These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,129 reserved CVEs with public mentions, ranked by all-time mention count.
Page 1 of 46
CVE-2026-53921 is a critical stack-based buffer overflow in OpenWrt's odhcpd service, specifically in the DHCPv6 Identity Association reply serialization path. The flaw is described as involving a fixed 512-byte stack buffer that can be overrun when odhcpd processes crafted DHCPv6 REQUEST packets and appends reply data without sufficient remaining-capacity checks. Available reporting indicates the vulnerable code path is associated with older odhcpd versions containing the DHCPv6 handling functions dhcpv6_ia_handle_IAs() and build_ia(). Under attacker-controlled IA option layouts, odhcpd can write beyond the allocated stack buffer while constructing a DHCPv6 reply. Because odhcpd runs with root privileges by default on affected OpenWrt systems, successful exploitation can result in severe compromise.
CVE-2026-53921First seen Jun 30, 2026
CVE-2026-59774 is a critical arbitrary file-read vulnerability in the markup rendering functionality of Gitea and Forgejo. The flaw is triggered through the Org-mode renderer used by the markup endpoint for repository content rendering. Affected implementations initialize the go-org library without overriding its default ReadFile callback, allowing Org-mode #+INCLUDE directives to resolve and read absolute paths from the server filesystem. As a result, an attacker can submit crafted Org-mode markup to the repository markup rendering endpoint and cause the application to include the contents of local files in the rendered response. Reported affected versions include Gitea 1.22.1 through 1.27.0, fixed in 1.27.1, and Forgejo 7.0 through 15.0.5 and 16.0.0 through 16.0.1, fixed in 15.0.6 and 16.0.2.
CVE-2026-59774First seen Aug 4, 2026
CVE-2026-9672 is a buffer overflow vulnerability in libgd's GIF processing functionality, associated with incorrect array indexing and uninitialized memory in the GIF LZW decoder. Processing a specially crafted GIF file can cause denial of service and potentially arbitrary code execution. The vulnerability affects applications that use an affected libgd implementation, including PHP's GD functionality.
CVE-2026-9672First seen Jul 31, 2026
CVE-2026-10797 is a legacy flaw in the Linux shim UEFI bootloader, affecting old Microsoft-signed shim builds primarily based on version 0.9 and earlier. The vulnerability lies in shim's certificate-based revocation logic for second-stage PE bootloaders: an Authenticode-signed PE binary stores signature length information in two separate structures, and vulnerable shim code reads the signature size from the wrong PE structure during revocation checking while using different data during signature verification. By tampering with the second-stage bootloader's WIN_CERTIFICATE header, an attacker can cause shim to compare dbx or MokListX revocation entries against bogus certificate data instead of the bootloader's actual signature. This allows a revoked or otherwise blocked second-stage boot component to pass the revocation check while still being accepted as signed. In practice, the flaw undermines UEFI Secure Boot trust decisions in environments that continue to trust old Microsoft-signed shim binaries.
CVE-2026-10797First seen Jun 14, 2026
CVE-2026-93519 is a buffer overflow in the XFixes pointer-barrier handling code in X.Org Server and Xwayland. Input_constrain_cursor() writes barrier events into a fixed-size buffer without checking bounds. With more than 100 active pointer barriers, these writes overflow the buffer on the stack or heap. An authenticated X client can trigger the flaw by creating pointer barriers through XFIXES and generating pointer motion events, for example through XTEST. The vulnerability is fixed in xorg-server 21.1.25 and Xwayland 24.1.14.
CVE-2026-93519First seen Oct 7, 2026
CVE-2026-44772 is a critical code injection vulnerability in SAP Manufacturing Integration and Intelligence (SAP MII), affecting XMII and MII_ADMIN versions 15.4 and 15.5. A vulnerable servlet accepts specially crafted input that causes SAP MII to retrieve and process attacker-controlled content from an external source. This processing can be abused to inject code and execute arbitrary commands on the underlying host. SAP assigned the issue a CVSS score of 9.9.
