Report Name: pt_trend_cve_combined2026_h1 report
Generated: 2026-07-30 23:40:05

Vulristics Vulnerability Scores
Basic Vulnerability Scores
Products

Product NamePrevalenceUCHMLAComment
Microsoft Desktop Window Manager0.9522Desktop Window Manager (DWM) is a core component of Microsoft Windows responsible for compositing and rendering the graphical user interface, including window effects, transparency, and desktop composition.
Linux Kernel0.9314The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel
Adobe Reader0.811Adobe Acrobat is a family of application software and Web services developed by Adobe Inc. to view, create, manipulate, print and manage Portable Document Format files
Microsoft Defender0.811Anti-malware component of Microsoft Windows
Microsoft Exchange0.811Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft
Microsoft Office0.811Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer
Windows Remote Desktop Services0.811Remote Desktop Services, known as Terminal Services in Windows Server 2008 and earlier, is one of the components of Microsoft Windows that allow a user to initiate and control an interactive session on a remote computer or virtual machine over a network connection
Windows Shell0.811Windows component
Microsoft SharePoint0.711Microsoft SharePoint
Apache ActiveMQ0.611Apache ActiveMQ is an open source message broker written in Java together with a full Java Message Service (JMS) client
Microsoft Word0.611Microsoft Word is a widely used commercial word processor developed by Microsoft. It is a component of the Microsoft Office suite of productivity software but can also be purchased as a standalone product.
Microsoft SharePoint Server0.511Microsoft SharePoint Server
PAN-OS0.511PAN-OS is the software that runs all Palo Alto Networks next-generation firewalls


Vulnerability Types

Vulnerability TypeCriticalityUCHMLA
Remote Code Execution1.0617
Elevation of Privilege0.85617
Information Disclosure0.8311
Cross Site Scripting0.811
Spoofing0.411


Vulnerabilities

Urgent (14)

1. Remote Code Execution - Windows Shell (CVE-2026-21510) - Urgent [954]

Description: {'ms_cve_data_all': 'Windows Shell Security Feature Bypass Vulnerability', 'nvd_cve_data_all': 'Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}

ComponentValueWeightComment
Exploited in the Wild1.018Exploitation in the wild is mentioned on Vulners (AttackerKB object, CISA object, cisa_kev object, vulncheck_kev object), AttackerKB, Microsoft, NVD:CISAKEV websites
Exploit Exists1.017The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:ANDREASSUDO:CVE-2026-21510-CVSS-8.8-IMPORTANT-WINDOWS-SHELL-SECURITY-FEATURE-BYPASS, Vulners:PublicExploit:GitHub:EPSILONPOINTORI:EPSILONPOINTLNK, Vulners:PublicExploit:GitHub:VIRUS-OR-NOT:CVE-2026-32202 websites
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.910CVSS Base Score is 8.8. According to Microsoft data source
EPSS Percentile1.010EPSS Probability is 0.25835, EPSS Percentile is 0.97766

2. Remote Code Execution - Adobe Reader (CVE-2026-34621) - Urgent [942]

Description: Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

ComponentValueWeightComment
Exploited in the Wild1.018Exploitation in the wild is mentioned on Vulners (CISA object, cisa_kev object, vulncheck_kev object), AttackerKB, NVD:CISAKEV websites
Exploit Exists1.017The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:SANCHIT-SAINI:ACROBAT-READER-ESCAPE, Vulners:PublicExploit:GitHub:NULL200OK:CVE_2026_34621_ADVANCED, Vulners:PublicExploit:GitHub:DAJNEEM23:CVE-2026-3462, BDU:PublicExploit websites
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Adobe Acrobat is a family of application software and Web services developed by Adobe Inc. to view, create, manipulate, print and manage Portable Document Format files
CVSS Base Score0.910CVSS Base Score is 8.6. According to NVD data source
EPSS Percentile0.910EPSS Probability is 0.07086, EPSS Percentile is 0.93569

3. Remote Code Execution - Microsoft Office (CVE-2026-21509) - Urgent [942]

Description: {'ms_cve_data_all': 'Microsoft Office Security Feature Bypass Vulnerability', 'nvd_cve_data_all': 'Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}

ComponentValueWeightComment
Exploited in the Wild1.018Exploitation in the wild is mentioned on Vulners (AttackerKB object, CISA object, cisa_kev object, vulncheck_kev object), AttackerKB, Microsoft, NVD:CISAKEV websites
Exploit Exists1.017The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:ASHWESKER:ASHWESKER-CVE-2026-21509, Vulners:PublicExploit:GitHub:NICOLE2ILODL:CVE-2026-21509-POC, Vulners:PublicExploit:GitHub:SENTINEL-AIDEFENSE:CVE-2026-21509, Vulners:PublicExploit:GitHub:DECALAGE2:DETECT_CVE-2026-21509, Vulners:PublicExploit:GitHub:GAVZ:CVE-2026-21509-POC, Vulners:PublicExploit:GitHub:SIMOESCTT:CTT-NFS-VORTEX-RCE, Vulners:PublicExploit:GitHub:DAMEDODE:CVE-2026-21509-POC, Vulners:PublicExploit:GitHub:SIMOESCTT:CTT-MICROSOFT-OFFICE-OLE-MANIFOLD-BYPASS-CVE-2026-21509, Vulners:PublicExploit:GitHub:RAZUREINK:CVE-2026-21509-OFFICE_SECURITY_BYPASS_REPRODUCTION, Vulners:PublicExploit:GitHub:XZ1R0:CVE-2026-POC-COLLECTION, Vulners:PublicExploit:GitHub:SUUHM:CVE-2026-21509-HANDLER, Vulners:PublicExploit:GitHub:INCURSIOHACK:CVE-2026-21509-POC, Vulners:PublicExploit:GitHub:PLANETOID:CVE-2026-21509-MITIGATION websites
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile1.010EPSS Probability is 0.72152, EPSS Percentile is 0.99371

