These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,097 reserved CVEs with public mentions, ranked by all-time mention count.
Page 1 of 44
CVE-2026-53921 is a critical stack-based buffer overflow in OpenWrt's odhcpd service, specifically in the DHCPv6 Identity Association reply serialization path. The flaw is described as involving a fixed 512-byte stack buffer that can be overrun when odhcpd processes crafted DHCPv6 REQUEST packets and appends reply data without sufficient remaining-capacity checks. Available reporting indicates the vulnerable code path is associated with older odhcpd versions containing the DHCPv6 handling functions dhcpv6_ia_handle_IAs() and build_ia(). Under attacker-controlled IA option layouts, odhcpd can write beyond the allocated stack buffer while constructing a DHCPv6 reply. Because odhcpd runs with root privileges by default on affected OpenWrt systems, successful exploitation can result in severe compromise.
CVE-2026-53921First seen Jun 30, 2026
CVE-2026-59774 is a critical arbitrary file-read vulnerability in the markup rendering functionality of Gitea and Forgejo. The flaw is triggered through the Org-mode renderer used by the markup endpoint for repository content rendering. Affected implementations initialize the go-org library without overriding its default ReadFile callback, allowing Org-mode #+INCLUDE directives to resolve and read absolute paths from the server filesystem. As a result, an attacker can submit crafted Org-mode markup to the repository markup rendering endpoint and cause the application to include the contents of local files in the rendered response. Reported affected versions include Gitea 1.22.1 through 1.27.0, fixed in 1.27.1, and Forgejo 7.0 through 15.0.5 and 16.0.0 through 16.0.1, fixed in 15.0.6 and 16.0.2.
CVE-2026-59774First seen Aug 4, 2026
CVE-2026-10797 is a legacy flaw in the Linux shim UEFI bootloader, affecting old Microsoft-signed shim builds primarily based on version 0.9 and earlier. The vulnerability lies in shim's certificate-based revocation logic for second-stage PE bootloaders: an Authenticode-signed PE binary stores signature length information in two separate structures, and vulnerable shim code reads the signature size from the wrong PE structure during revocation checking while using different data during signature verification. By tampering with the second-stage bootloader's WIN_CERTIFICATE header, an attacker can cause shim to compare dbx or MokListX revocation entries against bogus certificate data instead of the bootloader's actual signature. This allows a revoked or otherwise blocked second-stage boot component to pass the revocation check while still being accepted as signed. In practice, the flaw undermines UEFI Secure Boot trust decisions in environments that continue to trust old Microsoft-signed shim binaries.
CVE-2026-10797First seen Jun 14, 2026
CVE-2026-9672 is an input-validation vulnerability in libgd, the graphics library used by GD and PHP's GD component. Processing a malformed GIF file can trigger the flaw. Affected distributions include Debian libgd2 and GD-related packages for Amazon Linux; PHP security releases also upgraded libgd to address the issue. Exploitation may cause a denial of service and could potentially permit arbitrary code execution.
CVE-2026-9672First seen Jul 31, 2026
CVE-2026-44772 is a critical code injection vulnerability in SAP Manufacturing Integration and Intelligence (SAP MII), affecting XMII and MII_ADMIN versions 15.4 and 15.5. A vulnerable servlet accepts specially crafted input that causes SAP MII to retrieve and process attacker-controlled content from an external source. This processing can be abused to inject code and execute arbitrary commands on the underlying host. SAP assigned the issue a CVSS score of 9.9.
CVE-2026-44772First seen Aug 11, 2026
CVE-2025-70951First seen Apr 3, 2026
First seen Sep 27, 2026
CVE-2026-2270 is a confused-deputy vulnerability in the StatefulSet controller of Kubernetes kube-controller-manager. Before the fix, the controller could restore attacker-controlled fields beyond the StatefulSet spec from a ControllerRevision. A user holding namespace-scoped write permissions to both StatefulSet and ControllerRevision resources could cause the cluster-wide controller to create a pod in a different namespace. The resulting pod's metadata and specification, including its namespace, can be attacker-controlled.
