These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,099 reserved CVEs with public mentions, ranked by all-time mention count.
Page 5 of 44
CVE-2026-84644 is a server-side request forgery vulnerability in Red Hat Ansible Automation Controller's Thycotic Secret Server external credential-plugin test functionality. The affected credential-test endpoint can be induced to issue server-originated requests to attacker-specified destinations.
CVE-2026-84644First seen Sep 24, 2026
CVE-2026-84692 is a missing-authorization vulnerability in Red Hat Ansible Automation Platform Automation Controller workflow job template node handling. An attacker can create a workflow job template node with its unified job template unset, then patch the node to assign a target unified job template. The patch operation bypasses the required execute-permission validation, permitting cross-tenant execution that should be prohibited by Automation Controller RBAC controls.
CVE-2026-84692First seen Sep 24, 2026
CVE-2026-84679 is an arbitrary environment-variable injection vulnerability in Red Hat Ansible Automation Platform Automation Controller. The AWX_TASK_ENV setting accepts arbitrary environment variables and applies them to Automation Controller control-plane web and task processes, allowing an actor able to control this setting to alter the execution environment of those processes.
CVE-2026-84679First seen Sep 24, 2026
CVE-2026-84703 is an authorization flaw in Red Hat Ansible Automation Controller in which binding a credential to an execution environment does not enforce the required credential use-permission check. This missing object-level authorization allows cross-organization or cross-tenant use or disclosure of credentials through execution-environment credential associations.
CVE-2026-84703First seen Sep 24, 2026
CVE-2026-84709 is a denial-of-service vulnerability in Red Hat Ansible Automation Controller. CredentialType injector validation synchronously renders attacker-supplied Jinja2 templates in a web-worker context. A computationally expensive template can monopolize the worker during rendering.
CVE-2026-84709First seen Sep 24, 2026
CVE-2026-84643 is a missing-authorization vulnerability in Red Hat Ansible Automation Controller Project signature validation. The Project signature-validation credential foreign-key relationship does not enforce the required use_role authorization check. A user can therefore bind a credential belonging to a different organization to a Project and cause that credential to be used for signature validation.
CVE-2026-84643First seen Sep 24, 2026
CVE-2026-55868 is an authentication flaw in Secure Reliable Transport (SRT), a latency-aware UDP streaming library. SRT did not authenticate certain encryption control messages. A remote peer can abuse these unauthenticated messages to downgrade an encrypted SRT connection, enabling content injection or disruption of the media stream.
CVE-2026-55868First seen Aug 19, 2026
CVE-2026-55869 is an improper input validation vulnerability in SRT, a latency-aware UDP streaming library. SRT does not properly validate certain control packets received during connection setup and key-refresh operations. A remote attacker can send crafted control packets that cause the SRT process to crash.
CVE-2026-55869First seen Aug 19, 2026
CVE-2026-63676 is an algorithmic-complexity vulnerability in the libyaml parsing library as used by Perl YAML packages. Crafted YAML input can trigger excessive backtracking and exponential parsing time, causing the affected process to consume resources for an extended period. Amazon Linux 2 and Amazon Linux 2023 identify their perl-yaml packages as affected; Amazon Linux 2023 also lists perl-yaml-tests. Debian libyaml-perl is also identified as affected by an unpatched-vulnerability check.
CVE-2026-63676First seen Aug 26, 2026
CVE-2026-49926 is a critical denial-of-service vulnerability in Android System addressed in the September 2026 Android Security Bulletin. Available information identifies the affected scope as Android System but does not disclose the vulnerable component, underlying flaw class, attack vector, or a precise affected-version range.
CVE-2026-49926First seen Sep 9, 2026
CVE-2026-67414 is an uncontrolled resource-consumption vulnerability in RabbitMQ's AMQP 1.0 parser. Crafted AMQP 1.0 input involving aggregation of zero-width arrays can trigger memory-allocation amplification, allowing broker memory to be exhausted and resulting in denial of service. RabbitMQ 4.0 releases before 4.0.24, 4.1 releases before 4.1.15, and 4.2 releases before 4.2.10 are affected.
CVE-2026-67414First seen Sep 7, 2026
CVE-2026-68547 is an out-of-bounds read in Exiv2 versions earlier than 0.28.9. The flaw resides in RemoteIo::Impl::populateBlocks() while processing block-aligned remote CRW data. The affected RemoteIo code path is used when Exiv2 processes a URL rather than a local file.
CVE-2026-68547First seen Aug 31, 2026
CVE-2026-49275 is a low-severity out-of-bounds read in Exiv2's CrwMap::decodeBasic() image-metadata parsing functionality. The flaw was discovered by OSS-Fuzz and affects Exiv2 releases earlier than 0.28.9. It is reproducible using the project's fuzzing target; maintainers were unable to reproduce it through the Exiv2 command-line application.
CVE-2026-49275First seen Aug 31, 2026
CVE-2025-70292 is an integer-overflow vulnerability in Denx U-Boot's SquashFS handling, affecting sqfs_concat_tokens in the SquashFS filesystem implementation. Manipulated token lists cause sqfs_get_tokens_length() to overflow while calculating the aggregate token length. The resulting truncated size causes an undersized heap allocation, which is subsequently overwritten by strcpy() during token concatenation. U-Boot releases through v2026.01-rc4 are affected.
