CVE & CISA-KEV Catalog
| Severity | Description | ||||||
|---|---|---|---|---|---|---|---|
| CVE-2026-20135 | High | 8.6 v3 | - | - | -No fix available yet | 2026-09-16 | A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper buffer management during the TLS 1.3 connection. An attacker could exploit this vulnerability by sending a crafted TLS 1.3 packet to an affected system through a TLS 1.3-enabled listening socket. A successful exploit could allow the attacker to cause the LINA process to crash, which would cause the device to reload. The reload can happen before or after authentication of the connection.Note: TLS 1.3 connections include both data traffic and user-management traffic. |
| CVE-2026-84561 | Critical | 9.8 v3 | 0.2% | - | Fix available | 2026-09-14 | A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory. |
| CVE-2026-84558 | Medium | 5.5 v3 | 0.1% | - | Fix available | 2026-09-14 | A double free issue was addressed with improved memory management. This issue is fixed in macOS Golden Gate 27. An app may be able to cause unexpected system termination. |
| CVE-2026-87585 | High | 8.8 v3 | 0.3% | - | Fix available | 2026-09-14 | This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. |
| CVE-2026-85921 | Critical | 8.2 v3 | 0.3% | - | Fix available | 2026-09-14 | Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. |
| CVE-2026-23790 | Medium | 4.2 v3 | 0.1% | - | -No fix available yet | 2026-09-14 | An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A double-free vulnerability in the Samsung Exynos DPU driver (due to improper pointer management during DMA buffer reallocation) leads to kernel memory corruption and a potential use-after-free. |
| CVE-2026-23789 | High | 7.8 v3 | 0.1% | - | -No fix available yet | 2026-09-14 | An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC encoder driver (due to improper cleanup of dma_buf references during error handling) leads to kernel memory corruption and potential arbitrary code execution. |
| CVE-2026-57842 | High | 7.0 v3 | 0.1% | - | -No fix available yet | 2026-09-11 | NetBSD contains a use-after-free and double-free vulnerability in msg_recv_copyin() within the COMPAT_NETBSD32 compatibility layer due to a missing return statement before the cleanup label on the success path. Any local user able to execute a 32-bit binary on a 64-bit NetBSD system can trigger a kernel panic or memory corruption by calling recvmsg() with msg_iovlen between 9 and IOV_MAX, causing the kernel to access a freed iovec buffer and subsequently free the same allocation a second time. |
| CVE-2026-80080 | High | 8.8 v3 | 0.6% | - | Fix available | 2026-09-11 | Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network. |
| CVE-2026-61915 | Medium | 4.2 v3 | 0.2% | - | Fix available | 2026-09-09 | An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two or more properties of the matched kind. The memory holding the selector would be freed once on each iteration over the properties. |
| CVE-2026-33630 | High | 7.5 v3 | 0.5% | - | Fix available | 2026-09-09 | c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The same flaw — a query's callback being invoked while the query is still linked in the channel's internal lookup structures — is present at multiple points in the resend/finish path (timeout handling, response handling, and query dispatch). If the query, or for ares_getaddrinfo() the owning host_query, is freed as a side effect of that callback, it is then accessed and/or freed a second time. This vulnerability is fixed in ver 1.34.7. |
| CVE-2026-79907 | High | 7.8 v3 | 0.2% | - | Fix available | 2026-09-08 | Acrobat Reader is affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
| CVE-2026-81950 | Critical | 7.8 v3 | 0.4% | - | Fix available | 2026-09-08 | Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-77504 | Critical | 8.8 v3 | 0.6% | - | Fix available | 2026-09-08 | Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network. |
| CVE-2026-77493 | Critical | 9.8 v3 | 1.0% | - | Fix available | 2026-09-08 | Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. |
| CVE-2026-72958 | Critical | 8.2 v3 | 0.3% | - | Fix available | 2026-09-08 | Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally. |
| CVE-2026-71353 | High | 7.0 v3 | 0.2% | - | Fix available | 2026-09-08 | Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. |
| CVE-2026-71351 | High | 7.0 v3 | 0.3% | - | Fix available | 2026-09-08 | Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. |
| CVE-2026-71338 | High | 6.4 v3 | 0.3% | - | Fix available | 2026-09-08 | Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally. |
| CVE-2026-70567 | High | 7.0 v3 | 0.3% | - | Fix available | 2026-09-08 | Double free in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-70562 | High | 7.0 v3 | 0.3% | - | Fix available | 2026-09-08 | Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-69876 | High | 8.0 v3 | 0.6% | - | Fix available | 2026-09-08 | Use after free in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network. |
