These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,099 reserved CVEs with public mentions, ranked by all-time mention count.
Page 3 of 44
First seen Oct 7, 2026
First seen Oct 7, 2026
First seen Oct 7, 2026
First seen Oct 7, 2026
CVE-2026-42491, documented in Xen Security Advisory XSA-498, affects TLS verification in the XAPI C# and PowerShell SDKs. Certain HTTP handlers establish secondary connections to an XAPI host without properly verifying TLS, although the main RPC connection is verified correctly or delegates verification appropriately. The flaw has existed since TLS support was introduced in these bindings. An attacker able to intercept traffic between an affected application and an XAPI host can steal session tokens or read and modify transferred data.
CVE-2026-42491First seen Jul 14, 2026
CVE-2026-91148 is an insufficient input-sanitization vulnerability in Cockpit's handling of URLs received from PackageKit. The Cockpit 368-1 changelog associates the vulnerability with a change to sanitize these URLs. The precise vulnerable function, affected version range, exploitation mechanism, and resulting security impact are not established.
CVE-2026-91148First seen Sep 24, 2026
CVE-2026-53614 is an unsafe environment-variable handling vulnerability in util-linux libmount when used by the SUID mount utility. Improper handling of LIBMOUNT_FORCE_MOUNT2 may allow a local attacker to bypass nosuid and noexec mount restrictions and gain elevated privileges. The specifically described Ubuntu exposure affects Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. Debian, Echo, and SUSE security updates also reference this CVE, but the complete affected-version range and distribution-specific exploitation conditions are not established.
CVE-2026-53614First seen Aug 14, 2026
CVE-2026-84711 is an argument-injection vulnerability in Red Hat Ansible Automation Controller project synchronization. Attacker-controlled Project scm_branch or scm_refspec values can be interpreted as Git arguments during a project sync, rather than solely as a branch or refspec. This permits arbitrary file reads from the host performing the synchronization. Affected releases include Ansible Automation Platform 2.4, 2.5, and 2.6 Automation Controller deployments.
CVE-2026-84711First seen Sep 23, 2026
CVE-2026-84638 is an authorization flaw in Red Hat Ansible Automation Controller/AWX instance-group attachment handling. When attaching an instance group to a Schedule or WorkflowJobTemplateNode, the controller verifies only read permission on the instance group rather than enforcing the authorization required to assign it. A user with read access can therefore associate a restricted instance group with scheduling or workflow execution objects.
CVE-2026-84638First seen Sep 23, 2026
CVE-2026-84684 is an authorization flaw in Red Hat Ansible Automation Platform Automation Controller/AWX constructed-inventory attachment handling. The attachment authorization check requires only read permission on the source inventory, rather than enforcing the authorization required to attach and use that inventory. This permits an authorized low-privilege user to attach a source inventory they can read to a constructed inventory in a manner that bypasses intended tenant and privilege boundaries.
CVE-2026-84684First seen Sep 23, 2026
CVE-2026-53612 is a time-of-check/time-of-use race condition in the libmount ownership hook in util-linux. The flaw can allow a local attacker to race filesystem ownership-related operations and potentially obtain elevated privileges. It is reported to affect Ubuntu 24.04 LTS and Ubuntu 26.04 LTS.
CVE-2026-53612First seen Aug 14, 2026
CVE-2026-86340First seen Sep 11, 2026
CVE-2026-67416 is an improper-input-validation vulnerability in RabbitMQ's AMQP 1.0 message handling. Symbolic AMQP 1.0 body descriptor values that collide on a prefix can bypass validation, causing RabbitMQ to accept a descriptor that should be rejected.
CVE-2026-67416First seen Aug 19, 2026
CVE-2026-50055 is a mail forwarding restriction bypass vulnerability in Zimbra Collaboration Suite. The flaw allows an authenticated user to circumvent configured mail forwarding restrictions and exfiltrate email despite those restrictions being enabled. Publicly available information does not provide deeper technical detail about the vulnerable code path or function, but the issue is characterized as a security restriction bypass affecting enforcement of forwarding controls.
CVE-2026-50055First seen Jul 21, 2026
CVE-2025-2774 is a high-severity vulnerability in Webmin, the web-based system administration panel, affecting versions prior to 2.302. The flaw is caused by improper neutralization of CRLF sequences in CGI requests, allowing a remote authenticated attacker to submit specially crafted requests that alter request handling in a security-relevant way. Successful exploitation can lead to privilege escalation and arbitrary code execution, with execution occurring in the context of the root user on affected systems.
