These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,099 reserved CVEs with public mentions, ranked by all-time mention count.
Page 4 of 44
CVE-2026-85498 is a regression in the fix for CVE-2026-4897 affecting polkit's setuid polkit-agent-helper-1 helper. The read_cookie() function incorrectly handles an empty cookie read from standard input: its string-length calculation underflows, causing a one-byte out-of-bounds read from a stack buffer. This condition can crash polkit and may permit arbitrary code execution with administrator privileges.
CVE-2026-85498First seen Sep 4, 2026
CVE-2026-59177 is an authentication-bypass vulnerability in the ESPHome Home Assistant add-on ingress dashboard. In affected host-network deployments, the dashboard's intentionally unauthenticated ingress service binds to all network interfaces rather than being restricted to the Home Assistant Supervisor path. Direct access from the local network bypasses Supervisor ingress authentication, granting an unauthenticated user the same effective dashboard capabilities as an authenticated caller. The issue is classified as CWE-1327, Binding to an Unrestricted IP Address.
CVE-2026-59177First seen Sep 10, 2026
CVE-2026-62261 is a protection-mechanism failure in Open Identity Platform OpenAM's Groovy script sandbox. An authenticated attacker can escape the intended Groovy sandbox restrictions and achieve remote code execution in the OpenAM environment.
CVE-2026-62261First seen Jul 31, 2026
CVE-2021-27748 is a server-side request forgery vulnerability in HCL Digital Experience, including on-premises and container deployments. Proxy functionality could make server-side requests through configured outbound connections. Restricted destination policies could be bypassed by chaining requests through an open redirect on an allowlisted external service, causing the Digital Experience server to request attacker-selected arbitrary URLs. The issue affects Portal proxy functionality and was addressed through HCL maintenance and removal of the relevant outbound HTTP connection configuration.
CVE-2021-27748First seen Aug 14, 2026
CVE-2026-58221 is an authenticated access control vulnerability in Samba Active Directory. The issue affects Samba AD deployments and is associated with authenticated LDAP access that can permit an attacker to progress to domain takeover. Publicly available context identifies the flaw at a high level but does not provide sufficient technical detail about the specific vulnerable code path, function, or protocol handling logic involved.
CVE-2026-58221First seen Jul 28, 2026
CVE-2026-71385 is an incorrect authorization vulnerability in Adobe ColdFusion. It is one of several authorization-related flaws addressed in Adobe ColdFusion 2025 and 2023 security updates. The issue stems from improper enforcement of authorization controls, which can allow an attacker to bypass intended access restrictions within the application. Specific vulnerable functions or code paths are not available from the provided information.
CVE-2026-71385First seen Aug 11, 2026
CVE-2026-53918 is a high-severity use-after-free vulnerability in OpenWrt's odhcpd, affecting the DHCPv6 Identity Association (IA) handler. Available details indicate the flaw arises from a dangling first-lease pointer during DHCPv6 IA processing, causing the handler to retain and later dereference freed memory. Because odhcpd is a default-enabled network service in OpenWrt and the issue is described as remotely triggerable, a network-adjacent attacker can reach the vulnerable code path by sending crafted DHCPv6 traffic that exercises IA handling.
CVE-2026-53918First seen Jun 30, 2026
First seen Apr 30, 2026
CVE-2026-35328 is a vulnerability in libtls involving processing of the TLS supported_versions extension. According to the provided context, malformed or otherwise problematic handling of this extension can cause the affected code path to enter an infinite loop during TLS processing.
CVE-2026-35328First seen Apr 22, 2026
CVE-2026-66020 affects QEMU packages. Information about the technical cause, vulnerable functions, exploitation mechanism, and security impact is currently unavailable.
CVE-2026-66020First seen Aug 28, 2026
CVE-2026-66022 affects the QEMU package on Amazon Linux 2. The technical flaw, affected QEMU components, attack vector, and precise vulnerable version range are currently not available. Upstream QEMU fixes are identified in versions 11.0.4 and 11.1.0-rc2.
CVE-2026-66022First seen Aug 30, 2026
CVE-2026-63110 affects QEMU packages and is addressed by upstream and distribution security updates. The vulnerable component, function, underlying flaw, and exploitation mechanism are currently not available.
