These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,130 reserved CVEs with public mentions, ranked by all-time mention count.
Page 5 of 46
CVE-2026-84680 is an authorization flaw in Red Hat Ansible Automation Controller affecting organization-level Galaxy credential attachment. The attachment operation verifies only that the requesting user has read permission on the credential, rather than enforcing the required credential-use permission. A user able to read a Galaxy credential can therefore attach and use it in an organization without being authorized to use that credential.
CVE-2026-84680First seen Sep 24, 2026
CVE-2026-84689 is an improper-authorization vulnerability in Red Hat Ansible Automation Controller/AWX Bulk Job Launch workflow nodes. The Bulk Job Launch functionality permits a workflow node's unified-job reference to be set to an arbitrary unified job without enforcing tenant isolation. This allows a user to associate a node with a job belonging to another tenant and hijack that job's execution context.
CVE-2026-84689First seen Sep 24, 2026
CVE-2026-84708 is an information-exposure vulnerability in Red Hat Ansible Automation Platform Automation Controller container groups. A container-group pod_spec_override can cause job pods to receive the Automation Controller service-account token and secrets from the control-plane namespace. This permits a workload launched through the affected container-group configuration to access control-plane credentials and secret material that should not be available to the job pod.
CVE-2026-84708First seen Sep 24, 2026
CVE-2026-84686 is an information-disclosure vulnerability in Red Hat Ansible Automation Controller notification templates. A notification-template administrator can replay encrypted values between password-related subfields of a notification template, causing the controller to decrypt and reveal credential tokens in plaintext. The issue affects Ansible Automation Platform 2.5 and 2.6 Automation Controller deployments covered by the September 2026 security updates.
CVE-2026-84686First seen Sep 24, 2026
CVE-2026-84644 is a server-side request forgery vulnerability in Red Hat Ansible Automation Controller's Thycotic Secret Server external credential-plugin test functionality. The affected credential-test endpoint can be induced to issue server-originated requests to attacker-specified destinations.
CVE-2026-84644First seen Sep 24, 2026
CVE-2026-84692 is a missing-authorization vulnerability in Red Hat Ansible Automation Platform Automation Controller workflow job template node handling. An attacker can create a workflow job template node with its unified job template unset, then patch the node to assign a target unified job template. The patch operation bypasses the required execute-permission validation, permitting cross-tenant execution that should be prohibited by Automation Controller RBAC controls.
CVE-2026-84692First seen Sep 24, 2026
CVE-2026-84679 is an arbitrary environment-variable injection vulnerability in Red Hat Ansible Automation Platform Automation Controller. The AWX_TASK_ENV setting accepts arbitrary environment variables and applies them to Automation Controller control-plane web and task processes, allowing an actor able to control this setting to alter the execution environment of those processes.
CVE-2026-84679First seen Sep 24, 2026
CVE-2026-84703 is an authorization flaw in Red Hat Ansible Automation Controller in which binding a credential to an execution environment does not enforce the required credential use-permission check. This missing object-level authorization allows cross-organization or cross-tenant use or disclosure of credentials through execution-environment credential associations.
CVE-2026-84703First seen Sep 24, 2026
CVE-2026-84709 is a denial-of-service vulnerability in Red Hat Ansible Automation Controller. CredentialType injector validation synchronously renders attacker-supplied Jinja2 templates in a web-worker context. A computationally expensive template can monopolize the worker during rendering.
CVE-2026-84709First seen Sep 24, 2026
CVE-2026-84643 is a missing-authorization vulnerability in Red Hat Ansible Automation Controller Project signature validation. The Project signature-validation credential foreign-key relationship does not enforce the required use_role authorization check. A user can therefore bind a credential belonging to a different organization to a Project and cause that credential to be used for signature validation.
CVE-2026-84643First seen Sep 24, 2026
CVE-2026-55868 is an authentication flaw in Secure Reliable Transport (SRT), a latency-aware UDP streaming library. SRT did not authenticate certain encryption control messages. A remote peer can abuse these unauthenticated messages to downgrade an encrypted SRT connection, enabling content injection or disruption of the media stream.
CVE-2026-55868First seen Aug 19, 2026
CVE-2026-55869 is an improper input validation vulnerability in SRT, a latency-aware UDP streaming library. SRT does not properly validate certain control packets received during connection setup and key-refresh operations. A remote attacker can send crafted control packets that cause the SRT process to crash.
CVE-2026-55869First seen Aug 19, 2026
CVE-2026-63676 is an algorithmic-complexity vulnerability in the libyaml parsing library as used by Perl YAML packages. Crafted YAML input can trigger excessive backtracking and exponential parsing time, causing the affected process to consume resources for an extended period. Amazon Linux 2 and Amazon Linux 2023 identify their perl-yaml packages as affected; Amazon Linux 2023 also lists perl-yaml-tests. Debian libyaml-perl is also identified as affected by an unpatched-vulnerability check.
