type":"advisory","title":"cve@mitre.org"},{"url":"https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2026-23790/","type":"advisory","title":"cve@mitre.org"}],"epssScore":0.00091,"epssPercentile":0.00467,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-14T02:17:13.537Z","addedAt":"2026-09-14T03:50:34.577Z","updatedAt":"2026-09-22T21:50:38.864Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-23790","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-23790","note":"authoritative record"}]},{"id":"3d4ca250-a1cc-4c90-84ee-be786c55ac9b","slug":"cve-2026-23789","externalId":"CVE-2026-23789","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-23789 — An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580,…","description":"An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC encoder driver (due to improper cleanup of dma_buf references during error handling) leads to kernel memory corruption and potential arbitrary code execution.","cveId":"CVE-2026-23789","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-415"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://semiconductor.samsung.com/support/quality-support/product-security-updates/","type":"advisory","title":"cve@mitre.org"},{"url":"https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2026-23789/","type":"advisory","title":"cve@mitre.org"}],"epssScore":0.00109,"epssPercentile":0.01138,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-14T02:17:13.397Z","addedAt":"2026-09-14T03:50:34.571Z","updatedAt":"2026-09-22T21:50:38.859Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-23789","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-23789","note":"authoritative record"}]},{"id":"25322d8d-60f2-4811-b1a4-865c012a6f89","slug":"cve-2026-57842","externalId":"CVE-2026-57842","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-57842 — NetBSD contains a use-after-free and double-free vulnerability in msg_recv_copyin() within the COMPAT_NETBSD32 compatibility layer due to a missing…","description":"NetBSD contains a use-after-free and double-free vulnerability in msg_recv_copyin() within the COMPAT_NETBSD32 compatibility layer due to a missing return statement before the cleanup label on the success path. Any local user able to execute a 32-bit binary on a 64-bit NetBSD system can trigger a kernel panic or memory corruption by calling recvmsg() with msg_iovlen between 9 and IOV_MAX, causing the kernel to access a freed iovec buffer and subsequently free the same allocation a second time.","cveId":"CVE-2026-57842","cvssScore":7.3,"cvssVector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-415","CWE-416"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://gnats.netbsd.org/60373","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/netbsd-compat-netbsd32-double-free-use-after-free-via-recvmsg-msg-iovlen","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00135,"epssPercentile":0.02558,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-11T14:17:27.873Z","addedAt":"2026-09-11T15:50:35.601Z","updatedAt":"2026-09-24T21:50:41.716Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57842","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-57842","note":"authoritative record"}]},{"id":"7a78d9de-6368-4fe4-a774-3f39baa1bfcf","slug":"cve-2026-61915","externalId":"CVE-2026-61915","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-61915 — An issue was discovered in Cyrus IMAP before 3.12.4.","description":"An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION=\"BYPARAM@...\" against a resource with two or more properties of the matched kind. The memory holding the selector would be freed once on each iteration over the properties.","cveId":"CVE-2026-61915","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H","severity":"high","vendor":"cyrus","product":"imap","affectedVersions":["< 3.8.8",">= 3.9.0, < 3.10.4",">= 3.11.0, < 3.12.4"],"cwes":["CWE-415"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://cyrusimap.org/","type":"advisory","title":"Product"},{"url":"https://www.cyrusimap.org/3.12/imap/download/release-notes/3.10/x/3.10.4.html","type":"advisory","title":"Release Notes"},{"url":"https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.4.html","type":"advisory","title":"Release Notes"},{"url":"https://www.cyrusimap.org/3.12/imap/download/release-notes/3.8/x/3.8.8.html","type":"advisory","title":"Release Notes"}],"epssScore":0.00259,"epssPercentile":0.16106,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-09T20:18:36.943Z","addedAt":"2026-09-09T21:50:43.008Z","updatedAt":"2026-09-16T15:50:40.695Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61915","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-61915","note":"authoritative record"}]},{"id":"d7bc6cc3-8f9a-46d9-8a61-9010f10d620f","slug":"cve-2026-87585","externalId":"CVE-2026-87585","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87585 — Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside …","description":"Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)","cveId":"CVE-2026-87585","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 153.0.8010.36"],"cwes":["CWE-415"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed","msrc","vendor-advisory","microsoft","cve"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87585"],"references":[{"url":"https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/540817065","type":"advisory","title":"Permissions Required"},{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87585","type":"vendor","title":"Microsoft MSRC: Chromium CVE-2026-87585: Double free in PDFium"}],"epssScore":0.00382,"epssPercentile":0.30031,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-09T01:17:16.357Z","addedAt":"2026-09-09T01:50:34.364Z","updatedAt":"2026-09-15T01:52:57.464Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87585","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87585","note":"authoritative record"}]},{"id":"84e1477a-8e59-4b6a-8ae3-76a61853d382","slug":"cve-2026-79907","externalId":"CVE-2026-79907","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-79907 — Acrobat Reader is affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user.","description":"Acrobat Reader is affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.","cveId":"CVE-2026-79907","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"adobe","product":"acrobat","affectedVersions":[">= 24.001.20604, < 24.001.30429",">= 15.008.20082, < 26.002.21901"],"cwes":["CWE-415"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://helpx.adobe.com/security/products/acrobat/apsb26-141.html","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00293,"epssPercentile":0.20077,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-08T21:18:42.363Z","addedAt":"2026-09-08T21:50:42.437Z","updatedAt":"2026-09-10T17:50:35.778Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-79907","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-79907","note":"authoritative record"}]},{"id":"21bb20e8-e0ec-4739-82ac-be0e3363deea","slug":"cve-2026-81950","externalId":"CVE-2026-81950","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-81950 — Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.","description":"Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.","cveId":"CVE-2026-81950","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"microsoft","product":"365 apps","affectedVersions":["2016"],"cwes":["CWE-415"],"tags":["nvd","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81950"],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81950","type":"patch","title":"Patch"}],"epssScore":0.00466,"epssPercentile":0.38419,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-08T18:20:58.460Z","addedAt":"2026-09-08T19:50:43.126Z","updatedAt":"2026-09-17T21:50:36.490Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81950","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-81950","note":"authoritative record"}]},{"id":"df78a513-d1b0-4acf-ae01-eeb5ae5d07a6","slug":"cve-2026-80080","externalId":"CVE-2026-80080","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-80080 — Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.","description":"Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.","cveId":"CVE-2026-80080","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"microsoft","product":"365 apps","affectedVersions":["2016"],"cwes":["CWE-415"],"tags":["nvd","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80080"],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80080","type":"patch","title":"Patch"}],"epssScore":0.00819,"epssPercentile":0.55892,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-08T18:20:50.233Z","addedAt":"2026-09-08T19:50:42.848Z","updatedAt":"2026-09-17T21:50:36.262Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80080","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-80080","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":210,"totalPages":11,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T01:53:57.074Z","durationMs":29,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-415"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}