| CVE-2026-69725 | Critical | 7.8 v3 | 0.3% | - | Fix available | 2026-09-08 | Double free in Windows Hello allows an authorized attacker to elevate privileges locally. |
| CVE-2026-69398 | High | 7.0 v3 | 0.2% | - | Fix available | 2026-09-08 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-69337 | High | 7.1 v3 | 0.7% | - | Fix available | 2026-09-08 | Double free in Windows Registry allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-69322 | High | 8.0 v3 | 0.7% | - | Fix available | 2026-09-08 | Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-69309 | High | 7.0 v3 | 0.3% | - | Fix available | 2026-09-08 | Double free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. |
| CVE-2026-69292 | High | 7.0 v3 | 0.2% | - | Fix available | 2026-09-08 | Double free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-55007 | High | 8.1 v3 | 0.7% | - | Fix available | 2026-09-08 | Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. |
| CVE-2026-82325 | Medium | 6.8 v4 | 0.1% | - | -No fix available yet | 2026-09-07 | A use-after-free vulnerability in the OpenVPN ovpn-dco-win driver version 2.5.0 through 2.8.6 allows local authenticated users to cause a system crash via crafted control messages |
| CVE-2026-20510 | Medium | 6.7 v3 | 0.1% | - | -No fix available yet | 2026-09-07 | In camera middleware, there is a possible escalation of privilege due to double free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11134622; Issue ID: MSV-8894. |
| CVE-2026-84964 | Medium | 5.9 v3 | 0.1% | - | Fix available | 2026-09-03 | A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During the handshake, specially formed certificate data can cause the same heap object to be released twice. An unauthenticated party acting as the trusted endpoint may cause the connecting client application to terminate unexpectedly. |
| CVE-2026-52023 | High | 7.5 v3 | 0.3% | - | Fix available | 2026-09-01 | An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_pending path and security-agreement parsing in sec_agree.c:parse_sec_agree() |
| CVE-2026-82677 | Low | 2.4 v3 | 0.3% | - | Fix available | 2026-08-31 | A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/module.c of the component Module Timer Subsystem. This manipulation causes double free. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: b349fe2821e3998534b1454c1b64a478daf8c6b7. To fix this issue, it is recommended to deploy a patch. |
| CVE-2026-19316 | High | 8.7 v4 | 0.3% | - | -No fix available yet | 2026-08-28 | A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. |
| CVE-2026-75159 | Medium | 5.9 v3 | 0.3% | - | -No fix available yet | 2026-08-27 | An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication may cause mongosqld to terminate when a crafted authentication exchange encounters a specific GSSAPI error-handling condition. This can interrupt BI Connector availability until the process restarts. |
| CVE-2026-18798 | High | 7.5 v3 | 1.5% | - | Fix available | 2026-08-25 | Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC server process, leading to Denial of Service. There is so far no evidence that this double free is exploitable for remote code execution, thus it is considered highly improbable. CWE: CWE-415: Double Free Description: In order to validate initial packet, OpenSSL QUIC stack default packet handler (port_default_packet_handler()) creates a so-called QRX object. If the initial packet validates successfully with QRX object, the default packet handler proceeds to channel (connection object) creation. The QRX object used for packet validation is passed to port_bind_chann |
| CVE-2026-47895 | High | 7.5 v3 | 0.7% | - | Fix available | 2026-08-24 | In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed. |
| CVE-2026-45202 | Medium | 5.5 v3 | 0.1% | - | -No fix available yet | 2026-08-21 | Software installed and run as a non-privileged user may conduct GPU system calls which cause GPU memory leaks and possible kernel heap corruption. Scenario caused by memory free paths not maintaining state data of upgraded higher order allocations. This could cause memory leak or double free event. |
| CVE-2026-63652 | High | 7.1 v4 | 0.3% | - | Fix available | 2026-08-19 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without clearing the owning pointer or num_client_formats. An authenticated RDP client can trigger an error such as a cbSize larger than the remaining record, leave the dangling pointer in the server context, and cause rdpsnd_server_context_free to free the same allocation again at session teardown. This reliably terminates the server and can create allocator-dependent heap corruption. This issue is fixed in version 3.28.0. |
| CVE-2026-18663 | Medium | 5.9 v3 | 0.4% | - | Fix available | 2026-08-12 | A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Session Tracking critical-control rejection path without clearing the SLAPI_REQCONTROLS pblock slot. Operation teardown then frees the same pointer again, causing a double-free. An unauthenticated remote attacker can trigger this with a single BIND request carrying a critical Session Tracking control, resulting in heap corruption and potential denial of service. |
