These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,130 reserved CVEs with public mentions, ranked by all-time mention count.
Page 4 of 46
CVE-2026-85498 is a regression in the fix for CVE-2026-4897 affecting polkit's setuid polkit-agent-helper-1 helper. The read_cookie() function incorrectly handles an empty cookie read from standard input: its string-length calculation underflows, causing a one-byte out-of-bounds read from a stack buffer. This condition can crash polkit and may permit arbitrary code execution with administrator privileges.
CVE-2026-85498First seen Sep 4, 2026
CVE-2026-59177 is an authentication-bypass vulnerability in the ESPHome Home Assistant add-on ingress dashboard. In affected host-network deployments, the dashboard's intentionally unauthenticated ingress service binds to all network interfaces rather than being restricted to the Home Assistant Supervisor path. Direct access from the local network bypasses Supervisor ingress authentication, granting an unauthenticated user the same effective dashboard capabilities as an authenticated caller. The issue is classified as CWE-1327, Binding to an Unrestricted IP Address.
CVE-2026-59177First seen Sep 10, 2026
CVE-2026-62261 is a protection-mechanism failure in Open Identity Platform OpenAM's Groovy script sandbox. An authenticated attacker can escape the intended Groovy sandbox restrictions and achieve remote code execution in the OpenAM environment.
CVE-2026-62261First seen Jul 31, 2026
CVE-2021-27748 is a server-side request forgery vulnerability in HCL Digital Experience, including on-premises and container deployments. Proxy functionality could make server-side requests through configured outbound connections. Restricted destination policies could be bypassed by chaining requests through an open redirect on an allowlisted external service, causing the Digital Experience server to request attacker-selected arbitrary URLs. The issue affects Portal proxy functionality and was addressed through HCL maintenance and removal of the relevant outbound HTTP connection configuration.
CVE-2021-27748First seen Aug 14, 2026
CVE-2026-58221 is an authenticated access control vulnerability in Samba Active Directory. The issue affects Samba AD deployments and is associated with authenticated LDAP access that can permit an attacker to progress to domain takeover. Publicly available context identifies the flaw at a high level but does not provide sufficient technical detail about the specific vulnerable code path, function, or protocol handling logic involved.
CVE-2026-58221First seen Jul 28, 2026
CVE-2026-71385 is an incorrect authorization vulnerability in Adobe ColdFusion. It is one of several authorization-related flaws addressed in Adobe ColdFusion 2025 and 2023 security updates. The issue stems from improper enforcement of authorization controls, which can allow an attacker to bypass intended access restrictions within the application. Specific vulnerable functions or code paths are not available from the provided information.
CVE-2026-71385First seen Aug 11, 2026
CVE-2026-53918 is a high-severity use-after-free vulnerability in OpenWrt's odhcpd, affecting the DHCPv6 Identity Association (IA) handler. Available details indicate the flaw arises from a dangling first-lease pointer during DHCPv6 IA processing, causing the handler to retain and later dereference freed memory. Because odhcpd is a default-enabled network service in OpenWrt and the issue is described as remotely triggerable, a network-adjacent attacker can reach the vulnerable code path by sending crafted DHCPv6 traffic that exercises IA handling.
CVE-2026-53918First seen Jun 30, 2026
First seen Apr 30, 2026
CVE-2026-35328 is a vulnerability in libtls involving processing of the TLS supported_versions extension. According to the provided context, malformed or otherwise problematic handling of this extension can cause the affected code path to enter an infinite loop during TLS processing.
CVE-2026-35328First seen Apr 22, 2026
CVE-2026-84315 is a vulnerability in Nginx UI whose fix was incomplete. The follow-on vulnerability, CVE-2026-107813, involves missing secure-session enforcement on sensitive cluster-management operations and is fixed in Nginx UI 2.5.0. The original vulnerability's technical mechanism, affected versions, and exploitation requirements are not established by the available information.
CVE-2026-84315First seen Oct 9, 2026
CVE-2026-55480 is a symlink-following vulnerability in the CUPS copy_model() function. When adding or modifying a printer using a model PPD, the root-running cupsd scheduler opens a predictable temporary file without O_EXCL or O_NOFOLLOW. A local process with lp-group access can pre-create a symbolic link at that location, redirecting the scheduler's write to an arbitrary root-owned file. Successful exploitation can truncate or overwrite the target, potentially enabling root privilege escalation or denial of service.