4. Elevation of Privilege - Linux Kernel (CVE-2026-31431) - Urgent [932]

Description: In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

ComponentValueWeightComment
Exploited in the Wild1.018Exploitation in the wild is mentioned on Vulners (CISA object, cisa_kev object, vulncheck_kev object), AttackerKB, NVD:CISAKEV websites
Exploit Exists1.017The existence of a publicly available exploit is mentioned on NVD:PublicExploit:xint.io, Vulners:PublicExploit:GitHub:PYROCEPER:COPY-FAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:TGIES:COPY-FAIL-C, Vulners:PublicExploit:GitHub:B5NULL:CVE-2026-31431-C, Vulners:PublicExploit:GitHub:IBLAMENEAR:CVE-2026-31431-COPY-FAIL---ADVANCED-LPE-PROOF-OF-CONCEPT---C-REWRITE, Vulners:PublicExploit:GitHub:ABDELKABIROUADOUKOU:CVE-2026-31431-ANALYSIS-AND-FIX, Vulners:PublicExploit:GitHub:RAT5AK:CVE-2026-31431-COPY-FAIL-POC---578B, Vulners:PublicExploit:GitHub:ATTAATTAATTA:CVE-2026-31431, Vulners:PublicExploit:GitHub:SEC17BR:CVE-2026-31431-COPY-FAIL, Vulners:PublicExploit:GitHub:SPENSERCAI:COPY_FAIL, Vulners:PublicExploit:GitHub:KVAKIRSANOV:CVE-2026-31431-LIVE-PROCESS-CODE-INJECTION, Vulners:PublicExploit:GitHub:HAYDENJAMES:CVE-2026-31431-CHECK, Vulners:PublicExploit:GitHub:FIRST-JOHN:CVE-2026-43500, Vulners:PublicExploit:GitHub:CS8425:COPY-FAIL-GO, Vulners:PublicExploit:GitHub:B1GN0SE:COPY-FAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:AESTECHNO:CVE-2026-31431-ANSIBLE, Vulners:PublicExploit:GitHub:CXWX:CPP-CVE-2026-31431, Vulners:PublicExploit:GitHub:JUGUITOS:COPY-FAIL, Vulners:PublicExploit:GitHub:MARTINPHAM:COPY-FAIL-CVE-2026-31431-PHP, Vulners:PublicExploit:GitHub:CX330ZER0:CVE-2026-31431-COPY-FAIL-ADD-ARM64, Vulners:PublicExploit:GitHub:SILENT4LABS:CHECK-COPYFAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:PARMSTRO:COPY-FAIL-DETECT, Vulners:PublicExploit:GitHub:ALVAROGUZMANCODE:CVE-2026-31431-MITIGACION, Vulners:PublicExploit:GitHub:BADSECTORLABS:COPYFAIL-GO, Vulners:PublicExploit:GitHub:XD20111:CVE-2026-31431, Vulners:PublicExploit:GitHub:DANIMRTZP:CVE-2026-31431-REVSHELL, Vulners:PublicExploit:GitHub:KOSHMARE-BLOSSOM:COPYFAIL-SH, Vulners:PublicExploit:GitHub:ZENZUE:CVE-2026-31431-CHECKER-MITIGATOR, Vulners:PublicExploit:GitHub:DETECT-DEFENSELAB:CVE-2026-31431-DETECTION-DEFENSE, Vulners:PublicExploit:GitHub:ROOTSECDEV:CVE_2026_31431, Vulners:PublicExploit:GitHub:ADITYABHATT3010:CVE-2026-31431, Vulners:PublicExploit:GitHub:EUROFIBER-CLOUDINFRA:EFCI-COPYFAIL-MITIGATION, Vulners:PublicExploit:GitHub:THEMURSALIN:CVE-2026-31431, Vulners:PublicExploit:GitHub:FULUCKY0-YURI:CVE-2026-31431-POCC, Vulners:PublicExploit:GitHub:AEGEIGER:OPENSHELL-SANDBOX-POC, Vulners:PublicExploit:GitHub:BIGWARIO:COPY-FAIL-CVE-2026-31431-C, Vulners:PublicExploit:GitHub:0XDEADBEEFNETWORK:COPY_FAIL2-ELECTRIC_BOOGALOO, Vulners:PublicExploit:GitHub:KARAZAJAC:DIRTYFAIL, Vulners:PublicExploit:GitHub:RAPTORATACK:COPYFAIL-SCANNER-CVE-2026-31431, Vulners:PublicExploit:GitHub:SHOTAFRY:COPYFAIL-EXPLOITS-CVE-2026-31431, Vulners:PublicExploit:GitHub:WVVEREZ:CVE-2026-31431-COPY-FAIL, Vulners:PublicExploit:GitHub:SAMSULMAARIF:LINUX-COPY-FAIL-EXPLOIT, Vulners:PublicExploit:GitHub:SHADOWABI:CVE-2026-31431-COPYFAIL-UNIVERSAL-LPE, Vulners:PublicExploit:GitHub:NISEC-ERIC:CVE-2026-31431, Vulners:PublicExploit:GitHub:ZEPHRFISH:COPYFAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:MR-BV:COPY-FAIL-CVE-2026-31431-EXPLOIT-IN-C, Vulners:PublicExploit:GitHub:ADITYASINGH108:CVE-2026-31431-METASPLOIT-EXPLOIT, Vulners:PublicExploit:GitHub:4N4S4ZI:COPYFAIL-ALPINE, Vulners:PublicExploit:GitHub:PAULORLIMA9:COPYFAIL-FIX, Vulners:PublicExploit:GitHub:RAZVANDUDA:GHOSTSHELL, Vulners:PublicExploit:GitHub:H1D3R:COPY-FAIL_LPE_INTERACTIVE, Vulners:PublicExploit:GitHub:DANFORD2017:COPY-FAIL---CVE-2026-31431, Vulners:PublicExploit:GitHub:ROYAYUB:CVE-2026-31431, Vulners