CVE-2026-2270First seen Sep 24, 2026
CVE-2026-52682 is an uncontrolled resource-consumption vulnerability in PowerDNS Authoritative Server, PowerDNS Recursor, and dnsdist. Processing a specially crafted DNS packet from a malicious DNS server can cause excessive memory and CPU consumption, resulting in a denial-of-service condition. Affected releases include Authoritative Server 4.9.16, 5.0.6, and 5.1.3; Recursor 5.2.12, 5.3.9, and 5.4.4; and dnsdist 1.9.15, 2.0.7, and 2.1.0.
CVE-2026-52682First seen Aug 6, 2026
The provided content identifies CVE-2026-38264 as a Linux kernel vulnerability in the nvme-tcp subsystem, described by SUSE as "nvme-tcp: sanitize request list handling." It is referenced in cumulative SUSE kernel security advisories affecting products including SUSE Linux Enterprise Server 16.0, SUSE Linux Micro 6.2, SUSE Linux Micro Extras 6.2, and related package sets built from kernel version 6.12.0-160000.6.1. No further technical root-cause detail, vulnerable function name, trigger condition, or upstream commit information is provided in the supplied content beyond the fact that the fix sanitizes request list handling in nvme-tcp.
CVE-2026-38264First seen Jun 27, 2026
CVE-2026-12184 is a high-impact vulnerability in PHP’s HTTP stream wrapper implementation. The flaw is triggered during HTTP connection handling when Transport Layer Security initialization fails. In the vulnerable logic, PHP closes and resets the internal stream object after the TLS setup failure, but subsequent cleanup code continues to operate as though the stream object remains valid. This results in unsafe operations on a null reference and can crash the PHP process handling the request. The issue affects PHP versions earlier than 8.3.32, 8.4.21, and 8.5.6.
CVE-2026-12184First seen Jul 6, 2026
CVE-2026-100754 affects a script interpreter in OpenAI's ChatGPT app for macOS. The interpreter accepted external commands that could be injected into the trusted ChatGPT process, abusing the operating system's trust in that process. Exploitation required a user to execute malicious code locally and could allow an attacker to take over the assistant and access its entire conversation history and other stored data. OpenAI fixed the vulnerability in an update released in late September 2026.
CVE-2026-100754First seen Sep 30, 2026
CVE-2026-53613 is a time-of-check/time-of-use vulnerability in the libmount component of util-linux affecting mount target-path handling. The race condition allows target-path redirection during mount operations and may enable a local attacker to gain elevated privileges.
CVE-2026-53613First seen Aug 14, 2026
CVE-2026-76654 is a medium-severity improper link resolution vulnerability in Kubernetes kubelet on Windows nodes. A pod volumeMount subPath can be configured as a symbolic link to an attacker-controlled UNC network share. Vulnerable kubelet versions resolve that link without rejecting UNC targets and transparently initiate NTLM authentication to the remote share. Fixed kubelet versions reject symlink targets resolving to UNC paths.
CVE-2026-76654First seen Sep 24, 2026
CVE-2026-65094 is a CWE-123 write-what-where vulnerability in the NVIDIA BlueField-3 Virtio-Net implementation, affecting NVIDIA Networking BlueField/ConnectX VIRTIO-Net deployments. A virtual-machine user can send a crafted message that causes data to be written to unintended memory locations. The resulting arbitrary-write condition can lead to code execution within the Virtio-Net scope. CVE-2025-33209 was withdrawn and replaced by this identifier.
CVE-2026-65094First seen Jul 28, 2026
CVE-2026-18576 is a high-severity authentication bypass vulnerability in N-able N-central, the vendor’s remote monitoring and management platform. The flaw has been described as an authentication bypass using an alternate path or channel and affects N-central versions prior to 2026.3, with reporting indicating impact through at least version 2026.1 before subsequent fixes. Successful exploitation allows an unauthenticated attacker to hijack or take over administrative accounts. The initial vendor patch was incomplete, and attackers were able to continue exploiting the issue until an emergency hotfix was released.