CVE-2026-63676First seen Aug 26, 2026
CVE-2026-49926 is a critical denial-of-service vulnerability in Android System addressed in the September 2026 Android Security Bulletin. Available information identifies the affected scope as Android System but does not disclose the vulnerable component, underlying flaw class, attack vector, or a precise affected-version range.
CVE-2026-49926First seen Sep 9, 2026
CVE-2026-67414 is an uncontrolled resource-consumption vulnerability in RabbitMQ's AMQP 1.0 parser. Crafted AMQP 1.0 input involving aggregation of zero-width arrays can trigger memory-allocation amplification, allowing broker memory to be exhausted and resulting in denial of service. RabbitMQ 4.0 releases before 4.0.24, 4.1 releases before 4.1.15, and 4.2 releases before 4.2.10 are affected.
CVE-2026-67414First seen Sep 7, 2026
CVE-2026-68547 is an out-of-bounds read in Exiv2 versions earlier than 0.28.9. The flaw resides in RemoteIo::Impl::populateBlocks() while processing block-aligned remote CRW data. The affected RemoteIo code path is used when Exiv2 processes a URL rather than a local file.
CVE-2026-68547First seen Aug 31, 2026
CVE-2026-49275 is a low-severity out-of-bounds read in Exiv2's CrwMap::decodeBasic() image-metadata parsing functionality. The flaw was discovered by OSS-Fuzz and affects Exiv2 releases earlier than 0.28.9. It is reproducible using the project's fuzzing target; maintainers were unable to reproduce it through the Exiv2 command-line application.
CVE-2026-49275First seen Aug 31, 2026
CVE-2025-70292 is an integer-overflow vulnerability in Denx U-Boot's SquashFS handling, affecting sqfs_concat_tokens in the SquashFS filesystem implementation. Manipulated token lists cause sqfs_get_tokens_length() to overflow while calculating the aggregate token length. The resulting truncated size causes an undersized heap allocation, which is subsequently overwritten by strcpy() during token concatenation. U-Boot releases through v2026.01-rc4 are affected.
CVE-2025-70292First seen Aug 28, 2026
CVE-2025-70291 is an integer-overflow vulnerability in Denx U-Boot's do_mv directory-move command. Missing validation of string-length addition can cause the calculated allocation size for a constructed path to wrap, producing an undersized heap allocation. Subsequent copying with strcpy() can then write beyond the allocated heap buffer. U-Boot releases through v2026.01-rc4 are affected; the issue is fixed in v2026.04-rc1 and the upstream master branch.
CVE-2025-70291First seen Aug 28, 2026
CVE-2026-19720 is a buffer overflow vulnerability in GNU Inetutils talkd triggered by excessively long DNS names. Available information indicates that the flaw occurs during handling of DNS-derived host name data within talkd, where insufficient bounds checking allows an overlong name to overflow a buffer. The issue was reproduced by the maintainer, patched, and validated during coordinated disclosure. Specific vulnerable function details are not currently available.
CVE-2026-19720First seen Aug 15, 2026
CVE-2022-24087 is a critical improper input validation vulnerability in Adobe Commerce and Magento Open Source. It was assigned after researchers identified a bypass for earlier fixes associated with CVE-2022-24086. The flaw allows arbitrary code execution and is exploitable without authentication, indicating that crafted unauthenticated input processed by the application can reach vulnerable code paths and result in execution of attacker-controlled code on the target system.
CVE-2022-24087First seen Mar 18, 2026
CVE-2026-63078 is a patched zero-day vulnerability in Apache Traffic Server involving HTTP desynchronization. Available reporting indicates the issue was exposed through a crafted request sequence that triggered inconsistent request parsing and handling, and it has been associated with a desync trigger involving unusual method and header combinations. The flaw appears to fall within the request smuggling/desynchronization class, where malformed or ambiguously interpreted requests can cause a front-end and back-end component, or different parsing paths within the server, to disagree about request boundaries or semantics. Public technical detail about the exact vulnerable code path, affected versions, and fixed release mapping is currently not available.
CVE-2026-63078First seen Aug 5, 2026
First seen Jul 15, 2026
CVE-2023-28355 is an improper validation of integrity check value vulnerability in the CODESYS Control Runtime used in Schneider Electric devices that embed the CODESYS Runtime System V3. The PLC application code executed by the runtime relies on a checksum mechanism that is not sufficient to reliably detect PLC application code modified in memory or boot application files that have been manipulated. As a result, the integrity verification mechanism can be bypassed by altered application content, allowing unauthorized modifications to persist without dependable detection by the runtime.
CVE-2023-28355First seen Jan 22, 2026
CVE-2026-13135 is a moderate-severity vulnerability in Synology MailPlus Server on DiskStation Manager (DSM) caused by improper restriction of a communication channel to intended endpoints. The flaw allows a remote attacker to reach or access internal services that should not be exposed through the affected MailPlus Server deployment. Available reporting identifies the issue as ZDI-CAN-28485 and maps it to CWE-923. The vulnerability affects MailPlus Server deployments on DSM 7.3, 7.2.2, and 7.2.1 prior to the fixed releases.
CVE-2026-13135First seen Jun 29, 2026