:PublicExploit:GitHub:UNCLECHENG-LI:POC-LAB, Vulners:PublicExploit:GitHub:HORI0729:CVE-2026-31431-VERIFICADOR-EXPLOIT, Vulners:PublicExploit:GitHub:SIBERSAN:CVE-2026-31431-CHECKER, Vulners:PublicExploit:GitHub:STARXSKY:CVE-2026-31431, Vulners:PublicExploit:GitHub:MARIOHY:CVE_2026_31431_AUDIT, Vulners:PublicExploit:GitHub:THRANDOMV:CVE-2026-31431-DETECTION, Vulners:PublicExploit:GitHub:RIVALDOFWIJAYA:COPY-SUCCESS, Vulners:PublicExploit:GitHub:KINRYULABS:ROOTPACKET-CVE-2026-31431, Vulners:PublicExploit:GitHub:SUDOYTANG:COPYFAIL-ARM64, Vulners:PublicExploit:GitHub:STRUTTONPIGEON:OSCPTOOLKIT, Vulners:PublicExploit:GitHub:MONOBRAU:COPYFAILSCAN, Vulners:PublicExploit:GitHub:PAINOOB:COPY-FAIL-EXPLOIT-CVE-2026-31431, Vulners:PublicExploit:GitHub:METASPIOIT:CVE-2026-31431, Vulners:PublicExploit:GitHub:PERCIVALLL:COPY-FAIL-CVE-2026-31431-KUBERNETES-POC, Vulners:PublicExploit:GitHub:PULENTOSKI:CVE-2026-31431, Vulners:PublicExploit:GitHub:WGNET:WG.COPYFAIL.PATCH, Vulners:PublicExploit:GitHub:DULLPURPLE-SLOOP726:CVE-2026-31431-LINUX-COPY-FAIL, Vulners:PublicExploit:GitHub:SL4CK0TH:CVE-2026-31431-POC, Vulners:PublicExploit:GitHub:HORI0729:CVE-2026-31431---COPY-FAIL-VERIFICADOR-EXPLOIT, Vulners:PublicExploit:GitHub:KAROLLOOOOL:PORTING-CVE-2026-31431-COPY-FAIL-TO-A-CONSTRAINED-JAVA-RUNNER, Vulners:PublicExploit:GitHub:Y5NEKO:COPY-FAIL-CVE-2026-31431-UNIVERSAL, Vulners:PublicExploit:GitHub:BRYANVINE:COPY-FAIL-FIX, Vulners:PublicExploit:GitHub:CODESOURCE:COPYFAIL-CHECK, Vulners:PublicExploit:GitHub:POVZAYD:CVE-2026-31431, Vulners:PublicExploit:GitHub:RVIZX:CVE-2026-31431, Vulners:PublicExploit:GitHub:DESULTORY:CVE-2026-31431, Vulners:PublicExploit:GitHub:MCUB3:CVE-2026-31431, Vulners:PublicExploit:GitHub:T1CKPRIVATE:CVE-2026-31431-COPY-FAIL, Vulners:PublicExploit:GitHub:MISHL-DEV:CVE_2026_31431, Vulners:PublicExploit:GitHub:M4XSEC:CVE-2026-31431-RCE-EXPLOIT, Vulners:PublicExploit:GitHub:KW-SOFT:COPYFAIL, Vulners:PublicExploit:GitHub:NAIMADX123:CVE_2026_31431, Vulners:PublicExploit:GitHub:1AMBA7MAN:LINUX-COPY-FAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:POLYAKOVAVV:COPYFAIL, Vulners:PublicExploit:GitHub:MFLORESDACUNHA:CVE-2026-31431, Vulners:PublicExploit:GitHub:CYBROZEUS:COPY-FAIL-EXPLOIT-CVE-2026-31431, Vulners:PublicExploit:GitHub:INSOMNISEC:DETECTIONS-CVE-2026-31431, Vulners:PublicExploit:GitHub:CJ667113:OCI-ANSIBLE-FIX-CVE-2026-31431, Vulners:PublicExploit:GitHub:SAMMWYY:COPYFAIL-RS, Vulners:PublicExploit:GitHub:ASTOUNDS:COPY-FAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:WHOSFAULT:CVE-2026-31431, Vulners:PublicExploit:GitHub:ROSNLR5:MODROSNLR5, Vulners:PublicExploit:GitHub:WUWU001:CVE-2026-31431-EXPLOIT, Vulners:PublicExploit:GitHub:NOVYSODOPE:COPY-FAIL-CVE-2026-31431-C, Vulners:PublicExploit:GitHub:WALTRONE1:COPYFAIL-SAFE-CHECK, Vulners:PublicExploit:GitHub:W3LLR00T3D:CVE-2026-31431-POC, Vulners:PublicExploit:GitHub:WH1SKY02:COPY-FAIL-PYTHON, Vulners:PublicExploit:GitHub:AFMAGHRIBI:TETRAGON-LAB, Vulners:PublicExploit:GitHub:PITHASE:ASM-COPYFAIL, Vulners:PublicExploit:GitHub:EYNAEXP:COPY-FAIL-CVE-2026-31431-MODERNIZED, Vulners:PublicExploit:GitHub:LEELONG2020:CVE-2026-31431, Vulners:PublicExploit:GitHub:BEN-SLATES:CVE-2026-31431-EXPLOIT, Vulners:PublicExploit:GitHub:20ISAAK23:CHALLENGE_UNIX-, Vulners:PublicExploit:GitHub:MALWAREKID:CVE-2026-31431, Vulners:PublicExploit:GitHub:IMKK000:PLAY-GO-COPY-FAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:KALYANI4114:LINUX-COPY-FAIL-EXPLOIT, Vulners:PublicExploit:GitHub:PCDOYLE:COPY-FAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:WESMAR:CVE-2026-31431, Vulners:PublicExploit:GitHub:SBETETA42:CVE-2026-31431_JE_SAPPELLE_ROOT, Vulners:PublicExploit:GitHub:YANGH-BEEP:CVE-2026-31431-C, Vulners:PublicExploit:GitHub:DECKHOUSE:D8-COPY-FAIL-MITIGATION, Vulners:PublicExploit:GitHub:SILENT0X0:COPY-FAIL---