Bitdefender disclosed VA-13905, covering two high-severity out-of-bounds write flaws in the Napoca bare-metal hypervisor that allow a malicious guest in real mode to write past the 1 MB RealModeMemory buffer and corrupt adjacent hypervisor heap memory. The issues were assigned CVE-2026-10046 and CVE-2026-10047, both classified as CWE-787. In one case, the BIOS INT 0x15 / E820 memory map handler in napoca/guests/bios_handlers.c uses guest-controlled ES and EDI values to calculate a destination offset without validating that the address remains inside the allocated buffer.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-10047 was assigned for an out-of-bounds write in Bitdefender Napoca's real-mode hook handler, where a guest-controlled SS:SP-derived offset can exceed the 1 MB RealModeMemory buffer and overwrite adjacent hypervisor heap memory during an IRET frame push. The reference classifies the issue as CWE-787 and states the product was end-of-life and unsupported when assigned.
CVE-2026-10046 was assigned for an out-of-bounds write in Bitdefender Napoca's BIOS INT 0x15 / E820 memory map handler, where guest-controlled ES and EDI values can cause writes past the 1 MB RealModeMemory buffer into hypervisor heap memory. The reference notes the affected product was end-of-life and unsupported when the CVE was assigned.
Bitdefender published security advisory VA-13905 covering out-of-bounds write vulnerabilities in the Napoca bare-metal hypervisor, including issues in the real-mode hook handler and BIOS INT 0x15 / E820 memory map handler.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcebitdefender.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.