These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,211 reserved CVEs with public mentions, ranked by all-time mention count.
Page 24 of 49
First seen Jul 22, 2026
First seen Jul 22, 2026
First seen Jul 22, 2026
First seen Jul 22, 2026
First seen Jul 22, 2026
First seen Jul 22, 2026
First seen Jul 20, 2026
CVE-2026-46495 is a pre-authentication remote code execution vulnerability in OpenDJ Community Edition affecting the JMX RMI connector. The flaw is caused by unsafe Java deserialization of untrusted data received by the JMX RMI listener before authentication is completed. An unauthenticated attacker with network reachability to the exposed JMX service can supply a crafted serialized object stream and trigger deserialization in the target JVM. In environments where suitable gadget chains are present on the runtime classpath, successful exploitation can result in arbitrary code execution. Unauthenticated remote code execution was demonstrated against OpenDJ 4.4.15 running on JDK 11 with Jackson 2.12.6.1 present in the classpath.
CVE-2026-46495First seen Jun 23, 2026
First seen Jul 20, 2026
CVE-2026-54503 is a stored cross-site scripting vulnerability affecting plone.app.textfield and related Plone deployments using RichText rendering, including environments exposing the issue through plone.restapi. The flaw arises when attacker-controlled RichText content is stored with a spoofed MIME type such that the stored mimeType matches the outputMimeType. In that condition, expected safe_html sanitization is bypassed and unsanitized RichText content can be rendered directly. This allows malicious script content embedded in persisted RichText fields to be stored server-side and later executed in the browsers of users who view the affected content.
CVE-2026-54503First seen Jun 23, 2026
CVE-2026-53713 is an authentication bypass and path traversal vulnerability in Envoy Gateway's EnvoyExtensionPolicy Lua handling. Improper input validation in the logic intended to protect critical file-access paths allows an attacker who can submit Lua code through an EnvoyExtensionPolicy to evade traversal protections by using redundant path separators. By bypassing these checks, the attacker can cause the gateway controller pod to read arbitrary files from its filesystem, including sensitive operating system files, Kubernetes service account material, TLS certificates, and process environment data. The issue stems from insufficient normalization and validation of path input before enforcing traversal restrictions.
CVE-2026-53713First seen Jun 12, 2026
First seen Jul 17, 2026
First seen Jul 17, 2026
First seen Jul 17, 2026
First seen Jul 17, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026