These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,109 reserved CVEs with public mentions, ranked by all-time mention count.
Page 11 of 45
CVE-2026-9238 affects QEMU packages and is addressed by an Echo security update. It is also included in Oracle Linux 9 security advisory ELSA-2026-500220 alongside other QEMU vulnerabilities. Details of the underlying flaw, vulnerable function, affected-version range, and exploitation mechanism are currently unavailable.
CVE-2026-9238First seen Aug 24, 2026
CVE-2026-6425 affects QEMU packages and is also referenced in Oracle Linux 9 security advisory ELSA-2026-500220. The underlying weakness, vulnerable function, and exploitation mechanism are currently not available.
CVE-2026-6425First seen Aug 24, 2026
CVE-2026-12072 is a path traversal vulnerability in the Python Natural Language Toolkit (NLTK) NKJPCorpusReader. Insufficient validation of fileids accepted by its public read methods allows paths outside the intended corpus root to be accessed, bypassing nltk.pathsec sandbox protections even when enforcement is enabled. The header() method can directly disclose out-of-root file contents, while other reader methods can open and read such files.
CVE-2026-12072First seen Aug 1, 2026
CVE-2026-77913 is an out-of-bounds write vulnerability in QEMU's VGA text-mode display handling. The flaw occurs after a graphics-surface switch and can cause an out-of-bounds write during text-mode rendering.
CVE-2026-77913First seen Sep 30, 2026
CVE-2026-16271 is an improper input-validation issue in QEMU's QXL display-device handling. The flaw involves failure to validate a primary surface's stride against its width. Amazon Linux identifies the issue in the qemu package on Amazon Linux 2 Core; Amazon Linux 2023 and Amazon Linux 2027 Preview are listed as not affected.
CVE-2026-16271First seen Sep 30, 2026
CVE-2026-17588 is an important local vulnerability in QEMU's xHCI USB host-controller emulation component, hw/usb/hcd-xhci. The flaw involves a missing reentrancy guard in timer functions, which can permit unsafe reentrant execution in the emulated controller.
CVE-2026-17588First seen Sep 30, 2026
CVE-2026-96369First seen Sep 24, 2026
CVE-2026-84788 affects QEMU's io/channel-socket handling of zero-length writes. A zero-length write is treated as an error rather than handled as a non-error condition, resulting in incorrect exceptional-condition handling.
CVE-2026-84788First seen Sep 30, 2026
CVE-2026-66899First seen Sep 30, 2026
CVE-2026-66900 concerns QEMU's virtio-net device implementation when caching a Receive Segment Coalescing (RSC) segment. The associated fix strips trailing padding during RSC-segment caching. Available information does not establish the underlying vulnerability class, affected version range, or security impact.
CVE-2026-66900First seen Sep 30, 2026
First seen Sep 30, 2026
First seen Oct 1, 2026
CVE-2026-62439 is an Important-severity vulnerability in GIMP. Technical details, including the affected function and vulnerability class, are not available. The issue is fixed by GIMP commit 4427b9f31552060aafa5b03caee6ffdd6c257c8b and is addressed in GIMP 3.2.6.
CVE-2026-62439First seen Sep 30, 2026
CVE-2026-96544 is an integer overflow vulnerability in GIMP's PVR image loader. In pvr_decode_rect(), unchecked multiplication of attacker-controlled image dimensions can overflow, causing an undersized heap allocation. Processing the crafted PVR image can subsequently cause an out-of-bounds read.
CVE-2026-96544First seen Sep 25, 2026
CVE-2026-96543 is an out-of-bounds heap write vulnerability in GIMP's PVR image loader. When GIMP loads a crafted non-square PVR texture, the pvr_decode_twiddle() function does not bounds-check its destination offset and can write attacker-controlled pixel data past the end of a correctly allocated heap buffer.
CVE-2026-96543First seen Sep 25, 2026
CVE-2026-95622 is a reachable assertion vulnerability in ModemManager while parsing Cell Broadcast Messages. Certain 3GPP data-coding-scheme values, including 8-bit and reserved character sets, are not handled. A crafted Cell Broadcast PDU can cause the ModemManager process to hit an assertion and abort.
CVE-2026-95622First seen Sep 26, 2026
First seen Sep 30, 2026
CVE-2026-102672 is a time-of-check to time-of-use race condition in Electron on macOS affecting applications that use the bundled Squirrel.Mac auto-update framework. During an application update, a local attacker can race the privileged ShipIt helper and cause it to overwrite files owned by a different application with root privileges.
CVE-2026-102672First seen Sep 29, 2026
CVE-2026-49264 is a cross-site scripting vulnerability in oauthlib's RevocationEndpoint. When JSONP is enabled, the endpoint reflects an unvalidated JSONP callback parameter, permitting generation of attacker-controlled JavaScript.
CVE-2026-49264First seen Sep 29, 2026
First seen Sep 30, 2026
CVE-2026-65954 is an arbitrary code execution vulnerability in phpcsstandards/phpcsutils. The issue arises from use of eval() in AbstractArrayDeclarationSniff::getActualArrayKey(). When a PHPCS sniff that invokes this method scans malicious, untrusted PHP source, attacker-controlled PHP can execute in the context of the host running PHPCS.
CVE-2026-65954First seen Sep 29, 2026
CVE-2026-101895 is a denial-of-service vulnerability in Angular Server-Side Rendering (SSR) applications using @angular/platform-server. The Domino DOM-emulation parser can enter an infinite synchronous parsing loop when it processes an incomplete DOCTYPE declaration that ends in whitespace at end-of-file. This uncontrolled parsing behavior consumes CPU and prevents the Node.js SSR process from servicing requests.
CVE-2026-101895First seen Sep 29, 2026
First seen Sep 29, 2026
First seen Sep 29, 2026
CVE-2026-61478 is an error-handling flaw in libvirt XML context parsing. libvirt does not properly handle parsing errors, which may allow an attacker to trigger a libvirt process crash and deny service.
CVE-2026-61478First seen Aug 11, 2026