
Report Name: pt_trend_cve_combined2026_h1 reportGenerated: 2026-07-30 23:40:05
Vulristics Vulnerability Scores
- All vulnerabilities: 17
- Urgent: 14
- Critical: 3
- High: 0
- Medium: 0
- Low: 0
Basic Vulnerability Scores
- All vulnerabilities: 17
- Critical: 2
- High: 13
- Medium: 2
- Low: 0
Products
| Product Name | Prevalence | U | C | H | M | L | A | Comment |
| Microsoft Desktop Window Manager | 0.95 | 2 | | | | | 2 | Desktop Window Manager (DWM) is a core component of Microsoft Windows responsible for compositing and rendering the graphical user interface, including window effects, transparency, and desktop composition. |
| Linux Kernel | 0.9 | 3 | 1 | | | | 4 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel |
| Adobe Reader | 0.8 | 1 | | | | | 1 | Adobe Acrobat is a family of application software and Web services developed by Adobe Inc. to view, create, manipulate, print and manage Portable Document Format files |
| Microsoft Defender | 0.8 | 1 | | | | | 1 | Anti-malware component of Microsoft Windows |
| Microsoft Exchange | 0.8 | 1 | | | | | 1 | Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft |
| Microsoft Office | 0.8 | 1 | | | | | 1 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer |
| Windows Remote Desktop Services | 0.8 | 1 | | | | | 1 | Remote Desktop Services, known as Terminal Services in Windows Server 2008 and earlier, is one of the components of Microsoft Windows that allow a user to initiate and control an interactive session on a remote computer or virtual machine over a network connection |
| Windows Shell | 0.8 | 1 | | | | | 1 | Windows component |
| Microsoft SharePoint | 0.7 | 1 | | | | | 1 | Microsoft SharePoint |
| Apache ActiveMQ | 0.6 | 1 | | | | | 1 | Apache ActiveMQ is an open source message broker written in Java together with a full Java Message Service (JMS) client |
| Microsoft Word | 0.6 | | 1 | | | | 1 | Microsoft Word is a widely used commercial word processor developed by Microsoft. It is a component of the Microsoft Office suite of productivity software but can also be purchased as a standalone product. |
| Microsoft SharePoint Server | 0.5 | | 1 | | | | 1 | Microsoft SharePoint Server |
| PAN-OS | 0.5 | 1 | | | | | 1 | PAN-OS is the software that runs all Palo Alto Networks next-generation firewalls |
Vulnerability Types
| Vulnerability Type | Criticality | U | C | H | M | L | A |
| Remote Code Execution | 1.0 | 6 | 1 | | | | 7 |
| Elevation of Privilege | 0.85 | 6 | 1 | | | | 7 |
| Information Disclosure | 0.83 | 1 | | | | | 1 |
| Cross Site Scripting | 0.8 | 1 | | | | | 1 |
| Spoofing | 0.4 | | 1 | | | | 1 |
Vulnerabilities
Urgent (14)
1.
Remote Code Execution - Windows Shell (CVE-2026-21510) - Urgent [954]
Description: {'ms_cve_data_all': 'Windows Shell Security Feature Bypass Vulnerability', 'nvd_cve_data_all': 'Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
2.
Remote Code Execution - Adobe Reader (CVE-2026-34621) - Urgent [942]
Description: Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
| Component | Value | Weight | Comment |
|---|
| Exploited in the Wild | 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (CISA object, cisa_kev object, vulncheck_kev object), AttackerKB, NVD:CISAKEV websites |
| Exploit Exists | 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:SANCHIT-SAINI:ACROBAT-READER-ESCAPE, Vulners:PublicExploit:GitHub:NULL200OK:CVE_2026_34621_ADVANCED, Vulners:PublicExploit:GitHub:DAJNEEM23:CVE-2026-3462, BDU:PublicExploit websites |
| Criticality of Vulnerability Type | 1.0 | 15 | Remote Code Execution |
| Vulnerable Product is Common | 0.8 | 14 | Adobe Acrobat is a family of application software and Web services developed by Adobe Inc. to view, create, manipulate, print and manage Portable Document Format files |
| CVSS Base Score | 0.9 | 10 | CVSS Base Score is 8.6. According to NVD data source |
| EPSS Percentile | 0.9 | 10 | EPSS Probability is 0.07086, EPSS Percentile is 0.93569 |
3.
Remote Code Execution - Microsoft Office (CVE-2026-21509) - Urgent [942]
Description: {'ms_cve_data_all': 'Microsoft Office Security Feature Bypass Vulnerability', 'nvd_cve_data_all': 'Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|
| Exploited in the Wild | 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, CISA object, cisa_kev object, vulncheck_kev object), AttackerKB, Microsoft, NVD:CISAKEV websites |
| Exploit Exists | 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:ASHWESKER:ASHWESKER-CVE-2026-21509, Vulners:PublicExploit:GitHub:NICOLE2ILODL:CVE-2026-21509-POC, Vulners:PublicExploit:GitHub:SENTINEL-AIDEFENSE:CVE-2026-21509, Vulners:PublicExploit:GitHub:DECALAGE2:DETECT_CVE-2026-21509, Vulners:PublicExploit:GitHub:GAVZ:CVE-2026-21509-POC, Vulners:PublicExploit:GitHub:SIMOESCTT:CTT-NFS-VORTEX-RCE, Vulners:PublicExploit:GitHub:DAMEDODE:CVE-2026-21509-POC, Vulners:PublicExploit:GitHub:SIMOESCTT:CTT-MICROSOFT-OFFICE-OLE-MANIFOLD-BYPASS-CVE-2026-21509, Vulners:PublicExploit:GitHub:RAZUREINK:CVE-2026-21509-OFFICE_SECURITY_BYPASS_REPRODUCTION, Vulners:PublicExploit:GitHub:XZ1R0:CVE-2026-POC-COLLECTION, Vulners:PublicExploit:GitHub:SUUHM:CVE-2026-21509-HANDLER, Vulners:PublicExploit:GitHub:INCURSIOHACK:CVE-2026-21509-POC, Vulners:PublicExploit:GitHub:PLANETOID:CVE-2026-21509-MITIGATION websites |
| Criticality of Vulnerability Type | 1.0 | 15 | Remote Code Execution |
| Vulnerable Product is Common | 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer |
| CVSS Base Score | 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source |
| EPSS Percentile | 1.0 | 10 | EPSS Probability is 0.72152, EPSS Percentile is 0.99371 |
4.
