These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,132 reserved CVEs with public mentions, ranked by all-time mention count.
Page 12 of 46
First seen Sep 30, 2026
First seen Oct 1, 2026
CVE-2026-62439 is an Important-severity vulnerability in GIMP. Technical details, including the affected function and vulnerability class, are not available. The issue is fixed by GIMP commit 4427b9f31552060aafa5b03caee6ffdd6c257c8b and is addressed in GIMP 3.2.6.
CVE-2026-62439First seen Sep 30, 2026
CVE-2026-96544 is an integer overflow vulnerability in GIMP's PVR image loader. In pvr_decode_rect(), unchecked multiplication of attacker-controlled image dimensions can overflow, causing an undersized heap allocation. Processing the crafted PVR image can subsequently cause an out-of-bounds read.
CVE-2026-96544First seen Sep 25, 2026
CVE-2026-96543 is an out-of-bounds heap write vulnerability in GIMP's PVR image loader. When GIMP loads a crafted non-square PVR texture, the pvr_decode_twiddle() function does not bounds-check its destination offset and can write attacker-controlled pixel data past the end of a correctly allocated heap buffer.
CVE-2026-96543First seen Sep 25, 2026
CVE-2026-95622 is a reachable assertion vulnerability in ModemManager while parsing Cell Broadcast Messages. Certain 3GPP data-coding-scheme values, including 8-bit and reserved character sets, are not handled. A crafted Cell Broadcast PDU can cause the ModemManager process to hit an assertion and abort.
CVE-2026-95622First seen Sep 26, 2026
First seen Sep 30, 2026
CVE-2026-102672 is a time-of-check to time-of-use race condition in Electron on macOS affecting applications that use the bundled Squirrel.Mac auto-update framework. During an application update, a local attacker can race the privileged ShipIt helper and cause it to overwrite files owned by a different application with root privileges.
CVE-2026-102672First seen Sep 29, 2026
CVE-2026-49264 is a cross-site scripting vulnerability in oauthlib's RevocationEndpoint. When JSONP is enabled, the endpoint reflects an unvalidated JSONP callback parameter, permitting generation of attacker-controlled JavaScript.
CVE-2026-49264First seen Sep 29, 2026
First seen Sep 30, 2026
CVE-2026-65954 is an arbitrary code execution vulnerability in phpcsstandards/phpcsutils. The issue arises from use of eval() in AbstractArrayDeclarationSniff::getActualArrayKey(). When a PHPCS sniff that invokes this method scans malicious, untrusted PHP source, attacker-controlled PHP can execute in the context of the host running PHPCS.
CVE-2026-65954First seen Sep 29, 2026
CVE-2026-101895 is a denial-of-service vulnerability in Angular Server-Side Rendering (SSR) applications using @angular/platform-server. The Domino DOM-emulation parser can enter an infinite synchronous parsing loop when it processes an incomplete DOCTYPE declaration that ends in whitespace at end-of-file. This uncontrolled parsing behavior consumes CPU and prevents the Node.js SSR process from servicing requests.
CVE-2026-101895First seen Sep 29, 2026
First seen Sep 29, 2026
First seen Sep 29, 2026
CVE-2026-61478 is an error-handling flaw in libvirt XML context parsing. libvirt does not properly handle parsing errors, which may allow an attacker to trigger a libvirt process crash and deny service.
CVE-2026-61478First seen Aug 11, 2026
CVE-2026-95510 is an uninitialized-memory vulnerability in GNU Inetutils libinetutils' setsig() function, used by rlogin, rlogind, and telnetd. The function initializes signal masks but fails to initialize struct sigaction.sa_flags before OR-ing SA_RESTART into it. Residual stack data can therefore retain SA_RESTORER in sa_flags and leave sa_restorer as an uninitialized function pointer on architectures that honor application-supplied restorers. The flaw has existed since GNU Inetutils 1.9. Telnetd crashes triggered during SIGCHLD handling have been reproducibly observed; potential code execution through manipulation or use of the uninitialized signal-restorer pointer has not been confirmed.
CVE-2026-95510First seen Sep 26, 2026
First seen Aug 30, 2026
CVE-2026-92709 concerns rsyslog's omfile dynaFile facility when a dynamic file-path template incorporates untrusted input as a path component without secure path handling. Crafted input can cause the rendered output path to traverse outside the administrator-intended logging directory. The available information does not identify affected rsyslog versions, a vulnerable function, or a vendor-fixed release.
CVE-2026-92709First seen Sep 24, 2026
CVE-2026-93402 is an authorization flaw in rsyslog's optional imdtls input module. When DTLS is configured with tls.authmode set to "name" or "fingerprint", the module does not terminate or reject an established DTLS session when the tls.permittedpeer identity check fails. It logs a warning but retains the session and forwards received DTLS records to the configured rsyslog ruleset.
CVE-2026-93402First seen Sep 24, 2026
CVE-2026-93403 is a stack-based buffer overflow in rsyslog's mmpstrucdata output module affecting versions before 8.2606.0. An unauthenticated remote sender can trigger the flaw by delivering a crafted RFC 5424 syslog message to an affected rsyslog instance.
CVE-2026-93403First seen Sep 24, 2026
CVE-2026-61627 is an error in libass handling of certain ASS subtitle files during wrapped-line measurement. Processing a crafted ASS subtitle can cause libass to crash and may permit arbitrary code execution. The affected Debian 12 packages include libass9 and libass-dev.
CVE-2026-61627First seen Sep 4, 2026
CVE-2026-84678 is a code-execution vulnerability in Red Hat Ansible Automation Controller. The GALAXY_TASK_ENV setting permits unfiltered dynamic-linker or interpreter-related environment variables to be supplied to a task environment. An attacker able to control this setting can influence process initialization or interpreter behavior and execute attacker-controlled code in the relevant execution context.
CVE-2026-84678First seen Sep 24, 2026
CVE-2026-95507 is an out-of-bounds read in libslirp's NC-SI OEM response handler. When processing a truncated NC-SI OEM Ethernet frame, the handler can read up to four bytes beyond the supplied packet length. The out-of-bounds data is reflected in a response delivered to the guest, exposing adjacent memory from the host process running libslirp.
CVE-2026-95507First seen Sep 23, 2026
CVE-2026-85495 is a pre-authentication global buffer overflow in pppd's construction of LCP Configure-NAK messages. A PPP link peer can supply repeated PAP-AUTHTYPE options that cause pppd to write beyond the fixed 1500-byte nak_buffer. The condition is reported to affect CHAP-only hardening configurations that reject PAP and EAP.
CVE-2026-85495First seen Sep 23, 2026
CVE-2026-62846First seen Sep 17, 2026