These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,134 reserved CVEs with public mentions, ranked by all-time mention count.
Page 26 of 46
First seen Sep 15, 2026
First seen Sep 15, 2026
First seen Sep 14, 2026
First seen Sep 13, 2026
First seen Sep 13, 2026
CVE-2026-56826 is a missing server-side authorization vulnerability in Shopper Framework Livewire Settings components handling shipping zones, carrier options, tax zones, and tax rates. Authenticated users granted the coarse access_setting permission can directly invoke destructive delete actions and edit actions without enforcement of the corresponding granular authorization permissions. The affected functionality includes Settings Zones and Settings Taxes operations.
CVE-2026-56826First seen Sep 12, 2026
First seen Sep 11, 2026
CVE-2026-12075 is a server-side request forgery vulnerability in the Natural Language Toolkit (NLTK) URL handling protections implemented in `nltk.pathsec.urlopen`. A DNS rebinding condition allows an attacker to bypass the library's SSRF filtering logic, including documented `ENFORCE` mode protections. The issue affects code paths that rely on `nltk.pathsec` for URL safety, including `nltk.download` and `nltk.data.load`. By supplying a crafted URL that resolves benignly during validation and then rebinds to a prohibited internal destination at request time, an attacker can cause the application to issue HTTP requests to internal-only resources that the protection layer was intended to block.
CVE-2026-12075First seen Aug 1, 2026
First seen Sep 10, 2026
CVE-2026-45518First seen Sep 9, 2026
First seen Sep 9, 2026
First seen Sep 9, 2026
First seen Sep 9, 2026
First seen Sep 9, 2026
CVE-2026-69774 is a critical Microsoft Hyper-V vulnerability with a reported CVSS score of 9.0 that may allow arbitrary code execution. Technical details such as the affected Hyper-V versions, vulnerable function, attack vector, and execution context are not currently available.
CVE-2026-69774First seen Sep 9, 2026
CVE-2026-81961 is a high-severity vulnerability in Azure Resource Manager that can allow privilege escalation. Publicly available information does not identify the affected function, vulnerable versions, or the technical flaw underlying the issue.
CVE-2026-81961First seen Sep 9, 2026
First seen Sep 9, 2026
First seen Sep 9, 2026
First seen Sep 9, 2026
First seen Sep 9, 2026
First seen Sep 8, 2026
First seen Sep 8, 2026
First seen Sep 6, 2026
First seen Sep 5, 2026
First seen Sep 4, 2026