Elevation of Privilege - Linux Kernel (CVE-2026-31431) - Urgent [932]
Description: In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
| Component | Value | Weight | Comment |
|---|
| Exploited in the Wild | 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (CISA object, cisa_kev object, vulncheck_kev object), AttackerKB, NVD:CISAKEV websites |
| Exploit Exists | 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:xint.io, Vulners:PublicExploit:GitHub:PYROCEPER:COPY-FAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:TGIES:COPY-FAIL-C, Vulners:PublicExploit:GitHub:B5NULL:CVE-2026-31431-C, Vulners:PublicExploit:GitHub:IBLAMENEAR:CVE-2026-31431-COPY-FAIL---ADVANCED-LPE-PROOF-OF-CONCEPT---C-REWRITE, Vulners:PublicExploit:GitHub:ABDELKABIROUADOUKOU:CVE-2026-31431-ANALYSIS-AND-FIX, Vulners:PublicExploit:GitHub:RAT5AK:CVE-2026-31431-COPY-FAIL-POC---578B, Vulners:PublicExploit:GitHub:ATTAATTAATTA:CVE-2026-31431, Vulners:PublicExploit:GitHub:SEC17BR:CVE-2026-31431-COPY-FAIL, Vulners:PublicExploit:GitHub:SPENSERCAI:COPY_FAIL, Vulners:PublicExploit:GitHub:KVAKIRSANOV:CVE-2026-31431-LIVE-PROCESS-CODE-INJECTION, Vulners:PublicExploit:GitHub:HAYDENJAMES:CVE-2026-31431-CHECK, Vulners:PublicExploit:GitHub:FIRST-JOHN:CVE-2026-43500, Vulners:PublicExploit:GitHub:CS8425:COPY-FAIL-GO, Vulners:PublicExploit:GitHub:B1GN0SE:COPY-FAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:AESTECHNO:CVE-2026-31431-ANSIBLE, Vulners:PublicExploit:GitHub:CXWX:CPP-CVE-2026-31431, Vulners:PublicExploit:GitHub:JUGUITOS:COPY-FAIL, Vulners:PublicExploit:GitHub:MARTINPHAM:COPY-FAIL-CVE-2026-31431-PHP, Vulners:PublicExploit:GitHub:CX330ZER0:CVE-2026-31431-COPY-FAIL-ADD-ARM64, Vulners:PublicExploit:GitHub:SILENT4LABS:CHECK-COPYFAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:PARMSTRO:COPY-FAIL-DETECT, Vulners:PublicExploit:GitHub:ALVAROGUZMANCODE:CVE-2026-31431-MITIGACION, Vulners:PublicExploit:GitHub:BADSECTORLABS:COPYFAIL-GO, Vulners:PublicExploit:GitHub:XD20111:CVE-2026-31431, Vulners:PublicExploit:GitHub:DANIMRTZP:CVE-2026-31431-REVSHELL, Vulners:PublicExploit:GitHub:KOSHMARE-BLOSSOM:COPYFAIL-SH, Vulners:PublicExploit:GitHub:ZENZUE:CVE-2026-31431-CHECKER-MITIGATOR, Vulners:PublicExploit:GitHub:DETECT-DEFENSELAB:CVE-2026-31431-DETECTION-DEFENSE, Vulners:PublicExploit:GitHub:ROOTSECDEV:CVE_2026_31431, Vulners:PublicExploit:GitHub:ADITYABHATT3010:CVE-2026-31431, Vulners:PublicExploit:GitHub:EUROFIBER-CLOUDINFRA:EFCI-COPYFAIL-MITIGATION, Vulners:PublicExploit:GitHub:THEMURSALIN:CVE-2026-31431, Vulners:PublicExploit:GitHub:FULUCKY0-YURI:CVE-2026-31431-POCC, Vulners:PublicExploit:GitHub:AEGEIGER:OPENSHELL-SANDBOX-POC, Vulners:PublicExploit:GitHub:BIGWARIO:COPY-FAIL-CVE-2026-31431-C, Vulners:PublicExploit:GitHub:0XDEADBEEFNETWORK:COPY_FAIL2-ELECTRIC_BOOGALOO, Vulners:PublicExploit:GitHub:KARAZAJAC:DIRTYFAIL, Vulners:PublicExploit:GitHub:RAPTORATACK:COPYFAIL-SCANNER-CVE-2026-31431, Vulners:PublicExploit:GitHub:SHOTAFRY:COPYFAIL-EXPLOITS-CVE-2026-31431, Vulners:PublicExploit:GitHub:WVVEREZ:CVE-2026-31431-COPY-FAIL, Vulners:PublicExploit:GitHub:SAMSULMAARIF:LINUX-COPY-FAIL-EXPLOIT, Vulners:PublicExploit:GitHub:SHADOWABI:CVE-2026-31431-COPYFAIL-UNIVERSAL-LPE, Vulners:PublicExploit:GitHub:NISEC-ERIC:CVE-2026-31431, Vulners:PublicExploit:GitHub:ZEPHRFISH:COPYFAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:MR-BV:COPY-FAIL-CVE-2026-31431-EXPLOIT-IN-C, Vulners:PublicExploit:GitHub:ADITYASINGH108:CVE-2026-31431-METASPLOIT-EXPLOIT, Vulners:PublicExploit:GitHub:4N4S4ZI:COPYFAIL-ALPINE, Vulners:PublicExploit:GitHub:PAULORLIMA9:COPYFAIL-FIX, Vulners:PublicExploit:GitHub:RAZVANDUDA:GHOSTSHELL, Vulners:PublicExploit:GitHub:H1D3R:COPY-FAIL_LPE_INTERACTIVE, Vulners:PublicExploit:GitHub:DANFORD2017:COPY-FAIL---CVE-2026-31431, Vulners:PublicExploit:GitHub:ROYAYUB:CVE-2026-31431, Vulners:PublicExploit:GitHub:UNCLECHENG-LI:POC-LAB, Vulners:PublicExploit:GitHub:HORI0729:CVE-2026-31431-VERIFICADOR-EXPLOIT, Vulners:PublicExploit:GitHub:SIBERSAN:CVE-2026-31431-CHECKER, Vulners:PublicExploit:GitHub:STARXSKY:CVE-2026-31431, Vulners:PublicExploit:GitHub:MARIOHY:CVE_2026_31431_AUDIT, Vulners:PublicExploit:GitHub:THRANDOMV:CVE-2026-31431-DETECTION, Vulners:PublicExploit:GitHub:RIVALDOFWIJAYA:COPY-SUCCESS, Vulners:PublicExploit:GitHub:KINRYULABS:ROOTPACKET-CVE-2026-31431, Vulners:PublicExploit:GitHub:SUDOYTANG:COPYFAIL-ARM64, Vulners:PublicExploit:GitHub:STRUTTONPIGEON:OSCPTOOLKIT, Vulners:PublicExploit:GitHub:MONOBRAU:COPYFAILSCAN, Vulners:PublicExploit:GitHub:PAINOOB:COPY-FAIL-EXPLOIT-CVE-2026-31431, Vulners:PublicExploit:GitHub:METASPIOIT:CVE-2026-31431, Vulners:PublicExploit:GitHub:PERCIVALLL:COPY-FAIL-CVE-2026-31431-KUBERNETES-POC, Vulners:PublicExploit:GitHub:PULENTOSKI:CVE-2026-31431, Vulners:PublicExploit:GitHub:WGNET:WG.COPYFAIL.PATCH, Vulners:PublicExploit:GitHub:DULLPURPLE-SLOOP726:CVE-2026-31431-LINUX-COPY-FAIL, Vulners:PublicExploit:GitHub:SL4CK0TH:CVE-2026-31431-POC, Vulners:PublicExploit:GitHub:HORI0729:CVE-2026-31431---COPY-FAIL-VERIFICADOR-EXPLOIT, Vulners:PublicExploit:GitHub:KAROLLOOOOL:PORTING-CVE-2026-31431-COPY-FAIL-TO-A-CONSTRAINED-JAVA-RUNNER, Vulners:PublicExploit:GitHub:Y5NEKO:COPY-FAIL-CVE-2026-31431-UNIVERSAL, Vulners:PublicExploit:GitHub:BRYANVINE:COPY-FAIL-FIX, Vulners:PublicExploit:GitHub:CODESOURCE:COPYFAIL-CHECK, Vulners:PublicExploit:GitHub:POVZAYD:CVE-2026-31431, Vulners:PublicExploit:GitHub:RVIZX:CVE-2026-31431, Vulners:PublicExploit:GitHub:DESULTORY:CVE-2026-31431, Vulners:PublicExploit:GitHub:MCUB3:CVE-2026-31431, Vulners:PublicExploit:GitHub:T1CKPRIVATE:CVE-2026-31431-COPY-FAIL, Vulners:PublicExploit:GitHub:MISHL-DEV:CVE_2026_31431, Vulners:PublicExploit:GitHub:M4XSEC:CVE-2026-31431-RCE-EXPLOIT, Vulners:PublicExploit:GitHub:KW-SOFT:COPYFAIL, Vulners:PublicExploit:GitHub:NAIMADX123:CVE_2026_31431, Vulners:PublicExploit:GitHub:1AMBA7MAN:LINUX-COPY-FAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:POLYAKOVAVV:COPYFAIL, Vulners:PublicExploit:GitHub:MFLORESDACUNHA:CVE-2026-31431, Vulners:PublicExploit:GitHub:CYBROZEUS:COPY-FAIL-EXPLOIT-CVE-2026-31431, Vulners:PublicExploit:GitHub:INSOMNISEC:DETECTIONS-CVE-2026-31431, Vulners:PublicExploit:GitHub:CJ667113:OCI-ANSIBLE-FIX-CVE-2026-31431, Vulners:PublicExploit:GitHub:SAMMWYY:COPYFAIL-RS, Vulners:PublicExploit:GitHub:ASTOUNDS:COPY-FAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:WHOSFAULT:CVE-2026-31431, Vulners:PublicExploit:GitHub:ROSNLR5:MODROSNLR5, Vulners:PublicExploit:GitHub:WUWU001:CVE-2026-31431-EXPLOIT, Vulners:PublicExploit:GitHub:NOVYSODOPE:COPY-FAIL-CVE-2026-31431-C, Vulners:PublicExploit:GitHub:WALTRONE1:COPYFAIL-SAFE-CHECK, Vulners:PublicExploit:GitHub:W3LLR00T3D:CVE-2026-31431-POC, Vulners:PublicExploit:GitHub:WH1SKY02:COPY-FAIL-PYTHON, Vulners:PublicExploit:GitHub:AFMAGHRIBI:TETRAGON-LAB, Vulners:PublicExploit:GitHub:PITHASE:ASM-COPYFAIL, Vulners:PublicExploit:GitHub:EYNAEXP:COPY-FAIL-CVE-2026-31431-MODERNIZED, Vulners:PublicExploit:GitHub:LEELONG2020:CVE-2026-31431, Vulners:PublicExploit:GitHub:BEN-SLATES:CVE-2026-31431-EXPLOIT, Vulners:PublicExploit:GitHub:20ISAAK23:CHALLENGE_UNIX-, Vulners:PublicExploit:GitHub:MALWAREKID:CVE-2026-31431, Vulners:PublicExploit:GitHub:IMKK000:PLAY-GO-COPY-FAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:KALYANI4114:LINUX-COPY-FAIL-EXPLOIT, Vulners:PublicExploit:GitHub:PCDOYLE:COPY-FAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:WESMAR:CVE-2026-31431, Vulners:PublicExploit:GitHub:SBETETA42:CVE-2026-31431_JE_SAPPELLE_ROOT, Vulners:PublicExploit:GitHub:YANGH-BEEP:CVE-2026-31431-C, Vulners:PublicExploit:GitHub:DECKHOUSE:D8-COPY-FAIL-MITIGATION, Vulners:PublicExploit:GitHub:SILENT0X0:COPY-FAIL---CVE-2026-31431, Vulners:PublicExploit:GitHub:PITHASE:ASM-COPYFAIL-, Vulners:PublicExploit:GitHub:MRUNALP:BLOCK-COPYFAIL, Vulners:PublicExploit:GitHub:HUNT-BENITO:COPY-FAIL-CVE-2026-31431-LINUX-KERNEL-PAGE-CACHE-LPE, Vulners:PublicExploit:GitHub:GUBICZAP:CVE-2026-31431-CHECKER, Vulners:PublicExploit:GitHub:GUBAIOVO:CVE-2026-31431, Vulners:PublicExploit:GitHub:INDUSTRI4L-H3LL-XPL0IT3RS:CVE-2026-31431-COPY-FAIL, Vulners:PublicExploit:GitHub:GRABESEC:XCP_NG_CVE-2026-31431_TESTER, Vulners:PublicExploit:GitHub:FREELABZ:CVE-2026-31431, Vulners:PublicExploit:GitHub:SLAUGER:CVE-2026-31431, Vulners:PublicExploit:GitHub:SAMANZAMANI:COPY-FAIL-CHECKER, Vulners:PublicExploit:GitHub:MOHAMEDKARRAB:COPY-FAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:JULIOSUAS:COPYFAIL-GUARD, Vulners:PublicExploit:GitHub:RFXN:COPYFAIL, Vulners:PublicExploit:GitHub:PASCAL-GUJER:CVE-2026-31431, Vulners:PublicExploit:GitHub:LINUX-ZS:CVE-2026-31431-MITIGATION, Vulners:PublicExploit:GitHub:ERDEMOZGEN:COPY-FAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:RODKODANILA:COPY.FAIL.OCP-POC, Vulners:PublicExploit:GitHub:KANBARAAKIHITO:CVE-2026-31431-COPYFAIL-RS, Vulners:PublicExploit:GitHub:SUOMINEN:CVE-2026-31431, Vulners:PublicExploit:GitHub:ISS4CF0NG:CVE-2026-31431-LINUX-COPY-FAIL, Vulners:PublicExploit:GitHub:VASYAPOKEMON:CVE-2026-31431, Vulners:PublicExploit:GitHub:EXIMIAIT:CVE-2026-31431, Vulners:PublicExploit:GitHub:PERCIVALLL:COPY-FAIL-CVE-2026-31431-STATICALLY-POC, Vulners:PublicExploit:GitHub:IKOW:CVE-2026-31431-LIVE-CODE-CORRUPTION, Vulners:PublicExploit:GitHub:SEBINXAVI:CVE-CHECKER-2026, Vulners:PublicExploit:GitHub:GALORYBER:CVE-2026-31431-CLEANED, Vulners:PublicExploit:GitHub:ARKDEV1:CHECK-CVE-2026-31431, Vulners:PublicExploit:GitHub:ZHANGHANGORG:CVE-2026-31431, Vulners:PublicExploit:GitHub:MORTON-LI:COPY-FAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:0XN7Y:CVE-2026-31431, Vulners:PublicExploit:GitHub:RIPPSEC:CVE-2026-31431, Vulners:PublicExploit:GitHub:VEHICLE-SECURITY:POCLAB, Vulners:PublicExploit:GitHub:PEDRO-LUCAS-MELO:ESTUDO-DE-CASO-CVE-2026-31431-COPYFAIL, Vulners:PublicExploit:GitHub:WEBHOSTING4U:COPY-FAIL_DETECT_AND_MITIGATE_CVE-2026-31431, Vulners:PublicExploit:GitHub:XZ1R0:CVE-2026-POC-COLLECTION, Vulners:PublicExploit:GitHub:JOHANBURATI:CVE-2026-31431, Vulners:PublicExploit:GitHub:ROFLSECURITY:COPY_FAIL, Vulners:PublicExploit:GitHub:BEATBEAST007:LINUX-COPYFAIL-C-VERSION-CVE-2026-31431, Vulners:PublicExploit:GitHub:OFFSECGUY:CVE-2026-31431, Vulners:PublicExploit:GitHub:GUIIMORAES:COPYFAIL2-DIRTYFRAG-PY, Vulners:PublicExploit:GitHub:DGROBINSON0:COPYFILE_CVE-2026-31431, Vulners:PublicExploit:GitHub:ADVXRSARY:DIRTYFRAG-DETECTION, Vulners:PublicExploit:GitHub:ALIHZSEC:CVE-2026-31431, Vulners:PublicExploit:GitHub:XN0KKX:CVE-2026-31431_COPYFAIL_LINUXKERNEL_LPE, Vulners:PublicExploit:GitHub:361WAY:CVE-2026-31431, Vulners:PublicExploit:GitHub:LIAMROMANIS101:CVE-2026-31431-COPY-FAIL---VULNERABILITY-DETECTION-SCRIPT, Vulners:PublicExploit:GitHub:MAKITOS666:CVE-2026-31431-COPY-FAIL-DETECTION-TOOLKIT, Vulners:PublicExploit:GitHub:0XFUFFM3:CVE-2026-31431-COPYFAIL, Vulners:PublicExploit:GitHub:PULENTOSKI:CVE-2026-31431-, Vulners:PublicExploit:GitHub:GUIIMORAES:COPYFAIL2-PY, Vulners:PublicExploit:GitHub:JIANGBAN046-SPEC:CVE-2026-31431-EXPLOIT_PY2_PY3, Vulners:PublicExploit:GitHub:HAYDENJAMES:DIRTY-FRAG-CHECKER, Vulners:PublicExploit:GitHub:DENNISDGR:CVE-2026-31431-POC, Vulners:PublicExploit:GitHub:PARMSTRO:CFDR, Vulners:PublicExploit:GitHub:LUTFIFAKEE-PROJECT:CVE-2026-31431, Vulners:PublicExploit:GitHub:LUOTIAN2:CVE-2026-31431, Vulners:PublicExploit:GitHub:MEOWTEUSZ:COPYFAILAUTOPATCH, Vulners:PublicExploit:GitHub:OCHEBOTAR:COPY-FAIL-CVE-2026-31431-DETECTION-PROBE, Vulners:PublicExploit:GitHub:EXPLOITEOOM:CVE-2026-31431, Vulners:PublicExploit:GitHub:JULICHAAN:CVE-2026-31431-PYTHON-COPYFAIL-POC, Vulners:PublicExploit:GitHub:LYUTOON:COPYFAIL-EXPERIMENT, Vulners:PublicExploit:GitHub:PETRA976:SIGMA_RULE_FOR_COPYFAIL, Vulners:PublicExploit:GitHub:VISHVACYBER:DETECTION-TOOL-KIT-FOR-CVE-2026-31431, Vulners:PublicExploit:GitHub:TEMATEMARU:CVE-2026-31431-SIMPLE-TEST, Vulners:PublicExploit:GitHub:POYEA:CVE-2026-31431.C, Vulners:PublicExploit:GitHub:AEXDYHAXOR:CVE-2026-31431-COPY-FAIL, Vulners:PublicExploit:GitHub:MRMIXIES:COPY-FAIL---CVE-2026-31431, Vulners:PublicExploit:GitHub:0XBLACKFOX:COPY-FAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:PROFESSIONAL-SLACKER:ALG_CHECK, Vulners:PublicExploit:GitHub:ABDULLAABDULLAZADE:CVE-2026-31431, Vulners:PublicExploit:GitHub:RIDHINVA:COPYFAIL-CHECKER, Vulners:PublicExploit:GitHub:P401A-OPS:COPY-FAIL, Vulners:PublicExploit:GitHub:TIKOTIKTOK:COPY-FAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:PULLSEC:CVE-DEEP-DIVE, Vulners:PublicExploit:GitHub:RECOFU:CVE-2026-31431-COPY-FAIL, Vulners:PublicExploit