These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,130 reserved CVEs with public mentions, ranked by all-time mention count.
Page 2 of 46
CVE-2026-76654 is a medium-severity improper link resolution vulnerability in Kubernetes kubelet on Windows nodes. A pod volumeMount subPath can be configured as a symbolic link to an attacker-controlled UNC network share. Vulnerable kubelet versions resolve that link without rejecting UNC targets and transparently initiate NTLM authentication to the remote share. Fixed kubelet versions reject symlink targets resolving to UNC paths.
CVE-2026-76654First seen Sep 24, 2026
CVE-2026-65094 is a CWE-123 write-what-where vulnerability in the NVIDIA BlueField-3 Virtio-Net implementation, affecting NVIDIA Networking BlueField/ConnectX VIRTIO-Net deployments. A virtual-machine user can send a crafted message that causes data to be written to unintended memory locations. The resulting arbitrary-write condition can lead to code execution within the Virtio-Net scope. CVE-2025-33209 was withdrawn and replaced by this identifier.
CVE-2026-65094First seen Jul 28, 2026
CVE-2026-18576 is a high-severity authentication bypass vulnerability in N-able N-central, the vendor’s remote monitoring and management platform. The flaw has been described as an authentication bypass using an alternate path or channel and affects N-central versions prior to 2026.3, with reporting indicating impact through at least version 2026.1 before subsequent fixes. Successful exploitation allows an unauthenticated attacker to hijack or take over administrative accounts. The initial vendor patch was incomplete, and attackers were able to continue exploiting the issue until an emergency hotfix was released.
CVE-2026-18576First seen Aug 3, 2026
CVE-2026-13136 is a critical authorization flaw in Synology MailPlus Server on DiskStation Manager (DSM). The vulnerability is associated with CWE-863 (Incorrect Authorization) and allows a remote attacker to access functionality without authentication over the network. Successful exploitation can enable arbitrary file read and arbitrary file write operations and can also be used to trigger denial-of-service conditions. The issue affects MailPlus Server deployments on DSM 7.3, 7.2.2, and 7.2.1 prior to the fixed releases identified by Synology.
CVE-2026-13136First seen Jun 27, 2026
CVE-2026-57155 is a critical vulnerability in OPNsense fixed in version 26.7. The flaw affects GeoIP-related functionality exposed through the Web API, where insufficient validation of a user-supplied URL or file path allows path traversal during GeoIP data handling. An authenticated administrator can abuse the GeoIP alias import mechanism to cause arbitrary file creation or overwrite in attacker-controlled filesystem locations while the operation runs with root privileges. By placing a crafted configuration file in a privileged location processed by the system, the attacker can escalate from administrative access in the application to execution of shell commands as root on the underlying firewall appliance.
CVE-2026-57155First seen Jul 1, 2026
CVE-2026-85218 is a double stack overflow in BlueZ AVRCP ListPlayerAttributes response handling. The flaw is present in the avrcp_list_player_attributes_rsp and avrcp_get_current_player_value processing paths, where malformed AVRCP media-control data can corrupt stack memory.
CVE-2026-85218First seen Sep 4, 2026
CVE-2026-82374 is a null-pointer dereference vulnerability in the crypt module of the ZNC IRC bouncer. An IRC server can trigger the flaw, potentially causing ZNC to become unavailable. The issue is fixed in upstream ZNC 1.10.3 and in Debian 13's security-maintained package version 1.9.1-2+deb13u1.
CVE-2026-82374First seen Sep 13, 2026
CVE-2026-46675 is a use-after-free vulnerability in the sequential reader of libpng versions 1.6.0 through 1.6.58. Incomplete decompression of crafted zTXt, iTXt, or iCCP chunks can leave a stale zlib input pointer and input count after the chunk handler releases the stream. If an application calls png_read_end after png_read_info without first starting to read image rows, decompression can resume using that stale pointer. For zTXt and iTXt chunks, subsequent chunk-buffer reallocation can produce a heap use-after-free; for iCCP chunks, the pointer can reference expired local arrays, producing a stack use-after-return. Exploitation can cause an application crash. libpng 1.6.59 fixes the vulnerability.
