These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,130 reserved CVEs with public mentions, ranked by all-time mention count.
Page 42 of 46
First seen Mar 18, 2026
First seen Mar 18, 2026
First seen Mar 18, 2026
First seen Mar 18, 2026
First seen Mar 18, 2026
First seen Mar 18, 2026
First seen Mar 18, 2026
First seen Mar 18, 2026
First seen Mar 18, 2026
First seen Oct 9, 2026
First seen Oct 9, 2026
First seen Oct 9, 2026
First seen Oct 9, 2026
First seen Oct 9, 2026
First seen Oct 9, 2026
First seen Oct 9, 2026
First seen Oct 2, 2026
CVE-2024-36223First seen Jul 30, 2026
CVE-2026-100206 is a Microsoft Office information disclosure vulnerability caused by insertion of sensitive information into a log file. The exposed information can include a user's work-account sign-in access token.
CVE-2026-100206First seen Sep 25, 2026
First seen Sep 8, 2026
CVE-2025-64552 is a stored cross-site scripting vulnerability in Adobe Experience Manager. Available reporting identifies it as CWE-79 and places it among multiple AEM XSS issues addressed by Adobe. The vulnerability allows attacker-controlled content to be stored and later rendered in a victim’s browser without proper neutralization, causing execution of injected script in the context of the affected AEM application. Advisory language indicates that exploitation of the affected AEM vulnerabilities could lead to arbitrary code execution, arbitrary file system read, and privilege escalation, but the specific vulnerable component or function for CVE-2025-64552 is not currently available from the provided information.
CVE-2025-64552First seen Mar 19, 2026
CVE-2025-64860First seen Jul 30, 2026
First seen Jul 30, 2026
CVE-2025-64540First seen Jul 30, 2026
CVE-2020-4326 is a transport security weakness in HCL AppScan Enterprise affecting the security rules update administration section of the web application console. The application does not set the HTTP Strict-Transport-Security (HSTS) header for that interface, allowing browsers to access the affected functionality without being forced to use HTTPS on subsequent connections. This weakens protection against protocol downgrade and interception scenarios on untrusted networks.
CVE-2020-4326First seen Aug 23, 2026