:GitHub:LEOXSOFT:CVE-2026-31431, Vulners:PublicExploit:GitHub:TREX1E:COPYFAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:ELEVENI386:CVE-2026-31431-GOLANG, Vulners:PublicExploit:GitHub:4XURA:CVE-2026-31431-COPY-FAIL, Vulners:PublicExploit:GitHub:GOVIND28:LINUX-COPY-FAIL-EXPLOIT, Vulners:PublicExploit:GitHub:BOLIU83:CVE-2026-31431-ALGIF-AEAD-REMEDIATOR, Vulners:PublicExploit:GitHub:JIMMYPUGHTRON:CVE-2026-31431-COPY-FAIL---MINIFIED-LPE-POC, Vulners:PublicExploit:GitHub:SNDAV:CVE-2026-31431-ADVANCED-EXPLOIT, Vulners:PublicExploit:GitHub:0XSHE:CVE-2026-31431, Vulners:PublicExploit:GitHub:ISW-9:COPY-FAIL-CVE-2026-31431-AARCH64, Vulners:PublicExploit:GitHub:TANGJIE1:CVE-2026-31431-CHECK, Vulners:PublicExploit:GitHub:MAXIME288:CVE-2026-31431-COPY-FAIL-R-PERTOIRE-DE-PR-VENTION, Vulners:PublicExploit:GitHub:PVPAULO01:CVE-2026-31431, Vulners:PublicExploit:GitHub:RIPPSEC:CVE-2026-31431-COPY-FAIL, Vulners:PublicExploit:GitHub:CALLUM-CAMERON26:CVE_2026_31431-TESTING-THE-COPY-FAIL-EXPLOIT, Vulners:PublicExploit:GitHub:SEANRICKERD:CVE-2026-31431, Vulners:PublicExploit:GitHub:MRHUDSON69:CVE-2026-31431, Vulners:PublicExploit:GitHub:COZYSTACK:COPY-FAIL-BLOCKER, Vulners:PublicExploit:GitHub:ADAMPIELAK:CVE-2026-31431_SCA_WAZUH, Vulners:PublicExploit:GitHub:HELIOS973:CVE-2026-31431_EXP.C, Vulners:PublicExploit:GitHub:MYVPS2024-COMMITS:CVE_2026_31431, Vulners:PublicExploit:GitHub:SERCURITYCYBER:COPY-FAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:SONGZZZZ:CVE-2026-31431, Vulners:PublicExploit:GitHub:2H-K:COPYFAILRECURRENCE, Vulners:PublicExploit:GitHub:HAYDENJAMES:DIRTY-FRAG-CHECK, Vulners:PublicExploit:GitHub:0XLANE:PAGECACHE-GUARD, Vulners:PublicExploit:GitHub:ROSNLR5:MITIGATIONTOOLKIT-ROSN-LR5-FULL, Vulners:PublicExploit:GitHub:G01D3NW01F:CVE-2026-31431, Vulners:PublicExploit:GitHub:LMAKONEM:DIRTYFRAG-LAB, Vulners:PublicExploit:GitHub:ADYSEC:CVE-2026-31431, Vulners:PublicExploit:GitHub:3JEE:COPY-FAIL-GO, Vulners:PublicExploit:GitHub:KALETH4:CVE-2026-31431, Vulners:PublicExploit:GitHub:VYAHELLO:CVE-2026-31431, Vulners:PublicExploit:GitHub:CRIHEXE:COPY-FAIL-TINY-ELF-CVE-2026-31431, Vulners:PublicExploit:GitHub:MHDGNING131:CVE-2026-31431_POC, Vulners:PublicExploit:GitHub:QENGINEERING:RK35XX-COPYFAIL-HOTFIX, Vulners:PublicExploit:GitHub:XELOXA:COPYFAIL-EXPLOIT, Vulners:PublicExploit:GitHub:WEBSECNL:CVE-2026-31431, Vulners:PublicExploit:GitHub:JNAMERZ:COPYFAIL-CVE-2026-31431, Vulners:PublicExploit:04A5C710-1476-5097-B582-5B8A2F56C25E, Vulners:PublicExploit:73BC1BD5-F47B-587F-8097-46A6928F2661, Vulners:PublicExploit:EDB-ID:52573, Vulners:PublicExploit:MSF:EXPLOIT-LINUX-LOCAL-CVE_2026_31431_COPY_FAIL-, BDU:PublicExploit websites |
| Criticality of Vulnerability Type | 0.85 | 15 | Elevation of Privilege |
| Vulnerable Product is Common | 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel |
| CVSS Base Score | 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source |
| EPSS Percentile | 1.0 | 10 | EPSS Probability is 0.94545, EPSS Percentile is 0.99846 |
5.
Elevation of Privilege - Linux Kernel (CVE-2026-43284) - Urgent [932]
Description: In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a private copy. The IPv4/IPv6 datagram append paths did not set this flag when splicing pages into UDP skbs. That leaves an ESP-in-UDP packet made from shared pipe pages looking like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW fast path for uncloned skbs without a frag_list and decrypts in place over data that is not owned privately by the skb. Mark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching TCP. Also make ESP input fall back to skb_cow_data() when the flag is present, so ESP does not decrypt externally backed frags in place. Private nonlinear skb frags still use the existing fast path. This intentionally does not change ESP output. In esp_output_head(), the path that appends the ESP trailer to existing skb tailroom without calling skb_cow_data() is not reachable for nonlinear skbs: skb_tailroom() returns zero when skb->data_len is nonzero, while ESP tailen is positive. Thus ESP output will either use the separate destination-frag path or fall back to skb_cow_data().