CVE-2025-2774First seen Jan 17, 2026
The available context indicates that CVE-2026-46626 affects the Symfony Runtime component and is described in upstream security notes as: "[Runtime] Fix CVE-2024-50340 patch bypass by gating argv on $_SERVER['QUERY_STRING']". This indicates a bypass of a prior security fix in the Runtime component, where insufficient gating or validation around argv handling allowed the original protection for CVE-2024-50340 to be circumvented. The precise vulnerable function, code path, and exploit mechanics are not provided in the supplied content.
CVE-2026-46626First seen May 20, 2026
CVE-2026-4047 is an authentication bypass vulnerability in Qinglong affecting version 2.20.1 and earlier. The flaw is caused by a mismatch between Qinglong’s authentication middleware and Express.js routing behavior: the authentication check treats protected paths such as /api/ as case-sensitive, while the router matches paths case-insensitively. As a result, an unauthenticated attacker can send requests to altered path variants such as /aPi/... to bypass authentication and reach endpoints intended to be protected. According to the provided reporting, this issue was documented in GitHub Issue #2934 and was observed to enable direct remote code execution by reaching protected functionality without first resetting credentials.
CVE-2026-4047First seen Apr 28, 2026
CVE-2025-48932 is a critical SQL Injection vulnerability in Invision Community versions up to 4.7.20, specifically within the calendar application's view.php script. The vulnerability arises from improper sanitization of the 'location' parameter in the search() method, allowing remote, unauthenticated attackers to inject arbitrary SQL queries. Exploitation requires the calendar application and a configured GeoLocation feature (such as Google Maps). The vulnerability can be leveraged to read sensitive database data, and in versions prior to 4.7.18, may enable admin account takeover or remote code execution via password reset mechanisms.
CVE-2025-48932First seen Mar 18, 2026
CVE-2026-63347 is a path traversal vulnerability in suricata-update, the Suricata rule-update utility. The utility did not properly validate destination paths while extracting files referenced by downloaded rule archives. A crafted archive or malformed rules can use traversal sequences to cause extraction outside the configured Suricata rules directory, enabling overwrite of files elsewhere on the system.
CVE-2026-63347First seen Aug 27, 2026
CVE-2026-79604 is an uncontrolled resource consumption vulnerability in oxenstored, Xen's OCaml Xenstored implementation. Oxenstored tracks Xen watches in both a global trie and per-domain hash tables. On a requested Xenbus reconnect, it fails to remove the affected watches from the global trie. A guest can repeatedly trigger this condition and accumulate stale watch entries indefinitely, causing unbounded memory consumption. Xen versions from 4.6 onward are affected when configured to use OCaml Xenstored; the C Xenstored implementation is not affected.
CVE-2026-79604First seen Sep 9, 2026
CVE-2026-85747 is a security vulnerability in docker-distribution addressed by Fedora 46 package version 3.1.2-1.fc46. The vulnerability mechanism, affected functions, affected version range, and exploitation impact are currently unavailable.
CVE-2026-85747First seen Sep 24, 2026
CVE-2026-6949 is an Important-severity vulnerability affecting Samba. Available assessment information characterizes it as network-accessible, low-complexity, and exploitable without privileges or user interaction, with high integrity impact. The vulnerable component, flaw mechanism, and affected function have not been specified.
CVE-2026-6949First seen Jul 28, 2026
CVE-2026-68546 is a heap out-of-bounds write in Exiv2's RemoteIo::Impl::populateBlocks() function. The vulnerable RemoteIo code path is used when Exiv2 processes a remote URL rather than a local file. A malicious remote server or attacker-controlled URL processed through this functionality can trigger the memory-corruption condition. Exiv2 versions earlier than 0.28.9 are affected.
CVE-2026-68546First seen Aug 31, 2026
CVE-2024-9370 is a high-severity incorrect-optimization vulnerability in the V8 JavaScript engine used by Google Chrome. Maglev escape analysis can incorrectly elide an inlined allocation for a constructor’s receiver object when the constructor returns a primitive and no subsequent use of the receiver is visible to the optimizer. If Error() is invoked in that constructor, stack traversal can encounter the elided receiver and violate a V8 materialization invariant, resulting in a CHECK failure. The invariant violation may be exploitable for memory corruption and arbitrary code execution in the renderer process.
CVE-2024-9370First seen Apr 19, 2026
CVE-2026-85498 is a regression in the fix for CVE-2026-4897 affecting polkit's setuid polkit-agent-helper-1 helper. The read_cookie() function incorrectly handles an empty cookie read from standard input: its string-length calculation underflows, causing a one-byte out-of-bounds read from a stack buffer. This condition can crash polkit and may permit arbitrary code execution with administrator privileges.
CVE-2026-85498First seen Sep 4, 2026