| CVE-2026-65780 | High | 7.0 v3 | 0.2% | - | Fix available | 2026-08-11 | Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally. |
| CVE-2026-62889 | Critical | 8.1 v3 | 0.6% | - | Fix available | 2026-08-11 | Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. |
| CVE-2026-62766 | High | 7.0 v3 | 1.5% | - | Fix available | 2026-08-11 | Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally. |
| CVE-2026-61366 | High | 7.0 v3 | 0.2% | - | Fix available | 2026-08-11 | Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. |
| CVE-2026-11894 | Medium | 5.9 v3 | 0.2% | - | -No fix available yet | 2026-08-11 | The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the bt_hci_driver_api buffer-ownership contract. That contract requires the driver to consume (unref) the transmit net_buf only on success; on an error return the host caller retains ownership and unrefs the buffer itself. The pre-fix code routed all error paths through a shared cleanup label that unconditionally called net_buf_unref(buf) before returning the error code. Because the host TX paths (in subsys/bluetooth/host/hci_core.c) unref the buffer again after send() returns an error, the buffer is freed twice: the driver returns it to its net_buf pool and the host then unrefs the already-freed buffer, corrupting the shared pool / underflowing the reference count (CWE-415 |
| CVE-2026-11893 | Medium | 5.9 v3 | 0.2% | - | -No fix available yet | 2026-08-11 | The Bluetooth HCI driver for Bouffalo Lab on-chip BLE controllers (BL60x/BL70x/BL61x), bt_bflb_send() in drivers/bluetooth/hci/hci_bflb.c, violates the bt_hci_driver_api.send() buffer-ownership contract. That contract (documented at include/zephyr/drivers/bluetooth.h) requires the buffer reference to be consumed only on success; on error the caller still owns the reference and unrefs it. The driver instead routed all error paths through a shared label that unconditionally called net_buf_unref(buf) before returning the error code, consuming the buffer on failure as well. When send() returns an error, the host TX path (send_buf() in subsys/bluetooth/host/conn.c) unrefs the same buffer again, believing it still owns it. This double-unref over-decrements the net_buf reference count. Because t |
| CVE-2026-20338 | High | 7.5 v3 | 0.5% | - | -No fix available yet | 2026-08-11 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate as a result of a memory double-free, resulting in a DoS condition on the affected software. |
| CVE-2026-66032 | High | 8.8 v3 | 0.4% | - | Fix available | 2026-08-07 | libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites. |
| CVE-2026-55995 | High | 8.7 v4 | 0.3% | - | Fix available | 2026-08-07 | A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb. |
- HighCVSS 8.6 v3·EPSS -·No fix yet
A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper buffer management during the TLS 1.3 connection. An attacker could exploit this vulnerability by sending a crafted TLS 1.3 packet to an affected system through a TLS 1.3-enabled listening socket. A successful exploit could allow the attacker to cause the LINA process to crash, which would cause the device to reload. The reload can happen before or after authentication of the connection.Note: TLS 1.3 connections include both data traffic and user-management traffic.
Published 2026-09-16
- CriticalCVSS 9.8 v3·EPSS 0.2%·Fix available
A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory.
Published 2026-09-14
- MediumCVSS 5.5 v3·EPSS 0.1%·Fix available
A double free issue was addressed with improved memory management. This issue is fixed in macOS Golden Gate 27. An app may be able to cause unexpected system termination.
Published 2026-09-14
- HighCVSS 8.8 v3·EPSS 0.3%·Fix available
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Published 2026-09-14
- CriticalCVSS 8.2 v3·EPSS 0.3%·Fix available
Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
Published 2026-09-14
- MediumCVSS 4.2 v3·EPSS 0.1%·No fix yet
An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A double-free vulnerability in the Samsung Exynos DPU driver (due to improper pointer management during DMA buffer reallocation) leads to kernel memory corruption and a potential use-after-free.
Published 2026-09-14
- HighCVSS 7.8 v3·EPSS 0.1%·No fix yet
An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC encoder driver (due to improper cleanup of dma_buf references during error handling) leads to kernel memory corruption and potential arbitrary code execution.
Published 2026-09-14
- HighCVSS 7.0 v3·EPSS 0.1%·No fix yet
NetBSD contains a use-after-free and double-free vulnerability in msg_recv_copyin() within the COMPAT_NETBSD32 compatibility layer due to a missing return statement before the cleanup label on the success path. Any local user able to execute a 32-bit binary on a 64-bit NetBSD system can trigger a kernel panic or memory corruption by calling recvmsg() with msg_iovlen between 9 and IOV_MAX, causing the kernel to access a freed iovec buffer and subsequently free the same allocation a second time.