CVE-2026-18576First seen Aug 3, 2026
CVE-2026-13136 is a critical authorization flaw in Synology MailPlus Server on DiskStation Manager (DSM). The vulnerability is associated with CWE-863 (Incorrect Authorization) and allows a remote attacker to access functionality without authentication over the network. Successful exploitation can enable arbitrary file read and arbitrary file write operations and can also be used to trigger denial-of-service conditions. The issue affects MailPlus Server deployments on DSM 7.3, 7.2.2, and 7.2.1 prior to the fixed releases identified by Synology.
CVE-2026-13136First seen Jun 27, 2026
CVE-2026-57155 is a critical vulnerability in OPNsense fixed in version 26.7. The flaw affects GeoIP-related functionality exposed through the Web API, where insufficient validation of a user-supplied URL or file path allows path traversal during GeoIP data handling. An authenticated administrator can abuse the GeoIP alias import mechanism to cause arbitrary file creation or overwrite in attacker-controlled filesystem locations while the operation runs with root privileges. By placing a crafted configuration file in a privileged location processed by the system, the attacker can escalate from administrative access in the application to execution of shell commands as root on the underlying firewall appliance.
CVE-2026-57155First seen Jul 1, 2026
CVE-2026-82374 is a null-pointer dereference vulnerability in the crypt module of the ZNC IRC bouncer. An IRC server can trigger the flaw, potentially causing ZNC to become unavailable. The issue is fixed in upstream ZNC 1.10.3 and in Debian 13's security-maintained package version 1.9.1-2+deb13u1.
CVE-2026-82374First seen Sep 13, 2026
CVE-2026-46675 is a use-after-free vulnerability in the sequential reader of libpng versions 1.6.0 through 1.6.58. Incomplete decompression of crafted zTXt, iTXt, or iCCP chunks can leave a stale zlib input pointer and input count after the chunk handler releases the stream. If an application calls png_read_end after png_read_info without first starting to read image rows, decompression can resume using that stale pointer. For zTXt and iTXt chunks, subsequent chunk-buffer reallocation can produce a heap use-after-free; for iCCP chunks, the pointer can reference expired local arrays, producing a stack use-after-return. Exploitation can cause an application crash. libpng 1.6.59 fixes the vulnerability.
CVE-2026-46675First seen Sep 29, 2026
CVE-2026-54154 affects Kiteworks Email Protection Gateway releases before 9.4.1. A combination of input-handling flaws in publicly reachable endpoints can potentially allow an unauthenticated remote attacker to execute arbitrary code. The exploitation chain involves path traversal, code injection, and missing authentication; additional local weaknesses can enable escalation to root-level control of the appliance. Specific vulnerable functions are not identified.
CVE-2026-54154First seen Oct 1, 2026
CVE-2026-94603 is a sandbox bypass vulnerability in Podman's handling of container images carrying checkpoint annotations. When such an image is executed with podman run, Podman treats it as a restored checkpoint and ignores user-specified sandboxing options, including dropped privileges. An attacker can entice a user to execute a specially crafted image, potentially allowing execution with elevated system privileges.
CVE-2026-94603First seen Sep 29, 2026
CVE-2026-61642 is a CWE-841 improper enforcement of behavioral workflow vulnerability in Squid that permits HTTP/1.1 Transfer-Encoding request smuggling. A client trusted by the affected Squid proxy can smuggle requests through the HTTP/1.1 processing path, bypassing security mechanisms deployed between that client and Squid. If an HTTP cache is positioned upstream of the affected Squid instance, the flaw can also be used to inject attacker-controlled content into cached URLs.
CVE-2026-61642First seen Sep 14, 2026
First seen Sep 27, 2026
CVE-2026-62356 is a buffer-size calculation error in Redis CMSketch handling during Redis Database (RDB) loading. A malformed or specially constructed RDB can cause Redis to perform a heap-based out-of-bounds write while loading CMSketch data.
CVE-2026-62356First seen Aug 17, 2026