| Component | Value | Weight | Comment |
|---|
| Exploited in the Wild | 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (vulncheck_kev object) website |
| Exploit Exists | 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, Vulners:PublicExploit:GitHub:PORTBUSTER1337:LPE-TOOLKIT, Vulners:PublicExploit:GitHub:FIRST-JOHN:CVE-2026-43500, Vulners:PublicExploit:GitHub:K3YSTR0K3R:CVE-2026-43284-CVE-2026-43500-EXPLOIT, Vulners:PublicExploit:GitHub:XD20111:CVE-2026-43284, Vulners:PublicExploit:GitHub:ZEYUANGUO:DIRTYFRAG, Vulners:PublicExploit:GitHub:H4ZAZ:DIRTYFRAG-LINUX-KERNEL-LOCAL-PRIVILEGE-ESCALATION-EDUCATIONAL-MIRROR-, Vulners:PublicExploit:GitHub:MYM0US3R:DIRTY-FRAG-DETECTION-WITH-WAZUH-4.14.4, Vulners:PublicExploit:GitHub:ATLASVECTOR:DIRTY-FRAG-CVE-2026-43284, Vulners:PublicExploit:GitHub:MADEXPLOITS:CVE-2026-46300, Vulners:PublicExploit:GitHub:KARAZAJAC:DIRTYFAIL, Vulners:PublicExploit:GitHub:H0MI3E:CENTIPEDE, Vulners:PublicExploit:GitHub:FROSTERDL:CVE-2026-43284, Vulners:PublicExploit:GitHub:G0THAMRABB1T:DIRTYFRAG-CVE-2026-43284-AUDITD-DETECTION, Vulners:PublicExploit:GitHub:V4BEL:DIRTYFRAG, Vulners:PublicExploit:GitHub:WHOSFAULT:CVE-2026-43284, Vulners:PublicExploit:GitHub:JAYHUTAJULU1:CVE-2026-43284-DIRTYFRAG-POC, Vulners:PublicExploit:GitHub:1NEPTUNE:DIRTYFRAG, Vulners:PublicExploit:GitHub:LR1458644438:DIRTY-FRAG-ANALYSIS, Vulners:PublicExploit:GitHub:HAYDENJAMES:DIRTY-FRAG-CHECKER, Vulners:PublicExploit:GitHub:CYBER-NIZ:DIRTY-FRAG, Vulners:PublicExploit:GitHub:SUOMINEN:CVE-2026-43284, Vulners:PublicExploit:GitHub:LUCASPDINIZ:CVE-2026-43284, Vulners:PublicExploit:GitHub:SCRIPTZTEAM:PARANOID-DIRTY-FRAG-CVE-2026-43284, Vulners:PublicExploit:GitHub:PERCIVALLL:DIRTY-FRAG-KUBERNETES-POC, Vulners:PublicExploit:GitHub:LIAMROMANIS101:DIRTYFRAG-DETECTOR, Vulners:PublicExploit:GitHub:T1CKPRIVATE:CVE-2026-43284-DIRTY-FRAG, Vulners:PublicExploit:GitHub:METALX1993:DIRTYFRAG-PATCHES, Vulners:PublicExploit:GitHub:HAYDENJAMES:DIRTY-FRAG-CHECK, Vulners:PublicExploit:EDB-ID:52585, Vulners:PublicExploit:EDB-ID:52591, Vulners:PublicExploit:MSF:EXPLOIT-LINUX-LOCAL-CVE_2026_43284_DIRTY_FRAG-, BDU:PublicExploit, Dirty Frag: Universal Linux LPE websites |
| Criticality of Vulnerability Type | 0.85 | 15 | Elevation of Privilege |
| Vulnerable Product is Common | 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel |
| CVSS Base Score | 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source |
| EPSS Percentile | 1.0 | 10 | EPSS Probability is 0.93235, EPSS Percentile is 0.99825 |
6.
Elevation of Privilege - Linux Kernel (CVE-2026-43500) - Urgent [932]
Description: xfrm-ESP Page-Cache Write provides a powerful arbitrary 4-byte STORE primitive like Copy Fail, and is included on most distributions, but it requires the privilege to create a namespace. Ubuntu sometimes blocks unprivileged user namespace creation through AppArmor policy. In such an environment, xfrm-ESP Page-Cache Write cannot be triggered. RxRPC Page-Cache Write does not require the privilege to create a namespace, but the rxrpc.ko module itself is not included in most distributions. However, on Ubuntu, the rxrpc.ko module is loaded by default. Chaining the two variants makes the blind spots cover each other, allowing root privileges to be obtained on every major distribution. For details, refer to the technical details document.
| Component | Value | Weight | Comment |
|---|
| Exploited in the Wild | 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (vulncheck_kev object) website |
| Exploit Exists | 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:FIRST-JOHN:CVE-2026-43500, Vulners:PublicExploit:GitHub:K3YSTR0K3R:CVE-2026-43284-CVE-2026-43500-EXPLOIT, Vulners:PublicExploit:GitHub:ZEYUANGUO:DIRTYFRAG, Vulners:PublicExploit:GitHub:METALX1993:KERNEL-EXPLOIT-INTELLIGENCE, Vulners:PublicExploit:GitHub:H4ZAZ:DIRTYFRAG-LINUX-KERNEL-LOCAL-PRIVILEGE-ESCALATION-EDUCATIONAL-MIRROR-, Vulners:PublicExploit:GitHub:MYM0US3R:DIRTY-FRAG-DETECTION-WITH-WAZUH-4.14.4, Vulners:PublicExploit:GitHub:MADEXPLOITS:CVE-2026-46300, Vulners:PublicExploit:GitHub:KARAZAJAC:DIRTYFAIL, Vulners:PublicExploit:GitHub:H0MI3E:CENTIPEDE, Vulners:PublicExploit:GitHub:FROSTERDL:CVE-2026-43284, Vulners:PublicExploit:GitHub:V4BEL:DIRTYFRAG, Vulners:PublicExploit:GitHub:1NEPTUNE:DIRTYFRAG, Vulners:PublicExploit:GitHub:LR1458644438:DIRTY-FRAG-ANALYSIS, Vulners:PublicExploit:GitHub:HAYDENJAMES:DIRTY-FRAG-CHECKER, Vulners:PublicExploit:GitHub:LUCASPDINIZ:CVE-2026-43284, Vulners:PublicExploit:GitHub:LIAMROMANIS101:DIRTYFRAG-DETECTOR, Vulners:PublicExploit:GitHub:METALX1993:DIRTYFRAG-PATCHES, Vulners:PublicExploit:GitHub:HAYDENJAMES:DIRTY-FRAG-CHECK, Vulners:PublicExploit:EDB-ID:52585, Vulners:PublicExploit:EDB-ID:52591, Vulners:PublicExploit:MSF:EXPLOIT-LINUX-LOCAL-CVE_2026_43500_DIRTY_FRAG-, BDU:PublicExploit, Dirty Frag: Universal Linux LPE websites |
| Criticality of Vulnerability Type | 0.85 | 15 | Elevation of Privilege |
| Vulnerable Product is Common | 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel |
| CVSS Base Score | 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source |
| EPSS Percentile | 1.0 | 10 | EPSS Probability is 0.92855, EPSS Percentile is 0.9982 |
7.
Remote Code Execution - Apache ActiveMQ (CVE-2026-34197) - Urgent [921]
Description: Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. Because Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec(). This issue affects Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ All: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.3. Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue
| Component | Value | Weight | Comment |
|---|
| Exploited in the Wild | 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, CISA object, cisa_kev object, vulncheck_kev object), AttackerKB, NVD:CISAKEV websites |
| Exploit Exists | 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:ASDASDDQWDQ29-A11Y:CVE-2026-34197, Vulners:PublicExploit:GitHub:HNYTGL:CVE-2026-34197, Vulners:PublicExploit:GitHub:ROOTDIRECTIVE-SEC:CVE-2026-34197-LAB, Vulners:PublicExploit:GitHub:K3YSTR0K3R:CVE-2026-34197, Vulners:PublicExploit:GitHub:DEVSECURITYSPRO:CVE-2026-34197, Vulners:PublicExploit:GitHub:KERAATTIN:CVE-2026-34197, Vulners:PublicExploit:GitHub:DINOSN:APACHE-ACTIVEMQ-RCE-RESEARCH, Vulners:PublicExploit:GitHub:ATOPOSX-J:CVE-2026-34197-APACHE-ACTIVEMQ-RCE, Vulners:PublicExploit:GitHub:LAT-06:CVE-2026-34197, Vulners:PublicExploit:GitHub:DINOSN:CVE-2026-34197, Vulners:PublicExploit:GitHub:HG0434HONGZH0:CVE-2026-34197, Vulners:PublicExploit:MSF:EXPLOIT-MULTI-HTTP-APACHE_ACTIVEMQ_JOLOKIA_RCE-, Vulners:PublicExploit:PACKETSTORM:222271, Vulners:PublicExploit:PACKETSTORM:222315, BDU:PublicExploit websites |
| Criticality of Vulnerability Type | 1.0 | 15 | Remote Code Execution |
| Vulnerable Product is Common | 0.6 | 14 | Apache ActiveMQ is an open source message broker written in Java together with a full Java Message Service (JMS) client |
| CVSS Base Score | 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source |
| EPSS Percentile | 1.0 | 10 | EPSS Probability is 0.9722, EPSS Percentile is 0.99888 |
8.
Remote Code Execution - PAN-OS (CVE-2026-0300) - Urgent [916]
Description: A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.
| Component | Value | Weight | Comment |
|---|
| Exploited in the Wild | 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (CISA object, cisa_kev object, vulncheck_kev object), AttackerKB, NVD:CISAKEV websites |
| Exploit Exists | 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:BANNNED-BIT:CVE-2026-0300-PANOS, Vulners:PublicExploit:GitHub:RIDHINVA:CVE-2026-0300-PANOS-RCE, Vulners:PublicExploit:GitHub:MR-R3B00T:CVE-2026-0300, Vulners:PublicExploit:GitHub:BYTEWRAITH1:CVE-2026-0300, Vulners:PublicExploit:GitHub:LU4M575:CVE-2026-0300, Vulners:PublicExploit:GitHub:SHIZUKU198411:CVE-2026-0300, BDU:PublicExploit websites |
| Criticality of Vulnerability Type | 1.0 | 15 | Remote Code Execution |
| Vulnerable Product is Common | 0.5 | 14 | PAN-OS is the software that runs all Palo Alto Networks next-generation firewalls |
| CVSS Base Score | 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source |
| EPSS Percentile | 1.0 | 10 | EPSS Probability is 0.32074, EPSS Percentile is 0.9814 |
9.
Elevation of Privilege - Microsoft Defender (CVE-2026-41091) - Urgent [904]
Description: Microsoft Defender Elevation of Privilege Vulnerability
10.
Information Disclosure - Microsoft Desktop Window Manager (CVE-2026-20805) - Urgent [901]
Description: Desktop Window Manager Information Disclosure Vulnerability
| Component | Value | Weight | Comment |
|---|
| Exploited in the Wild | 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, CISA object, cisa_kev object, vulncheck_kev object), AttackerKB, Microsoft, NVD:CISAKEV websites |
| Exploit Exists | 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:SIMOESCTT:-SCTT-2026-33-0002-DWM-VISUAL-FIELD-SINGULARITY, Vulners:PublicExploit:GitHub:FEVAR54:CVE-2026-20805-POC, Vulners:PublicExploit:GitHub:UZAIR-BAIG0900:CVE-2026-20805-POC, Vulners:PublicExploit:GitHub:SIMOESCTT:CTT-MEMORY-VORTEX-20805, Vulners:PublicExploit:GitHub:SIMOESCTT:SCTT-2026-33-0002-DWM-VISUAL-FIELD-SINGULARITY, BDU:PublicExploit websites |
| Criticality of Vulnerability Type | 0.83 | 15 | Information Disclosure |
| Vulnerable Product is Common | 0.95 | 14 | Desktop Window Manager (DWM) is a core component of Microsoft Windows responsible for compositing and rendering the graphical user interface, including window effects, transparency, and desktop composition. |
| CVSS Base Score | 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source |
| EPSS Percentile | 0.9 | 10 | EPSS Probability is 0.05028, EPSS Percentile is 0.914 |
11.
Cross Site Scripting - Microsoft Exchange (CVE-2026-42897) - Urgent [895]
Description: {'ms_cve_data_all': 'Microsoft Exchange Server Spoofing Vulnerability', 'nvd_cve_data_all': 'Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|
| Exploited in the Wild | 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, CISA object, cisa_kev object, vulncheck_kev object), AttackerKB, Microsoft, NVD:CISAKEV websites |
| Exploit Exists | 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:ATIILLA:CVE-2026-42897, BDU:PublicExploit websites |
| Criticality of Vulnerability Type | 0.8 | 15 | Cross Site Scripting |
| Vulnerable Product is Common | 0.8 | 14 | Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft |
| CVSS Base Score | 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source |
| EPSS Percentile | 0.9 | 10 | EPSS Probability is 0.0564, EPSS Percentile is 0.9217 |
12.
Remote Code Execution - Microsoft SharePoint (CVE-2026-20963) - Urgent [848]
Description: Microsoft SharePoint Remote Code Execution Vulnerability
| Component | Value | Weight | Comment |
|---|
| Exploited in the Wild | 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (CISA object, cisa_kev object, vulncheck_kev object), AttackerKB, NVD:CISAKEV websites |
| Exploit Exists | 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website |
| Criticality of Vulnerability Type | 1.0 | 15 | Remote Code Execution |
| Vulnerable Product is Common | 0.7 | 14 | Microsoft SharePoint |
| CVSS Base Score | 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source |
| EPSS Percentile | 1.0 | 10 | EPSS Probability is 0.29459, EPSS Percentile is 0.97992 |
13.