CVE-2026-46675First seen Sep 29, 2026
CVE-2026-54154 affects Kiteworks Email Protection Gateway releases before 9.4.1. A combination of input-handling flaws in publicly reachable endpoints can potentially allow an unauthenticated remote attacker to execute arbitrary code. The exploitation chain involves path traversal, code injection, and missing authentication; additional local weaknesses can enable escalation to root-level control of the appliance. Specific vulnerable functions are not identified.
CVE-2026-54154First seen Oct 1, 2026
CVE-2026-94603 is a sandbox bypass vulnerability in Podman's handling of container images carrying checkpoint annotations. When such an image is executed with podman run, Podman treats it as a restored checkpoint and ignores user-specified sandboxing options, including dropped privileges. An attacker can entice a user to execute a specially crafted image, potentially allowing execution with elevated system privileges.
CVE-2026-94603First seen Sep 29, 2026
CVE-2026-61642 is a CWE-841 improper enforcement of behavioral workflow vulnerability in Squid that permits HTTP/1.1 Transfer-Encoding request smuggling. A client trusted by the affected Squid proxy can smuggle requests through the HTTP/1.1 processing path, bypassing security mechanisms deployed between that client and Squid. If an HTTP cache is positioned upstream of the affected Squid instance, the flaw can also be used to inject attacker-controlled content into cached URLs.
CVE-2026-61642First seen Sep 14, 2026
First seen Sep 27, 2026
CVE-2026-62356 is a buffer-size calculation error in Redis CMSketch handling during Redis Database (RDB) loading. A malformed or specially constructed RDB can cause Redis to perform a heap-based out-of-bounds write while loading CMSketch data.
CVE-2026-62356First seen Aug 17, 2026
CVE-2026-82373 is a use-after-free vulnerability in the ZNC IRC bouncer’s module-unloading functionality. An unprivileged ZNC user able to trigger module unloading can cause the vulnerable object-lifetime condition. The documented consequence is denial of service.
CVE-2026-82373First seen Sep 13, 2026
CVE-2026-67418 is an input-validation vulnerability in RabbitMQ's MQTT 5.0 message handling. A PUBLISH message containing a property that is inapplicable to PUBLISH operations can cause RabbitMQ to disconnect subscribers whose subscriptions match the published topic, rather than isolating or rejecting the malformed publication appropriately.
CVE-2026-67418First seen Aug 19, 2026
First seen Mar 18, 2026
CVE-2024-31884 is an improper certificate validation flaw in Ceph's Pybind-related handling of SSL/TLS connections for mail functionality. The issue arises because no SSL context is passed to the Python constructors imaplib.IMAP4_SSL and smtplib.SMTP_SSL. As a result, the remote server's X.509 certificate is not correctly validated and Ceph may accept any certificate presented by a server. This breaks the trust guarantees expected from TLS and allows interception or spoofing of the mail server connection in transit.
CVE-2024-31884First seen Jan 21, 2026
CVE-2026-3865 is a path traversal vulnerability in the Kubernetes CSI Driver for SMB. The flaw is caused by insufficient validation of the attacker-controlled subDir component embedded in the PersistentVolume volumeHandle used by the SMB CSI driver. The driver treated the volume identifier as a composite string, parsed the subdirectory field from it, and used path-joining logic to construct filesystem paths for operations on the backing SMB share without ensuring the resolved path remained confined to the intended managed subdirectory. By supplying traversal sequences in the volumeHandle, an attacker with permission to create PersistentVolume objects could cause the driver to escape the designated storage boundary. The vulnerable behavior is particularly exposed during cleanup and deletion workflows, where the driver may operate on unintended directories on the SMB server. Affected versions are CSI Driver for SMB releases prior to v1.20.1.