CVE-2026-44772First seen Aug 11, 2026
CVE-2025-70951First seen Apr 3, 2026
CVE-2026-93524 is a heap out-of-bounds read vulnerability in the XKB SetMap handling of X.Org Server and Xwayland. A key-width/action-count desynchronization leaves the key symbol map width inconsistent with a shorter action allocation. A subsequent XkbGetMap request reads XkbKeyNumActions() entries derived from the wider key symbol map, exceeding the allocated action buffer. The overread bytes are copied into the GetMap reply and returned to the requesting client. The vulnerability affects releases preceding the fixes in xorg-server 21.1.25 and Xwayland 24.1.14.
CVE-2026-93524First seen Oct 7, 2026
CVE-2026-93521 is a heap buffer overflow in the RandR RRChangeProviderProperty() function in X.Org Server and Xwayland. When processing PrependMode, the function sets new_value.size to len rather than total_len. It also uses prop_value->size instead of len when calculating the destination offset for copying existing property data. These errors cause a heap buffer overflow when property data is prepended. The flaw repeats a bug pattern previously corrected in RRChangeOutputProperty(), without the corresponding correction being applied to the provider-property path. Fixes are available in xorg-server 21.1.25 and Xwayland 24.1.14.
CVE-2026-93521First seen Oct 7, 2026
CVE-2026-93522 is a heap buffer overflow in Xwayland's GPU-accelerated Glamor CopyArea CPU-to-framebuffer-object path. The temporary buffer, tmp_bits, is allocated using the destination height but indexed using source coordinates. When the source region is taller than the destination, writes exceed the allocated buffer and corrupt heap memory. The flaw affects Xwayland and is fixed in version 24.1.14. CVE-specific affected-component information identifies Xwayland only, although some bundled distribution advisories also associate the CVE with xorg-server updates.
CVE-2026-93522First seen Oct 7, 2026
CVE-2026-2270 is a confused-deputy vulnerability in the StatefulSet controller within Kubernetes kube-controller-manager. During restoration from a ControllerRevision, the controller could restore attacker-controlled fields beyond the StatefulSet specification. A user with write permissions to both StatefulSets and ControllerRevisions in one namespace could thereby cause the more privileged controller to create a pod in another namespace, controlling its metadata and specification. Kubernetes garbage collection normally deletes the resulting pod unless it has a valid StatefulSet OwnerReference in the target namespace. Affected releases are 1.34.11 and earlier in the 1.34 branch, 1.35.8 and earlier in the 1.35 branch, 1.36.4 and earlier in the 1.36 branch, and 1.37.0.
CVE-2026-2270First seen Sep 24, 2026
CVE-2026-93517 is a heap buffer overflow in GLX RenderLarge request processing in X.Org Server and Xwayland. An authenticated X client can trigger the overflow by submitting a crafted request in which dataBytes exceeds cmdlen. Successful exploitation can result in arbitrary code execution or denial of service. The vulnerability affects versions preceding the fixed upstream releases xorg-server 21.1.25 and xwayland 24.1.14.
CVE-2026-93517First seen Oct 7, 2026
CVE-2026-93518 is a numeric-truncation vulnerability in the XKB XkbResizeKeyType() function in X.Org Server and Xwayland. The expression (nTotal * 15) / 10 can exceed 65535 and is truncated when assigned to the unsigned short size_syms variable. The truncated allocation size produces an undersized heap buffer that subsequent writes overflow. The vulnerability affects releases preceding the fixes in xorg-server 21.1.25 and Xwayland 24.1.14.
CVE-2026-93518First seen Oct 7, 2026
CVE-2026-88812 is a double-free vulnerability in XKB SetGeometry TextDoodad processing in X.Org Server and Xwayland. CheckSetDoodad() frees doodad->text.text on an error path without clearing the pointer. Subsequent cleanup through _XkbClearDoodad() frees the same pointer again. The vulnerability affects releases preceding xorg-server 21.1.25 and xwayland 24.1.14.
CVE-2026-88812First seen Oct 7, 2026
CVE-2026-93536 is a use-after-free vulnerability in GestureBuildSprite affecting X.Org Server versions before 21.1.25 and Xwayland versions before 24.1.14. When a window is destroyed, WindowGone() repairs touch sprite traces but does not check or clean gesture sprite traces. Consequently, gesture sprites retain stale WindowPtr references, leading to use-after-free in gesture sprite processing.