Published 2026-09-11
- HighCVSS 8.8 v3·EPSS 0.6%·Fix available
Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Published 2026-09-11
- MediumCVSS 4.2 v3·EPSS 0.2%·Fix available
An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two or more properties of the matched kind. The memory holding the selector would be freed once on each iteration over the properties.
Published 2026-09-09
- HighCVSS 7.5 v3·EPSS 0.5%·Fix available
c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The same flaw — a query's callback being invoked while the query is still linked in the channel's internal lookup structures — is present at multiple points in the resend/finish path (timeout handling, response handling, and query dispatch). If the query, or for ares_getaddrinfo() the owning host_query, is freed as a side effect of that callback, it is then accessed and/or freed a second time. This vulnerability is fixed in ver 1.34.7.
Published 2026-09-09
- HighCVSS 7.8 v3·EPSS 0.2%·Fix available
Acrobat Reader is affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published 2026-09-08
- CriticalCVSS 7.8 v3·EPSS 0.4%·Fix available
Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Published 2026-09-08
- CriticalCVSS 8.8 v3·EPSS 0.6%·Fix available
Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Published 2026-09-08
- CriticalCVSS 9.8 v3·EPSS 1.0%·Fix available
Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
Published 2026-09-08
- CriticalCVSS 8.2 v3·EPSS 0.3%·Fix available
Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally.
Published 2026-09-08
- HighCVSS 7.0 v3·EPSS 0.2%·Fix available
Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
Published 2026-09-08
- HighCVSS 7.0 v3·EPSS 0.3%·Fix available
Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
Published 2026-09-08
- HighCVSS 6.4 v3·EPSS 0.3%·Fix available
Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally.
Published 2026-09-08
- HighCVSS 7.0 v3·EPSS 0.3%·Fix available
Double free in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.
Published 2026-09-08
- HighCVSS 7.0 v3·EPSS 0.3%·Fix available
Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally.
Published 2026-09-08
- HighCVSS 8.0 v3·EPSS 0.6%·Fix available
Use after free in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.
Published 2026-09-08
- CriticalCVSS 7.8 v3·EPSS 0.3%·Fix available
Double free in Windows Hello allows an authorized attacker to elevate privileges locally.
Published 2026-09-08
- HighCVSS 7.0 v3·EPSS 0.2%·Fix available
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
Published 2026-09-08
- HighCVSS 7.1 v3·EPSS 0.7%·Fix available
Double free in Windows Registry allows an authorized attacker to elevate privileges over a network.
Published 2026-09-08
- HighCVSS 8.0 v3·EPSS 0.7%·Fix available
Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.
Published 2026-09-08
- HighCVSS 7.0 v3·EPSS 0.3%·Fix available
Double free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
Published 2026-09-08
- HighCVSS 7.0 v3·EPSS 0.2%·Fix available
Double free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges locally.
Published 2026-09-08
- HighCVSS 8.1 v3·EPSS 0.7%·Fix available
Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
Published 2026-09-08
- MediumCVSS 6.8 v4·EPSS 0.1%·No fix yet
A use-after-free vulnerability in the OpenVPN ovpn-dco-win driver version 2.5.0 through 2.8.6 allows local authenticated users to cause a system crash via crafted control messages
Published 2026-09-07
- MediumCVSS 6.7 v3·EPSS 0.1%·No fix yet
In camera middleware, there is a possible escalation of privilege due to double free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11134622; Issue ID: MSV-8894.
Published 2026-09-07
- MediumCVSS 5.9 v3·EPSS 0.1%·Fix available
A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During the handshake, specially formed certificate data can cause the same heap object to be released twice. An unauthenticated party acting as the trusted endpoint may cause the connecting client application to terminate unexpectedly.
Published 2026-09-03
- HighCVSS 7.5 v3·EPSS 0.3%·Fix available
An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_pending path and security-agreement parsing in sec_agree.c:parse_sec_agree()
Published 2026-09-01
- CVSS 2.4 v3·EPSS 0.3%·Fix available
A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/module.c of the component Module Timer Subsystem. This manipulation causes double free. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: b349fe2821e3998534b1454c1b64a478daf8c6b7. To fix this issue, it is recommended to deploy a patch.
Published 2026-08-31
- HighCVSS 8.7 v4·EPSS 0.3%·No fix yet
A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
Published 2026-08-28
- MediumCVSS 5.9 v3·EPSS 0.3%·No fix yet
An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication may cause mongosqld to terminate when a crafted authentication exchange encounters a specific GSSAPI error-handling condition. This can interrupt BI Connector availability until the process restarts.