CVE-2026-63110First seen Aug 30, 2026
CVE-2026-18724 is a stack-based buffer overflow in the open-iscsi idbm_recinfo_config function during idbm record parsing. The vulnerability affects open-iscsi packages distributed by Debian and through Amazon Linux iscsi-initiator-utils packages. The precise triggering input and exploit consequences are not established.
CVE-2026-18724First seen Sep 1, 2026
CVE-2026-18725 is an out-of-bounds memory access vulnerability in the IPv6 ICMPv6 echo handling of iscsiuio, a component of open-iscsi. Affected packages include open-iscsi on Debian 12 Bookworm and iscsi-initiator-utils on Amazon Linux 2 and Amazon Linux 2023. The precise triggering condition, whether the access is a read or write, and the resulting security impact are currently not available.
CVE-2026-18725First seen Sep 1, 2026
CVE-2026-57582 is a reflected cross-site scripting vulnerability in GeoNetwork's unauthenticated public catalog search function. An attacker can cause attacker-controlled JavaScript to be reflected and executed in a victim's browser.
CVE-2026-57582First seen Sep 1, 2026
First seen Mar 8, 2026
CVE-2026-101305 is an improper pathname-restriction vulnerability in renameat(2). The system call does not enforce FD_RESOLVE_BENEATH on its directory arguments. A process confined to a jail can rename a directory relative to a restricted file descriptor and subsequently use fchdir(2) to escape the jail root.
CVE-2026-101305First seen Sep 29, 2026
When fdescfs is mounted inside a jail with the nodup option, opening a /dev/fd/N entry returns a file descriptor that does not inherit descriptor N's FD_RESOLVE_BENEATH restriction or Capsicum capability rights. This permits the duplicated descriptor to bypass access restrictions intended to constrain the original descriptor.
CVE-2026-101304First seen Sep 29, 2026
CVE-2026-8408 is a cross-site request forgery vulnerability in the IBM WebSphere Application Server Administrative Console caused by improper validation of user-supplied input. A remote attacker can induce an authenticated, privileged console user to visit a malicious URL during a limited timing window, causing the browser to issue a specially crafted request that performs unauthorized actions.
CVE-2026-8408First seen Jul 8, 2026
First seen Sep 25, 2026
CVE-2026-84707 is an authorization flaw in Red Hat Ansible Automation Controller. A crafted host_filter SmartFilter query can traverse the ORM to access JobEvent and AdHocCommandEvent objects without enforcing the required job permissions. This exposes job event_data and standard-output content to unauthorized users.
CVE-2026-84707First seen Sep 24, 2026
CVE-2026-84680 is an authorization flaw in Red Hat Ansible Automation Controller affecting organization-level Galaxy credential attachment. The attachment operation verifies only that the requesting user has read permission on the credential, rather than enforcing the required credential-use permission. A user able to read a Galaxy credential can therefore attach and use it in an organization without being authorized to use that credential.
CVE-2026-84680First seen Sep 24, 2026
CVE-2026-84689 is an improper-authorization vulnerability in Red Hat Ansible Automation Controller/AWX Bulk Job Launch workflow nodes. The Bulk Job Launch functionality permits a workflow node's unified-job reference to be set to an arbitrary unified job without enforcing tenant isolation. This allows a user to associate a node with a job belonging to another tenant and hijack that job's execution context.
CVE-2026-84689First seen Sep 24, 2026
CVE-2026-84708 is an information-exposure vulnerability in Red Hat Ansible Automation Platform Automation Controller container groups. A container-group pod_spec_override can cause job pods to receive the Automation Controller service-account token and secrets from the control-plane namespace. This permits a workload launched through the affected container-group configuration to access control-plane credentials and secret material that should not be available to the job pod.
CVE-2026-84708First seen Sep 24, 2026
CVE-2026-84686 is an information-disclosure vulnerability in Red Hat Ansible Automation Controller notification templates. A notification-template administrator can replay encrypted values between password-related subfields of a notification template, causing the controller to decrypt and reveal credential tokens in plaintext. The issue affects Ansible Automation Platform 2.5 and 2.6 Automation Controller deployments covered by the September 2026 security updates.
CVE-2026-84686First seen Sep 24, 2026