CVE-2025-70292First seen Aug 28, 2026
CVE-2025-70291 is an integer-overflow vulnerability in Denx U-Boot's do_mv directory-move command. Missing validation of string-length addition can cause the calculated allocation size for a constructed path to wrap, producing an undersized heap allocation. Subsequent copying with strcpy() can then write beyond the allocated heap buffer. U-Boot releases through v2026.01-rc4 are affected; the issue is fixed in v2026.04-rc1 and the upstream master branch.
CVE-2025-70291First seen Aug 28, 2026
CVE-2026-19720 is a buffer overflow vulnerability in GNU Inetutils talkd triggered by excessively long DNS names. Available information indicates that the flaw occurs during handling of DNS-derived host name data within talkd, where insufficient bounds checking allows an overlong name to overflow a buffer. The issue was reproduced by the maintainer, patched, and validated during coordinated disclosure. Specific vulnerable function details are not currently available.
CVE-2026-19720First seen Aug 15, 2026
CVE-2022-24087 is a critical improper input validation vulnerability in Adobe Commerce and Magento Open Source. It was assigned after researchers identified a bypass for earlier fixes associated with CVE-2022-24086. The flaw allows arbitrary code execution and is exploitable without authentication, indicating that crafted unauthenticated input processed by the application can reach vulnerable code paths and result in execution of attacker-controlled code on the target system.
CVE-2022-24087First seen Mar 18, 2026
CVE-2026-63078 is a patched zero-day vulnerability in Apache Traffic Server involving HTTP desynchronization. Available reporting indicates the issue was exposed through a crafted request sequence that triggered inconsistent request parsing and handling, and it has been associated with a desync trigger involving unusual method and header combinations. The flaw appears to fall within the request smuggling/desynchronization class, where malformed or ambiguously interpreted requests can cause a front-end and back-end component, or different parsing paths within the server, to disagree about request boundaries or semantics. Public technical detail about the exact vulnerable code path, affected versions, and fixed release mapping is currently not available.
CVE-2026-63078First seen Aug 5, 2026
First seen Jul 15, 2026
CVE-2023-28355 is an improper validation of integrity check value vulnerability in the CODESYS Control Runtime used in Schneider Electric devices that embed the CODESYS Runtime System V3. The PLC application code executed by the runtime relies on a checksum mechanism that is not sufficient to reliably detect PLC application code modified in memory or boot application files that have been manipulated. As a result, the integrity verification mechanism can be bypassed by altered application content, allowing unauthorized modifications to persist without dependable detection by the runtime.
CVE-2023-28355First seen Jan 22, 2026
CVE-2026-13135 is a moderate-severity vulnerability in Synology MailPlus Server on DiskStation Manager (DSM) caused by improper restriction of a communication channel to intended endpoints. The flaw allows a remote attacker to reach or access internal services that should not be exposed through the affected MailPlus Server deployment. Available reporting identifies the issue as ZDI-CAN-28485 and maps it to CWE-923. The vulnerability affects MailPlus Server deployments on DSM 7.3, 7.2.2, and 7.2.1 prior to the fixed releases.
CVE-2026-13135First seen Jun 29, 2026
CVE-2025-68405 is a stack overflow vulnerability in QNAP products, including affected releases of QTS, QuTS hero, QuTS cloud, and QVP. The flaw can be exploited by an authenticated administrator and may trigger unexpected system behavior or a denial-of-service condition. The available information identifies the issue as a stack overflow but does not provide the specific vulnerable component, function, or code path.
CVE-2025-68405First seen Jun 17, 2026
CVE-2025-15660 is a critical vulnerability in Synology MailPlus Server on DiskStation Manager (DSM). The issue is associated with CWE-338, Use of Cryptographically Weak PRNG, and has been identified as ZDI-CAN-28554. Successful exploitation allows an adjacent attacker to read arbitrary files, write arbitrary files, and trigger denial-of-service conditions, resulting in compromise of data confidentiality and integrity as well as service availability. Publicly available context does not provide the specific vulnerable function or code path.
CVE-2025-15660First seen Jun 29, 2026
CVE-2026-53922 is a moderate-severity vulnerability in OpenWrt's odhcpd affecting DHCPv6 Identity Association handling. The flaw is described as a size_t underflow in the DHCPv6 IA processing path, reachable before authentication by a network-adjacent attacker sending crafted DHCPv6 traffic. The vulnerable condition occurs while parsing or handling DHCPv6 IA-related data, where insufficient bounds validation allows an unsigned size calculation to wrap, leading to invalid memory access during request processing. OpenWrt addressed the issue in an odhcpd update that also incorporated additional DHCPv6 input-validation and bounds-checking hardening.
CVE-2026-53922First seen Jun 30, 2026
CVE-2026-39218 is a heap buffer overflow vulnerability in FFmpeg's DASH demuxer. The flaw was reportedly introduced in 2017 and affects FFmpeg media parsing functionality within the DASH demuxing path. A crafted DASH media input can trigger out-of-bounds writes to heap memory during demuxer processing, leading to memory corruption. As a parser-side memory safety flaw in a widely deployed media framework, the vulnerability is relevant anywhere FFmpeg processes attacker-controlled or untrusted DASH content, whether directly through command-line use or indirectly through applications and services embedding FFmpeg.
CVE-2026-39218First seen Jun 6, 2026