Published 2026-08-27
- HighCVSS 7.5 v3·EPSS 1.5%·Fix available
Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC server process, leading to Denial of Service. There is so far no evidence that this double free is exploitable for remote code execution, thus it is considered highly improbable. CWE: CWE-415: Double Free Description: In order to validate initial packet, OpenSSL QUIC stack default packet handler (port_default_packet_handler()) creates a so-called QRX object. If the initial packet validates successfully with QRX object, the default packet handler proceeds to channel (connection object) creation. The QRX object used for packet validation is passed to port_bind_chann
Published 2026-08-25
- HighCVSS 7.5 v3·EPSS 0.7%·Fix available
In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.
Published 2026-08-24
- MediumCVSS 5.5 v3·EPSS 0.1%·No fix yet
Software installed and run as a non-privileged user may conduct GPU system calls which cause GPU memory leaks and possible kernel heap corruption. Scenario caused by memory free paths not maintaining state data of upgraded higher order allocations. This could cause memory leak or double free event.
Published 2026-08-21
- HighCVSS 7.1 v4·EPSS 0.3%·Fix available
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without clearing the owning pointer or num_client_formats. An authenticated RDP client can trigger an error such as a cbSize larger than the remaining record, leave the dangling pointer in the server context, and cause rdpsnd_server_context_free to free the same allocation again at session teardown. This reliably terminates the server and can create allocator-dependent heap corruption. This issue is fixed in version 3.28.0.
Published 2026-08-19
- MediumCVSS 5.9 v3·EPSS 0.4%·Fix available
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Session Tracking critical-control rejection path without clearing the SLAPI_REQCONTROLS pblock slot. Operation teardown then frees the same pointer again, causing a double-free. An unauthenticated remote attacker can trigger this with a single BIND request carrying a critical Session Tracking control, resulting in heap corruption and potential denial of service.
Published 2026-08-12
- HighCVSS 7.0 v3·EPSS 0.2%·Fix available
Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Published 2026-08-11
- CriticalCVSS 8.1 v3·EPSS 0.6%·Fix available
Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
Published 2026-08-11
- HighCVSS 7.0 v3·EPSS 1.5%·Fix available
Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally.
Published 2026-08-11
- HighCVSS 7.0 v3·EPSS 0.2%·Fix available
Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.
Published 2026-08-11
- MediumCVSS 5.9 v3·EPSS 0.2%·No fix yet
The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the bt_hci_driver_api buffer-ownership contract. That contract requires the driver to consume (unref) the transmit net_buf only on success; on an error return the host caller retains ownership and unrefs the buffer itself. The pre-fix code routed all error paths through a shared cleanup label that unconditionally called net_buf_unref(buf) before returning the error code. Because the host TX paths (in subsys/bluetooth/host/hci_core.c) unref the buffer again after send() returns an error, the buffer is freed twice: the driver returns it to its net_buf pool and the host then unrefs the already-freed buffer, corrupting the shared pool / underflowing the reference count (CWE-415
Published 2026-08-11
- MediumCVSS 5.9 v3·EPSS 0.2%·No fix yet
The Bluetooth HCI driver for Bouffalo Lab on-chip BLE controllers (BL60x/BL70x/BL61x), bt_bflb_send() in drivers/bluetooth/hci/hci_bflb.c, violates the bt_hci_driver_api.send() buffer-ownership contract. That contract (documented at include/zephyr/drivers/bluetooth.h) requires the buffer reference to be consumed only on success; on error the caller still owns the reference and unrefs it. The driver instead routed all error paths through a shared label that unconditionally called net_buf_unref(buf) before returning the error code, consuming the buffer on failure as well. When send() returns an error, the host TX path (send_buf() in subsys/bluetooth/host/conn.c) unrefs the same buffer again, believing it still owns it. This double-unref over-decrements the net_buf reference count. Because t
Published 2026-08-11
- HighCVSS 7.5 v3·EPSS 0.5%·No fix yet
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate as a result of a memory double-free, resulting in a DoS condition on the affected software.
Published 2026-08-11
- HighCVSS 8.8 v3·EPSS 0.4%·Fix available
libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites.
Published 2026-08-07
- HighCVSS 8.7 v4·EPSS 0.3%·Fix available
A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.
Published 2026-08-07
Free CVE lookup by TridentStack Control, automated patching for Windows, macOS, and Linux fleets. Learn more·Uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog.