CVE-2025-59612
Memory corruption in windows drivers while sending incorrect trusted application request
CVSS
6.7
Medium
EPSS
0.1%
p0
KEV
—
Exploit Today
0
0-100
Published: Jun 1, 2026 · Last modified: Jul 22, 2026 · CWE-121
0.1%EPSS · 30 days0.1%
2026-08-192026-09-17
Memory corruption in windows drivers while sending incorrect trusted application request
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-908239.8 CRI—
——0FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based buffer overflow in /usr/sbin/auth_user_pass. An unauthenticated remote attacker with access to the affected management interface can submit a crafted authentication request that reaches an unchecked copy into a fixed-size stack buffer, potentially allowing arbitrary code execution as root.
The affected management interface is disabled by default and must be affirmatively enabled by the customer before the endpoint becomes reachable. FatPipe recommends restricting management access to trusted administrative networks and using WAN access control lists to limit access to trusted sources.11hCVE-2026-814807.2 HIG—
——0Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Stack-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.11hCVE-2026-252838.8 HIG1.4%
——0Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.18hCVE-2026-815467.7 HIG1.4%
——0The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based buffer overflow. A threat actor could craft a Affinity document that when opened by a user in Affinity could result in arbitrary code execution.21hCVE-2026-863586.5 MED22.3%
——7Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote execution.11hCVE-2026-918439.8 CRI41.7%
——13A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.11h