CVE-2026-3865First seen Apr 11, 2026
CVE-2026-20140 is a high-severity local privilege escalation vulnerability affecting Splunk Enterprise for Windows. The flaw arises from unsafe DLL resolution during Splunk service startup, allowing DLL search-order hijacking. A low-privileged local attacker who can place a malicious DLL in a location that is searched during service initialization may cause the Splunk service to load attacker-controlled code. Because the service starts with elevated privileges on Windows, successful exploitation can result in execution as NT AUTHORITY\SYSTEM. The issue affects Windows deployments only and does not impact non-Windows installations. Reported affected versions include Splunk Enterprise for Windows 10.0.0 through 10.0.2, 9.4.0 through 9.4.7, 9.3.0 through 9.3.8, and 9.2.0 through 9.2.11.
CVE-2026-20140First seen Feb 20, 2026
CVE-2024-28080 is an authentication bypass vulnerability in Gitblit’s SSH service. The flaw is in Gitblit’s integration with Apache MINA SSHD, specifically its handling of multi-stage public-key authentication. During the initial public-key authentication stage, Gitblit’s SshKeyAuthenticator.authenticate method stores authenticated user state in the ServerSession-backed SshDaemonClient by calling client.setUser(user) and client.setKey(key) as soon as the supplied public key matches a configured key for the requested username, before proof-of-possession of the corresponding private key has been verified. If signature generation or verification does not complete successfully, the session can still retain that user state. Gitblit’s UsernamePasswordAuthenticator.authenticate method then returns success early when client.getUser() is not null, causing subsequent password authentication to succeed even with an arbitrary or empty password. As a result, an attacker can impersonate a user on the SSH transport without the victim’s private key or password, provided the attacker knows a valid username and one of that user’s configured public keys. The issue reportedly affects Gitblit versions prior to 1.10.0 with public-key SSH authentication enabled.
CVE-2024-28080First seen Mar 18, 2026
CVE-2026-61547 is a heap-based buffer overflow in rabbitmq-c, as distributed in librabbitmq. The public amqp_send_frame() API improperly handles serialization of an oversized AMQP_FRAME_BODY, allowing an application-provided oversized body frame to cause a heap out-of-bounds write. The flaw can crash the affected process and corrupt memory.
CVE-2026-61547First seen Aug 18, 2026
CVE-2026-59986 is an integer-overflow vulnerability in an internal bounds check in librabbitmq, a C-based AMQP client library. On 32-bit systems, the bounds-check arithmetic can overflow, allowing an out-of-bounds read that can cause information disclosure or denial of service. The affected function name and precise triggering input are not established.
CVE-2026-59986First seen Aug 18, 2026
CVE-2026-3886 is an integer overflow vulnerability in QEMU's virtio-gpu driver, associated with calc_image_hostmem. Improper validation of user-supplied data can cause an integer overflow before buffer allocation. An attacker capable of executing low-privileged code in a guest system can exploit the flaw to execute arbitrary code in the context of the host system. The vulnerability was publicly disclosed on June 9, 2026.
CVE-2026-3886First seen Jun 9, 2026
CVE-2026-89085 is a heap-based buffer overflow in GNU Parted's FAT-handling code, specifically involving the _init_fats and fat_table_read functions. Affected distributions include Fedora, Ubuntu, Debian, and Amazon Linux systems using vulnerable Parted packages. The flaw is associated with processing FAT metadata.
CVE-2026-89085First seen Sep 15, 2026
CVE-2026-89088 is a heap-based buffer overflow in GNU Parted's duplicate_legacy_root_dir functionality. Fedora updates for Parted resolve the vulnerability alongside fixes for partition-number allocation, FAT metadata-triggered errors, and resize-related integer-overflow conditions.
CVE-2026-89088First seen Sep 15, 2026