CVE-2026-31431, Vulners:PublicExploit:GitHub:PITHASE:ASM-COPYFAIL-, Vulners:PublicExploit:GitHub:MRUNALP:BLOCK-COPYFAIL, Vulners:PublicExploit:GitHub:HUNT-BENITO:COPY-FAIL-CVE-2026-31431-LINUX-KERNEL-PAGE-CACHE-LPE, Vulners:PublicExploit:GitHub:GUBICZAP:CVE-2026-31431-CHECKER, Vulners:PublicExploit:GitHub:GUBAIOVO:CVE-2026-31431, Vulners:PublicExploit:GitHub:INDUSTRI4L-H3LL-XPL0IT3RS:CVE-2026-31431-COPY-FAIL, Vulners:PublicExploit:GitHub:GRABESEC:XCP_NG_CVE-2026-31431_TESTER, Vulners:PublicExploit:GitHub:FREELABZ:CVE-2026-31431, Vulners:PublicExploit:GitHub:SLAUGER:CVE-2026-31431, Vulners:PublicExploit:GitHub:SAMANZAMANI:COPY-FAIL-CHECKER, Vulners:PublicExploit:GitHub:MOHAMEDKARRAB:COPY-FAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:JULIOSUAS:COPYFAIL-GUARD, Vulners:PublicExploit:GitHub:RFXN:COPYFAIL, Vulners:PublicExploit:GitHub:PASCAL-GUJER:CVE-2026-31431, Vulners:PublicExploit:GitHub:LINUX-ZS:CVE-2026-31431-MITIGATION, Vulners:PublicExploit:GitHub:ERDEMOZGEN:COPY-FAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:RODKODANILA:COPY.FAIL.OCP-POC, Vulners:PublicExploit:GitHub:KANBARAAKIHITO:CVE-2026-31431-COPYFAIL-RS, Vulners:PublicExploit:GitHub:SUOMINEN:CVE-2026-31431, Vulners:PublicExploit:GitHub:ISS4CF0NG:CVE-2026-31431-LINUX-COPY-FAIL, Vulners:PublicExploit:GitHub:VASYAPOKEMON:CVE-2026-31431, Vulners:PublicExploit:GitHub:EXIMIAIT:CVE-2026-31431, Vulners:PublicExploit:GitHub:PERCIVALLL:COPY-FAIL-CVE-2026-31431-STATICALLY-POC, Vulners:PublicExploit:GitHub:IKOW:CVE-2026-31431-LIVE-CODE-CORRUPTION, Vulners:PublicExploit:GitHub:SEBINXAVI:CVE-CHECKER-2026, Vulners:PublicExploit:GitHub:GALORYBER:CVE-2026-31431-CLEANED, Vulners:PublicExploit:GitHub:ARKDEV1:CHECK-CVE-2026-31431, Vulners:PublicExploit:GitHub:ZHANGHANGORG:CVE-2026-31431, Vulners:PublicExploit:GitHub:MORTON-LI:COPY-FAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:0XN7Y:CVE-2026-31431, Vulners:PublicExploit:GitHub:RIPPSEC:CVE-2026-31431, Vulners:PublicExploit:GitHub:VEHICLE-SECURITY:POCLAB, Vulners:PublicExploit:GitHub:PEDRO-LUCAS-MELO:ESTUDO-DE-CASO-CVE-2026-31431-COPYFAIL, Vulners:PublicExploit:GitHub:WEBHOSTING4U:COPY-FAIL_DETECT_AND_MITIGATE_CVE-2026-31431, Vulners:PublicExploit:GitHub:XZ1R0:CVE-2026-POC-COLLECTION, Vulners:PublicExploit:GitHub:JOHANBURATI:CVE-2026-31431, Vulners:PublicExploit:GitHub:ROFLSECURITY:COPY_FAIL, Vulners:PublicExploit:GitHub:BEATBEAST007:LINUX-COPYFAIL-C-VERSION-CVE-2026-31431, Vulners:PublicExploit:GitHub:OFFSECGUY:CVE-2026-31431, Vulners:PublicExploit:GitHub:GUIIMORAES:COPYFAIL2-DIRTYFRAG-PY, Vulners:PublicExploit:GitHub:DGROBINSON0:COPYFILE_CVE-2026-31431, Vulners:PublicExploit:GitHub:ADVXRSARY:DIRTYFRAG-DETECTION, Vulners:PublicExploit:GitHub:ALIHZSEC:CVE-2026-31431, Vulners:PublicExploit:GitHub:XN0KKX:CVE-2026-31431_COPYFAIL_LINUXKERNEL_LPE, Vulners:PublicExploit:GitHub:361WAY:CVE-2026-31431, Vulners:PublicExploit:GitHub:LIAMROMANIS101:CVE-2026-31431-COPY-FAIL---VULNERABILITY-DETECTION-SCRIPT, Vulners:PublicExploit:GitHub:MAKITOS666:CVE-2026-31431-COPY-FAIL-DETECTION-TOOLKIT, Vulners:PublicExploit:GitHub:0XFUFFM3:CVE-2026-31431-COPYFAIL, Vulners:PublicExploit:GitHub:PULENTOSKI:CVE-2026-31431-, Vulners:PublicExploit:GitHub:GUIIMORAES:COPYFAIL2-PY, Vulners:PublicExploit:GitHub:JIANGBAN046-SPEC:CVE-2026-31431-EXPLOIT_PY2_PY3, Vulners:PublicExploit:GitHub:HAYDENJAMES:DIRTY-FRAG-CHECKER, Vulners:PublicExploit:GitHub:DENNISDGR:CVE-2026-31431-POC, Vulners:PublicExploit:GitHub:PARMSTRO:CFDR, Vulners:PublicExploit:GitHub:LUTFIFAKEE-PROJECT:CVE-2026-31431, Vulners:PublicExploit:GitHub:LUOTIAN2:CVE-2026-31431, Vulners:PublicExploit:GitHub:MEOWTEUSZ:COPYFAILAUTOPATCH, Vulners:PublicExploit:GitHub:OCHEBOTAR:COPY-FAIL-CVE-2026-31431-DETECTION-PROBE, Vulners:PublicExploit:GitHub:EXPLOITEOOM:CVE-2026-31431, Vulners:PublicExploit:GitHub:JULICHAAN:CVE-2026-31431