CVE-2026-93536First seen Oct 7, 2026
CVE-2026-93520 is a heap out-of-bounds write vulnerability in the XKB ChangeKeycodeRange functionality of X.Org Server and Xwayland. The vulnerability results from an incomplete earlier fix and allows an authenticated X client to trigger heap memory corruption. It affects releases preceding the security fixes in xorg-server 21.1.25 and Xwayland 24.1.14. The precise triggering input and vulnerability-specific consequences beyond the out-of-bounds write are not established.
CVE-2026-93520First seen Oct 7, 2026
CVE-2026-93515 is a use-after-free vulnerability in the Present extension's cross-window notification handling in X.Org Server and Xwayland. The vulnerability requires the Present and SYNC extensions, which are enabled by default. It affects releases preceding the fixes in xorg-server 21.1.25 and Xwayland 24.1.14. The precise triggering sequence and CVE-specific exploitation consequences are not established.
CVE-2026-93515First seen Oct 7, 2026
First seen Sep 27, 2026
CVE-2026-93516 is a use-after-free vulnerability involving modifierDevice in XInput Passive Grab handling in X.Org Server and Xwayland. It affects X.Org Server versions before 21.1.25 and Xwayland versions before 24.1.14. Specific triggering conditions and exploitation outcomes are currently not available.
CVE-2026-93516First seen Oct 7, 2026
CVE-2026-93523 is a modifier-related out-of-bounds write in the XInput2 PassiveUngrabDevice operation in X.Org Server and Xwayland. The vulnerability affects releases preceding xorg-server 21.1.25 and xwayland 24.1.14 and can corrupt server memory. The precise triggering condition and subsequent exploitation outcomes are not established.
CVE-2026-93523First seen Oct 7, 2026
CVE-2026-52682 is an uncontrolled resource-consumption vulnerability in PowerDNS Authoritative Server, PowerDNS Recursor, and dnsdist. Processing a specially crafted DNS packet from a malicious DNS server can cause excessive memory and CPU consumption, resulting in a denial-of-service condition. Affected releases include Authoritative Server 4.9.16, 5.0.6, and 5.1.3; Recursor 5.2.12, 5.3.9, and 5.4.4; and dnsdist 1.9.15, 2.0.7, and 2.1.0.
CVE-2026-52682First seen Aug 6, 2026
The provided content identifies CVE-2026-38264 as a Linux kernel vulnerability in the nvme-tcp subsystem, described by SUSE as "nvme-tcp: sanitize request list handling." It is referenced in cumulative SUSE kernel security advisories affecting products including SUSE Linux Enterprise Server 16.0, SUSE Linux Micro 6.2, SUSE Linux Micro Extras 6.2, and related package sets built from kernel version 6.12.0-160000.6.1. No further technical root-cause detail, vulnerable function name, trigger condition, or upstream commit information is provided in the supplied content beyond the fact that the fix sanitizes request list handling in nvme-tcp.
CVE-2026-38264First seen Jun 27, 2026
CVE-2026-12184 is a null pointer dereference vulnerability in PHP’s HTTP stream wrapper during HTTP connection handling. When TLS initialization fails, PHP closes and resets the internal stream object but continues cleanup operations that assume the object remains valid. An unauthenticated remote attacker can trigger the failure through TLS validation errors, such as an expired certificate or mismatched peer name, potentially crashing PHP-FPM and disrupting service. Affected PHP branches have fixes in versions 8.3.32, 8.4.21, and 8.5.6.
CVE-2026-12184First seen Jul 6, 2026
CVE-2026-100754 is a code-injection vulnerability in OpenAI’s ChatGPT application for macOS. The application’s script interpreter accepted external commands that could be injected into the trusted ChatGPT process, allowing attackers to take over the assistant, induce command execution, and access stored application data, including the entire conversation history. Exploitation required malicious code to execute locally on the Mac. OpenAI fixed the vulnerability in an update released in late September 2026; affected and fixed version numbers are not available.
CVE-2026-100754First seen Sep 30, 2026
CVE-2026-53613 is a time-of-check/time-of-use vulnerability in the libmount component of util-linux affecting mount target-path handling. The race condition allows target-path redirection during mount operations and may enable a local attacker to gain elevated privileges.
CVE-2026-53613First seen Aug 14, 2026