Elevation of Privilege - Microsoft Desktop Window Manager (CVE-2026-21519) - Urgent [816]
Description: Desktop Window Manager Elevation of Privilege Vulnerability
| Component | Value | Weight | Comment |
|---|
| Exploited in the Wild | 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, CISA object, cisa_kev object, vulncheck_kev object), AttackerKB, Microsoft, NVD:CISAKEV websites |
| Exploit Exists | 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website |
| Criticality of Vulnerability Type | 0.85 | 15 | Elevation of Privilege |
| Vulnerable Product is Common | 0.95 | 14 | Desktop Window Manager (DWM) is a core component of Microsoft Windows responsible for compositing and rendering the graphical user interface, including window effects, transparency, and desktop composition. |
| CVSS Base Score | 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source |
| EPSS Percentile | 0.8 | 10 | EPSS Probability is 0.0242, EPSS Percentile is 0.82512 |
14.
Elevation of Privilege - Windows Remote Desktop Services (CVE-2026-21533) - Urgent [802]
Description: Windows Remote Desktop Services Elevation of Privilege Vulnerability
| Component | Value | Weight | Comment |
|---|
| Exploited in the Wild | 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, CISA object, cisa_kev object, vulncheck_kev object), AttackerKB, Microsoft, NVD:CISAKEV websites |
| Exploit Exists | 0.5 | 17 | The existence of a private exploits is mentioned on Microsoft:PrivateExploit:Functional, BDU:PrivateExploit websites |
| Criticality of Vulnerability Type | 0.85 | 15 | Elevation of Privilege |
| Vulnerable Product is Common | 0.8 | 14 | Remote Desktop Services, known as Terminal Services in Windows Server 2008 and earlier, is one of the components of Microsoft Windows that allow a user to initiate and control an interactive session on a remote computer or virtual machine over a network connection |
| CVSS Base Score | 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source |
| EPSS Percentile | 0.9 | 10 | EPSS Probability is 0.03846, EPSS Percentile is 0.89067 |
Critical (3)
15.
Spoofing - Microsoft SharePoint Server (CVE-2026-32201) - Critical [773]
Description: Microsoft SharePoint Server Spoofing Vulnerability
| Component | Value | Weight | Comment |
|---|
| Exploited in the Wild | 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (CISA object, cisa_kev object, vulncheck_kev object), AttackerKB, Microsoft, NVD:CISAKEV websites |
| Exploit Exists | 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:B1TBIT:CVE-2026-32201-EXPLOIT website |
| Criticality of Vulnerability Type | 0.4 | 15 | Spoofing |
| Vulnerable Product is Common | 0.5 | 14 | Microsoft SharePoint Server |
| CVSS Base Score | 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source |
| EPSS Percentile | 1.0 | 10 | EPSS Probability is 0.21476, EPSS Percentile is 0.97365 |
16.
Remote Code Execution - Microsoft Word (CVE-2026-21514) - Critical [772]
Description: {'ms_cve_data_all': 'Microsoft Word Security Feature Bypass Vulnerability', 'nvd_cve_data_all': 'Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|
| Exploited in the Wild | 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, CISA object, cisa_kev object, vulncheck_kev object), AttackerKB, Microsoft, NVD:CISAKEV websites |
| Exploit Exists | 0.5 | 17 | The existence of a private exploits is mentioned on Microsoft:PrivateExploit:Functional, BDU:PrivateExploit websites |
| Criticality of Vulnerability Type | 1.0 | 15 | Remote Code Execution |
| Vulnerable Product is Common | 0.6 | 14 | Microsoft Word is a widely used commercial word processor developed by Microsoft. It is a component of the Microsoft Office suite of productivity software but can also be purchased as a standalone product. |
| CVSS Base Score | 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source |
| EPSS Percentile | 0.7 | 10 | EPSS Probability is 0.01517, EPSS Percentile is 0.72005 |
17.
Elevation of Privilege - Linux Kernel (CVE-2026-46300) - Critical [706]
Description: In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to. If @from has SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same externally-owned or page-cache-backed frags, but the shared-frag marker is currently lost. That breaks the invariant relied on by later in-place writers. In particular, ESP input checks skb_has_shared_frag() before deciding whether an uncloned nonlinear skb can skip skb_cow_data(). If TCP receive coalescing has moved shared frags into an unmarked skb, ESP can see skb_has_shared_frag() as false and decrypt in place over page-cache backed frags. Propagate SKBFL_SHARED_FRAG when skb_try_coalesce() transfers paged frags. The tailroom copy path does not need the marker because it copies bytes into @to's linear data rather than transferring frag descriptors.
| Component | Value | Weight | Comment |
|---|
| Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources |
| Exploit Exists | 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:MADEXPLOITS:CVE-2026-46300, Vulners:PublicExploit:GitHub:1NEPTUNE:FRAGNESIA, Vulners:PublicExploit:GitHub:MAXIME288:FRAGNESIA-CVE-2026-46300, Vulners:PublicExploit:GitHub:AZDEVOPS143:FRAGNESIA-CHARAN-CVE-2026-46300, Vulners:PublicExploit:GitHub:AZILRABABE:CVE-2026-46300, Vulners:PublicExploit:GitHub:SENTEBALE:CVE-2026-46300, Vulners:PublicExploit:GitHub:0XDEADROOT:FRAGNESIA-PYTHON-EXPLOIT, Vulners:PublicExploit:GitHub:EXPLOITEOOM:CVE-2026-46300, Vulners:PublicExploit:GitHub:HORKIMHAB:CVE-2026-46300, Vulners:PublicExploit:GitHub:AZDEVOPS143:FRAGNESIA-CVE-2026-46300, Vulners:PublicExploit:EDB-ID:52591, BDU:PublicExploit websites |
| Criticality of Vulnerability Type | 0.85 | 15 | Elevation of Privilege |
| Vulnerable Product is Common | 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel |
| CVSS Base Score | 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source |
| EPSS Percentile | 0.9 | 10 | EPSS Probability is 0.07006, EPSS Percentile is 0.93505 |
High (0)
Medium (0)
Low (0)
Exploitation in the wild detected (16)
Remote Code Execution (7)
Elevation of Privilege (6)
Information Disclosure (1)
Cross Site Scripting (1)
Spoofing (1)
Public exploit exists, but exploitation in the wild is NOT detected (1)
Elevation of Privilege (1)
Other Vulnerabilities (0)