-PYTHON-COPYFAIL-POC, Vulners:PublicExploit:GitHub:LYUTOON:COPYFAIL-EXPERIMENT, Vulners:PublicExploit:GitHub:PETRA976:SIGMA_RULE_FOR_COPYFAIL, Vulners:PublicExploit:GitHub:VISHVACYBER:DETECTION-TOOL-KIT-FOR-CVE-2026-31431, Vulners:PublicExploit:GitHub:TEMATEMARU:CVE-2026-31431-SIMPLE-TEST, Vulners:PublicExploit:GitHub:POYEA:CVE-2026-31431.C, Vulners:PublicExploit:GitHub:AEXDYHAXOR:CVE-2026-31431-COPY-FAIL, Vulners:PublicExploit:GitHub:MRMIXIES:COPY-FAIL---CVE-2026-31431, Vulners:PublicExploit:GitHub:0XBLACKFOX:COPY-FAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:PROFESSIONAL-SLACKER:ALG_CHECK, Vulners:PublicExploit:GitHub:ABDULLAABDULLAZADE:CVE-2026-31431, Vulners:PublicExploit:GitHub:RIDHINVA:COPYFAIL-CHECKER, Vulners:PublicExploit:GitHub:P401A-OPS:COPY-FAIL, Vulners:PublicExploit:GitHub:TIKOTIKTOK:COPY-FAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:PULLSEC:CVE-DEEP-DIVE, Vulners:PublicExploit:GitHub:RECOFU:CVE-2026-31431-COPY-FAIL, Vulners:PublicExploit:GitHub:LEOXSOFT:CVE-2026-31431, Vulners:PublicExploit:GitHub:TREX1E:COPYFAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:ELEVENI386:CVE-2026-31431-GOLANG, Vulners:PublicExploit:GitHub:4XURA:CVE-2026-31431-COPY-FAIL, Vulners:PublicExploit:GitHub:GOVIND28:LINUX-COPY-FAIL-EXPLOIT, Vulners:PublicExploit:GitHub:BOLIU83:CVE-2026-31431-ALGIF-AEAD-REMEDIATOR, Vulners:PublicExploit:GitHub:JIMMYPUGHTRON:CVE-2026-31431-COPY-FAIL---MINIFIED-LPE-POC, Vulners:PublicExploit:GitHub:SNDAV:CVE-2026-31431-ADVANCED-EXPLOIT, Vulners:PublicExploit:GitHub:0XSHE:CVE-2026-31431, Vulners:PublicExploit:GitHub:ISW-9:COPY-FAIL-CVE-2026-31431-AARCH64, Vulners:PublicExploit:GitHub:TANGJIE1:CVE-2026-31431-CHECK, Vulners:PublicExploit:GitHub:MAXIME288:CVE-2026-31431-COPY-FAIL-R-PERTOIRE-DE-PR-VENTION, Vulners:PublicExploit:GitHub:PVPAULO01:CVE-2026-31431, Vulners:PublicExploit:GitHub:RIPPSEC:CVE-2026-31431-COPY-FAIL, Vulners:PublicExploit:GitHub:CALLUM-CAMERON26:CVE_2026_31431-TESTING-THE-COPY-FAIL-EXPLOIT, Vulners:PublicExploit:GitHub:SEANRICKERD:CVE-2026-31431, Vulners:PublicExploit:GitHub:MRHUDSON69:CVE-2026-31431, Vulners:PublicExploit:GitHub:COZYSTACK:COPY-FAIL-BLOCKER, Vulners:PublicExploit:GitHub:ADAMPIELAK:CVE-2026-31431_SCA_WAZUH, Vulners:PublicExploit:GitHub:HELIOS973:CVE-2026-31431_EXP.C, Vulners:PublicExploit:GitHub:MYVPS2024-COMMITS:CVE_2026_31431, Vulners:PublicExploit:GitHub:SERCURITYCYBER:COPY-FAIL-CVE-2026-31431, Vulners:PublicExploit:GitHub:SONGZZZZ:CVE-2026-31431, Vulners:PublicExploit:GitHub:2H-K:COPYFAILRECURRENCE, Vulners:PublicExploit:GitHub:HAYDENJAMES:DIRTY-FRAG-CHECK, Vulners:PublicExploit:GitHub:0XLANE:PAGECACHE-GUARD, Vulners:PublicExploit:GitHub:ROSNLR5:MITIGATIONTOOLKIT-ROSN-LR5-FULL, Vulners:PublicExploit:GitHub:G01D3NW01F:CVE-2026-31431, Vulners:PublicExploit:GitHub:LMAKONEM:DIRTYFRAG-LAB, Vulners:PublicExploit:GitHub:ADYSEC:CVE-2026-31431, Vulners:PublicExploit:GitHub:3JEE:COPY-FAIL-GO, Vulners:PublicExploit:GitHub:KALETH4:CVE-2026-31431, Vulners:PublicExploit:GitHub:VYAHELLO:CVE-2026-31431, Vulners:PublicExploit:GitHub:CRIHEXE:COPY-FAIL-TINY-ELF-CVE-2026-31431, Vulners:PublicExploit:GitHub:MHDGNING131:CVE-2026-31431_POC, Vulners:PublicExploit:GitHub:QENGINEERING:RK35XX-COPYFAIL-HOTFIX, Vulners:PublicExploit:GitHub:XELOXA:COPYFAIL-EXPLOIT, Vulners:PublicExploit:GitHub:WEBSECNL:CVE-2026-31431, Vulners:PublicExploit:GitHub:JNAMERZ:COPYFAIL-CVE-2026-31431, Vulners:PublicExploit:04A5C710-1476-5097-B582-5B8A2F56C25E, Vulners:PublicExploit:73BC1BD5-F47B-587F-8097-46A6928F2661, Vulners:PublicExploit:EDB-ID:52573, Vulners:PublicExploit:MSF:EXPLOIT-LINUX-LOCAL-CVE_2026_31431_COPY_FAIL-, BDU:PublicExploit websites
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.914The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile1.010EPSS Probability is 0.94545, EPSS Percentile is 0.99846