CVE-2026-55480First seen Oct 6, 2026
CVE-2026-31001 is a reported JavaScriptCore type-confusion vulnerability targeting iOS 26, involving garbage collection and a stale JIT-held type-descriptor pointer. Exploit development remained unfinished, with companion sandbox-escape and kernel stages implemented only as placeholders. An operational exploit chain or deployed attack using this vulnerability has not been established.
CVE-2026-31001First seen Oct 7, 2026
CVE-2026-66020 is a vulnerability in QEMU associated with virtio-gpu blob scanouts during mapping cleanup. The upstream fix disables blob scanouts when mappings are cleaned up and is identified as included in QEMU 10.0.14. The precise underlying weakness and exploitation consequences are not established by the available technical information.
CVE-2026-66020First seen Aug 28, 2026
CVE-2026-85714 is an H2 database import remote code execution vulnerability affecting Stirling PDF versions 2.13.1 and earlier. The vulnerability concerns database-import functionality. Associated technical details reference H2 SQL operations INSERT, FILE_READ(), and RUNSCRIPT, along with validateSqlContent() and verifyBackup() routines, but the precise vulnerable operation and exploitation sequence are not established.
CVE-2026-85714First seen Oct 2, 2026
CVE-2026-66022 affects the QEMU package on Amazon Linux 2. The technical flaw, affected QEMU components, attack vector, and precise vulnerable version range are currently not available. Upstream QEMU fixes are identified in versions 11.0.4 and 11.1.0-rc2.
CVE-2026-66022First seen Aug 30, 2026
CVE-2026-63110 affects QEMU packages and is addressed by upstream and distribution security updates. The vulnerable component, function, underlying flaw, and exploitation mechanism are currently not available.
CVE-2026-63110First seen Aug 30, 2026
CVE-2026-18724 is a stack-based buffer overflow in the open-iscsi idbm_recinfo_config function during idbm record parsing. The vulnerability affects open-iscsi packages distributed by Debian and through Amazon Linux iscsi-initiator-utils packages. The precise triggering input and exploit consequences are not established.
CVE-2026-18724First seen Sep 1, 2026
CVE-2026-18725 is an out-of-bounds memory access vulnerability in the IPv6 ICMPv6 echo handling of iscsiuio, a component of open-iscsi. Affected packages include open-iscsi on Debian 12 Bookworm and iscsi-initiator-utils on Amazon Linux 2 and Amazon Linux 2023. The precise triggering condition, whether the access is a read or write, and the resulting security impact are currently not available.
CVE-2026-18725First seen Sep 1, 2026
CVE-2026-57582 is a reflected cross-site scripting vulnerability in GeoNetwork's unauthenticated public catalog search function. An attacker can cause attacker-controlled JavaScript to be reflected and executed in a victim's browser.
CVE-2026-57582First seen Sep 1, 2026
First seen Mar 8, 2026
CVE-2026-101305 is an improper pathname-restriction vulnerability in renameat(2). The system call does not enforce FD_RESOLVE_BENEATH on its directory arguments. A process confined to a jail can rename a directory relative to a restricted file descriptor and subsequently use fchdir(2) to escape the jail root.
CVE-2026-101305First seen Sep 29, 2026
When fdescfs is mounted inside a jail with the nodup option, opening a /dev/fd/N entry returns a file descriptor that does not inherit descriptor N's FD_RESOLVE_BENEATH restriction or Capsicum capability rights. This permits the duplicated descriptor to bypass access restrictions intended to constrain the original descriptor.
CVE-2026-101304First seen Sep 29, 2026
CVE-2026-8408 is a cross-site request forgery vulnerability in the IBM WebSphere Application Server Administrative Console caused by improper validation of user-supplied input. A remote attacker can induce an authenticated, privileged console user to visit a malicious URL during a limited timing window, causing the browser to issue a specially crafted request that performs unauthorized actions.
CVE-2026-8408First seen Jul 8, 2026
First seen Sep 25, 2026
CVE-2026-84707 is an authorization flaw in Red Hat Ansible Automation Controller. A crafted host_filter SmartFilter query can traverse the ORM to access JobEvent and AdHocCommandEvent objects without enforcing the required job permissions. This exposes job event_data and standard-output content to unauthorized users.
CVE-2026-84707First seen Sep 24, 2026