5. Elevation of Privilege - Linux Kernel (CVE-2026-43284) - Urgent [932]

Description: In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a private copy. The IPv4/IPv6 datagram append paths did not set this flag when splicing pages into UDP skbs. That leaves an ESP-in-UDP packet made from shared pipe pages looking like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW fast path for uncloned skbs without a frag_list and decrypts in place over data that is not owned privately by the skb. Mark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching TCP. Also make ESP input fall back to skb_cow_data() when the flag is present, so ESP does not decrypt externally backed frags in place. Private nonlinear skb frags still use the existing fast path. This intentionally does not change ESP output. In esp_output_head(), the path that appends the ESP trailer to existing skb tailroom without calling skb_cow_data() is not reachable for nonlinear skbs: skb_tailroom() returns zero when skb->data_len is nonzero, while ESP tailen is positive. Thus ESP output will either use the separate destination-frag path or fall back to skb_cow_data().

ComponentValueWeightComment
Exploited in the Wild1.018Exploitation in the wild is mentioned on Vulners (vulncheck_kev object) website
Exploit Exists1.017The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, Vulners:PublicExploit:GitHub:PORTBUSTER1337:LPE-TOOLKIT, Vulners:PublicExploit:GitHub:FIRST-JOHN:CVE-2026-43500, Vulners:PublicExploit:GitHub:K3YSTR0K3R:CVE-2026-43284-CVE-2026-43500-EXPLOIT, Vulners:PublicExploit:GitHub:XD20111:CVE-2026-43284, Vulners:PublicExploit:GitHub:ZEYUANGUO:DIRTYFRAG, Vulners:PublicExploit:GitHub:H4ZAZ:DIRTYFRAG-LINUX-KERNEL-LOCAL-PRIVILEGE-ESCALATION-EDUCATIONAL-MIRROR-, Vulners:PublicExploit:GitHub:MYM0US3R:DIRTY-FRAG-DETECTION-WITH-WAZUH-4.14.4, Vulners:PublicExploit:GitHub:ATLASVECTOR:DIRTY-FRAG-CVE-2026-43284, Vulners:PublicExploit:GitHub:MADEXPLOITS:CVE-2026-46300, Vulners:PublicExploit:GitHub:KARAZAJAC:DIRTYFAIL, Vulners:PublicExploit:GitHub:H0MI3E:CENTIPEDE, Vulners:PublicExploit:GitHub:FROSTERDL:CVE-2026-43284, Vulners:PublicExploit:GitHub:G0THAMRABB1T:DIRTYFRAG-CVE-2026-43284-AUDITD-DETECTION, Vulners:PublicExploit:GitHub:V4BEL:DIRTYFRAG, Vulners:PublicExploit:GitHub:WHOSFAULT:CVE-2026-43284, Vulners:PublicExploit:GitHub:JAYHUTAJULU1:CVE-2026-43284-DIRTYFRAG-POC, Vulners:PublicExploit:GitHub:1NEPTUNE:DIRTYFRAG, Vulners:PublicExploit:GitHub:LR1458644438:DIRTY-FRAG-ANALYSIS, Vulners:PublicExploit:GitHub:HAYDENJAMES:DIRTY-FRAG-CHECKER, Vulners:PublicExploit:GitHub:CYBER-NIZ:DIRTY-FRAG, Vulners:PublicExploit:GitHub:SUOMINEN:CVE-2026-43284, Vulners:PublicExploit:GitHub:LUCASPDINIZ:CVE-2026-43284, Vulners:PublicExploit:GitHub:SCRIPTZTEAM:PARANOID-DIRTY-FRAG-CVE-2026-43284, Vulners:PublicExploit:GitHub:PERCIVALLL:DIRTY-FRAG-KUBERNETES-POC, Vulners:PublicExploit:GitHub:LIAMROMANIS101:DIRTYFRAG-DETECTOR, Vulners:PublicExploit:GitHub:T1CKPRIVATE:CVE-2026-43284-DIRTY-FRAG, Vulners:PublicExploit:GitHub:METALX1993:DIRTYFRAG-PATCHES, Vulners:PublicExploit:GitHub:HAYDENJAMES:DIRTY-FRAG-CHECK, Vulners:PublicExploit:EDB-ID:52585, Vulners:PublicExploit:EDB-ID:52591, Vulners:PublicExploit:MSF:EXPLOIT-LINUX-LOCAL-CVE_2026_43284_DIRTY_FRAG-, BDU:PublicExploit, Dirty Frag: Universal Linux LPE websites
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.914The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile1.010EPSS Probability is 0.93235, EPSS Percentile is 0.99825

6. Elevation of Privilege - Linux Kernel (CVE-2026-43500) - Urgent [932]

Description: xfrm-ESP Page-Cache Write provides a powerful arbitrary 4-byte STORE primitive like Copy Fail, and is included on most distributions, but it requires the privilege to create a namespace. Ubuntu sometimes blocks unprivileged user namespace creation through AppArmor policy. In such an environment, xfrm-ESP Page-Cache Write cannot be triggered. RxRPC Page-Cache Write does not require the privilege to create a namespace, but the rxrpc.ko module itself is not included in most distributions. However, on Ubuntu, the rxrpc.ko module is loaded by default. Chaining the two variants makes the blind spots cover each other, allowing root privileges to be obtained on every major distribution. For details, refer to the technical details document.

ComponentValueWeightComment
Exploited in the Wild1.018Exploitation in the wild is mentioned on Vulners (vulncheck_kev object) website
Exploit Exists1.017The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:FIRST-JOHN:CVE-2026-43500, Vulners:PublicExploit:GitHub:K3YSTR0K3R:CVE-2026-43284-CVE-2026-43500-EXPLOIT, Vulners:PublicExploit:GitHub:ZEYUANGUO:DIRTYFRAG, Vulners:PublicExploit:GitHub:METALX1993:KERNEL-EXPLOIT-INTELLIGENCE, Vulners:PublicExploit:GitHub:H4ZAZ:DIRTYFRAG-LINUX-KERNEL-LOCAL-PRIVILEGE-ESCALATION-EDUCATIONAL-MIRROR-, Vulners:PublicExploit:GitHub:MYM0US3R:DIRTY-FRAG-DETECTION-WITH-WAZUH-4.14.4, Vulners:PublicExploit:GitHub:MADEXPLOITS:CVE-2026-46300, Vulners:PublicExploit:GitHub:KARAZAJAC:DIRTYFAIL, Vulners:PublicExploit:GitHub:H0MI3E:CENTIPEDE, Vulners:PublicExploit:GitHub:FROSTERDL:CVE-2026-43284, Vulners:PublicExploit:GitHub:V4BEL:DIRTYFRAG, Vulners:PublicExploit:GitHub:1NEPTUNE:DIRTYFRAG, Vulners:PublicExploit:GitHub:LR1458644438:DIRTY-FRAG-ANALYSIS, Vulners:PublicExploit:GitHub:HAYDENJAMES:DIRTY-FRAG-CHECKER, Vulners:PublicExploit:GitHub:LUCASPDINIZ:CVE-2026-43284, Vulners:PublicExploit:GitHub:LIAMROMANIS101:DIRTYFRAG-DETECTOR, Vulners:PublicExploit:GitHub:METALX1993:DIRTYFRAG-PATCHES, Vulners:PublicExploit:GitHub:HAYDENJAMES:DIRTY-FRAG-CHECK, Vulners:PublicExploit:EDB-ID:52585, Vulners:PublicExploit:EDB-ID:52591, Vulners:PublicExploit:MSF:EXPLOIT-LINUX-LOCAL-CVE_2026_43500_DIRTY_FRAG-, BDU:PublicExploit, Dirty Frag: Universal Linux LPE websites
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.914The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel
CVSS Base Score0.810CVSS Base Score is 7.8. According to NVD data source
EPSS Percentile1.010EPSS Probability is 0.92855, EPSS Percentile is 0.9982

7. Remote Code Execution - Apache ActiveMQ (CVE-2026-34197) - Urgent [921]

Description: Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. Because Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec(). This issue affects Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ All: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.3. Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue

ComponentValueWeightComment
Exploited in the Wild1.018Exploitation in the wild is mentioned on Vulners (AttackerKB object, CISA object, cisa_kev object, vulncheck_kev object), AttackerKB, NVD:CISAKEV websites
Exploit Exists1.017The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:ASDASDDQWDQ29-A11Y:CVE-2026-34197, Vulners:PublicExploit:GitHub:HNYTGL:CVE-2026-34197, Vulners:PublicExploit:GitHub:ROOTDIRECTIVE-SEC:CVE-2026-34197-LAB, Vulners:PublicExploit:GitHub:K3YSTR0K3R:CVE-2026-34197, Vulners:PublicExploit:GitHub:DEVSECURITYSPRO:CVE-2026-34197, Vulners:PublicExploit:GitHub:KERAATTIN:CVE-2026-34197, Vulners:PublicExploit:GitHub:DINOSN:APACHE-ACTIVEMQ-RCE-RESEARCH, Vulners:PublicExploit:GitHub:ATOPOSX-J:CVE-2026-34197-APACHE-ACTIVEMQ-RCE, Vulners:PublicExploit:GitHub:LAT-06:CVE-2026-34197, Vulners:PublicExploit:GitHub:DINOSN:CVE-2026-34197, Vulners:PublicExploit:GitHub:HG0434HONGZH0:CVE-2026-34197, Vulners:PublicExploit:MSF:EXPLOIT-MULTI-HTTP-APACHE_ACTIVEMQ_JOLOKIA_RCE-, Vulners:PublicExploit:PACKETSTORM:222271, Vulners:PublicExploit:PACKETSTORM:222315, BDU:PublicExploit websites
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.614Apache ActiveMQ is an open source message broker written in Java together with a full Java Message Service (JMS) client
CVSS Base Score0.910CVSS Base Score is 8.8. According to NVD data source
EPSS Percentile1.010EPSS Probability is 0.9722, EPSS Percentile is 0.99888

8. Remote Code Execution - PAN-OS (CVE-2026-0300) - Urgent [916]

Description: A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.

ComponentValueWeightComment
Exploited in the Wild1.018Exploitation in the wild is mentioned on Vulners (CISA object, cisa_kev object, vulncheck_kev object), AttackerKB, NVD:CISAKEV websites
Exploit Exists1.017The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:BANNNED-BIT:CVE-2026-0300-PANOS, Vulners:PublicExploit:GitHub:RIDHINVA:CVE-2026-0300-PANOS-RCE, Vulners:PublicExploit:GitHub:MR-R3B00T:CVE-2026-0300, Vulners:PublicExploit:GitHub:BYTEWRAITH1:CVE-2026-0300, Vulners:PublicExploit:GitHub:LU4M575:CVE-2026-0300, Vulners:PublicExploit:GitHub:SHIZUKU198411:CVE-2026-0300, BDU:PublicExploit websites
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.514PAN-OS is the software that runs all Palo Alto Networks next-generation firewalls
CVSS Base Score1.010CVSS Base Score is 9.8. According to NVD data source
EPSS Percentile1.010EPSS Probability is 0.32074, EPSS Percentile is 0.9814

9. Elevation of Privilege - Microsoft Defender (CVE-2026-41091) - Urgent [904]

Description: Microsoft Defender Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild1.018Exploitation in the wild is mentioned on Vulners (AttackerKB object, CISA object, cisa_kev object, vulncheck_kev object), AttackerKB, Microsoft, NVD:CISAKEV websites
Exploit Exists1.017The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:0XBLACKASH:CVE-2026-41091, Vulners:PublicExploit:GitHub:RIDHINVA:DEFENDER-VULNERABILITY-SCANNER, BDU:PublicExploit websites
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Anti-malware component of Microsoft Windows
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.910EPSS Probability is 0.09641, EPSS Percentile is 0.94993

10. Information Disclosure - Microsoft Desktop Window Manager (CVE-2026-20805) - Urgent [901]

Description: Desktop Window Manager Information Disclosure Vulnerability

ComponentValueWeightComment
Exploited in the Wild1.018Exploitation in the wild is mentioned on Vulners (AttackerKB object, CISA object, cisa_kev object, vulncheck_kev object), AttackerKB, Microsoft, NVD:CISAKEV websites
Exploit Exists1.017The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:SIMOESCTT:-SCTT-2026-33-0002-DWM-VISUAL-FIELD-SINGULARITY, Vulners:PublicExploit:GitHub:FEVAR54:CVE-2026-20805-POC, Vulners:PublicExploit:GitHub:UZAIR-BAIG0900:CVE-2026-20805-POC, Vulners:PublicExploit:GitHub:SIMOESCTT:CTT-MEMORY-VORTEX-20805, Vulners:PublicExploit:GitHub:SIMOESCTT:SCTT-2026-33-0002-DWM-VISUAL-FIELD-SINGULARITY, BDU:PublicExploit websites
Criticality of Vulnerability Type0.8315Information Disclosure
Vulnerable Product is Common0.9514Desktop Window Manager (DWM) is a core component of Microsoft Windows responsible for compositing and rendering the graphical user interface, including window effects, transparency, and desktop composition.
CVSS Base Score0.610CVSS Base Score is 5.5. According to Microsoft data source
EPSS Percentile0.910EPSS Probability is 0.05028, EPSS Percentile is 0.914

11. Cross Site Scripting - Microsoft Exchange (CVE-2026-42897) - Urgent [895]

Description: {'ms_cve_data_all': 'Microsoft Exchange Server Spoofing Vulnerability', 'nvd_cve_data_all': 'Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}

ComponentValueWeightComment
Exploited in the Wild1.018Exploitation in the wild is mentioned on Vulners (AttackerKB object, CISA object, cisa_kev object, vulncheck_kev object), AttackerKB, Microsoft, NVD:CISAKEV websites
Exploit Exists1.017The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:ATIILLA:CVE-2026-42897, BDU:PublicExploit websites
Criticality of Vulnerability Type0.815Cross Site Scripting
Vulnerable Product is Common0.814Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft
CVSS Base Score0.810CVSS Base Score is 8.1. According to Microsoft data source
EPSS Percentile0.910EPSS Probability is 0.0564, EPSS Percentile is 0.9217

12. Remote Code Execution - Microsoft SharePoint (CVE-2026-20963) - Urgent [848]

Description: Microsoft SharePoint Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild1.018Exploitation in the wild is mentioned on Vulners (CISA object, cisa_kev object, vulncheck_kev object), AttackerKB, NVD:CISAKEV websites
Exploit Exists0.517The existence of a private exploit is mentioned on BDU:PrivateExploit website
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.714Microsoft SharePoint
CVSS Base Score1.010CVSS Base Score is 9.8. According to Microsoft data source
EPSS Percentile1.010EPSS Probability is 0.29459, EPSS Percentile is 0.97992

13. Elevation of Privilege - Microsoft Desktop Window Manager (CVE-2026-21519) - Urgent [816]

Description: Desktop Window Manager Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild1.018Exploitation in the wild is mentioned on Vulners (AttackerKB object, CISA object, cisa_kev object, vulncheck_kev object), AttackerKB, Microsoft, NVD:CISAKEV websites
Exploit Exists0.517The existence of a private exploit is mentioned on BDU:PrivateExploit website
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.9514Desktop Window Manager (DWM) is a core component of Microsoft Windows responsible for compositing and rendering the graphical user interface, including window effects, transparency, and desktop composition.
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.810EPSS Probability is 0.0242, EPSS Percentile is 0.82512

14. Elevation of Privilege - Windows Remote Desktop Services (CVE-2026-21533) - Urgent [802]

Description: Windows Remote Desktop Services Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild1.018Exploitation in the wild is mentioned on Vulners (AttackerKB object, CISA object, cisa_kev object, vulncheck_kev object), AttackerKB, Microsoft, NVD:CISAKEV websites
Exploit Exists0.517The existence of a private exploits is mentioned on Microsoft:PrivateExploit:Functional, BDU:PrivateExploit websites
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Remote Desktop Services, known as Terminal Services in Windows Server 2008 and earlier, is one of the components of Microsoft Windows that allow a user to initiate and control an interactive session on a remote computer or virtual machine over a network connection
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.910EPSS Probability is 0.03846, EPSS Percentile is 0.89067

Critical (3)

15. Spoofing - Microsoft SharePoint Server (CVE-2026-32201) - Critical [773]

Description: Microsoft SharePoint Server Spoofing Vulnerability

ComponentValueWeightComment
Exploited in the Wild1.018Exploitation in the wild is mentioned on Vulners (CISA object, cisa_kev object, vulncheck_kev object), AttackerKB, Microsoft, NVD:CISAKEV websites
Exploit Exists1.017The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:B1TBIT:CVE-2026-32201-EXPLOIT website
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.514Microsoft SharePoint Server
CVSS Base Score0.710CVSS Base Score is 6.5. According to Microsoft data source
EPSS Percentile1.010EPSS Probability is 0.21476, EPSS Percentile is 0.97365

16. Remote Code Execution - Microsoft Word (CVE-2026-21514) - Critical [772]

Description: {'ms_cve_data_all': 'Microsoft Word Security Feature Bypass Vulnerability', 'nvd_cve_data_all': 'Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}

ComponentValueWeightComment
Exploited in the Wild1.018Exploitation in the wild is mentioned on Vulners (AttackerKB object, CISA object, cisa_kev object, vulncheck_kev object), AttackerKB, Microsoft, NVD:CISAKEV websites
Exploit Exists0.517The existence of a private exploits is mentioned on Microsoft:PrivateExploit:Functional, BDU:PrivateExploit websites
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.614Microsoft Word is a widely used commercial word processor developed by Microsoft. It is a component of the Microsoft Office suite of productivity software but can also be purchased as a standalone product.
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.710EPSS Probability is 0.01517, EPSS Percentile is 0.72005

17. Elevation of Privilege - Linux Kernel (CVE-2026-46300) - Critical [706]

Description: In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to. If @from has SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same externally-owned or page-cache-backed frags, but the shared-frag marker is currently lost. That breaks the invariant relied on by later in-place writers. In particular, ESP input checks skb_has_shared_frag() before deciding whether an uncloned nonlinear skb can skip skb_cow_data(). If TCP receive coalescing has moved shared frags into an unmarked skb, ESP can see skb_has_shared_frag() as false and decrypt in place over page-cache backed frags. Propagate SKBFL_SHARED_FRAG when skb_try_coalesce() transfers paged frags. The tailroom copy path does not need the marker because it copies bytes into @to's linear data rather than transferring frag descriptors.

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists1.017The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:MADEXPLOITS:CVE-2026-46300, Vulners:PublicExploit:GitHub:1NEPTUNE:FRAGNESIA, Vulners:PublicExploit:GitHub:MAXIME288:FRAGNESIA-CVE-2026-46300, Vulners:PublicExploit:GitHub:AZDEVOPS143:FRAGNESIA-CHARAN-CVE-2026-46300, Vulners:PublicExploit:GitHub:AZILRABABE:CVE-2026-46300, Vulners:PublicExploit:GitHub:SENTEBALE:CVE-2026-46300, Vulners:PublicExploit:GitHub:0XDEADROOT:FRAGNESIA-PYTHON-EXPLOIT, Vulners:PublicExploit:GitHub:EXPLOITEOOM:CVE-2026-46300, Vulners:PublicExploit:GitHub:HORKIMHAB:CVE-2026-46300, Vulners:PublicExploit:GitHub:AZDEVOPS143:FRAGNESIA-CVE-2026-46300, Vulners:PublicExploit:EDB-ID:52591, BDU:PublicExploit websites
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.914The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.910EPSS Probability is 0.07006, EPSS Percentile is 0.93505

High (0)

Medium (0)

Low (0)

Exploitation in the wild detected (16)

Remote Code Execution (7)

Elevation of Privilege (6)

Information Disclosure (1)

Cross Site Scripting (1)

Spoofing (1)

Public exploit exists, but exploitation in the wild is NOT detected (1)

Elevation of Privilege (1)

Other Vulnerabilities (0)