PULSE
FEED
ransompanzer reclama a Asesoría FAR · Professional Servicesransompanzer reclama a Ressources Si · FR · Professional Servicesransomstorm reclama a First Secure Bank Group · US · Financial Servicesransomqilin reclama a XICO · MX · Not Foundransomqilin reclama a Island · CA · Technologyransomqilin reclama a Revenga Smart Solutions · ES · Technologyransomqilin reclama a Willatt & Flickinger · US · Not Foundransomarcusmedia reclama a Pantaneiro Capas · BR · Manufacturingransomemperador reclama a Car Service Abschlepp · DE · TransportationvulnKEV agrega CVE-2026-88772 — Citrix / NetScalervulnKEV agrega CVE-2026-88771 — Citrix / NetScalerransomm3rx reclama a cipher.systems · US · Technologyransombarracuda reclama a International Chemical Co. · Manufacturingransompayoutsking reclama a M****n · US · Not Foundransompanzer reclama a Asesoría FAR · Professional Servicesransompanzer reclama a Ressources Si · FR · Professional Servicesransomstorm reclama a First Secure Bank Group · US · Financial Servicesransomqilin reclama a XICO · MX · Not Foundransomqilin reclama a Island · CA · Technologyransomqilin reclama a Revenga Smart Solutions · ES · Technologyransomqilin reclama a Willatt & Flickinger · US · Not Foundransomarcusmedia reclama a Pantaneiro Capas · BR · Manufacturingransomemperador reclama a Car Service Abschlepp · DE · TransportationvulnKEV agrega CVE-2026-88772 — Citrix / NetScalervulnKEV agrega CVE-2026-88771 — Citrix / NetScalerransomm3rx reclama a cipher.systems · US · Technologyransombarracuda reclama a International Chemical Co. · Manufacturingransompayoutsking reclama a M****n · US · Not Found
← All CVEs
CVE WatchSep 28, 2026

CVE-2026-100892

A vulnerability was found in aligungr UERANSIM up to 3.3.0. This affects the function ULInformationTransfer of the file src/gnb/rrc/handler.

CVSS

5.3

Medium

EPSS

—

KEV

—

Exploit Today

0

0-100

Published: Sep 28, 2026 · Last modified: Sep 28, 2026 · CWE-119

EPSS · 30d

Not enough EPSS history yet.

Technical description

A vulnerability was found in aligungr UERANSIM up to 3.3.0. This affects the function ULInformationTransfer of the file src/gnb/rrc/handler.cpp of the component nr-gnb. Performing a manipulation of the argument dedicatedNASMessage results in memory corruption. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-1008887.3 HIG
—
——0A weakness has been identified in Trusted Domain Project OpenDKIM up to 2.11.0. This affects the function dkim_canon_selecthdrs of the file libopendkim/dkim-canon.c of the component DKIM Signature Header Selection. Executing a manipulation of the argument h can lead to out-of-bounds write. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.4h
CVE-2026-88772—
—
KEV—50Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability5h
CVE-2026-1007456.3 MED
21.3%
——6A vulnerability has been found in Edimax BR-6428nC 1.16. The impacted element is an unknown function of the file /goform/formWizSurvey of the component Wireless Wizard Handler. The manipulation of the argument interface1/interface2 leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.1d
CVE-2026-1007409.9 CRI
36.9%
——11A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack may be initiated remotely. The exploit is now public and may be used.1d
CVE-2026-580058.1 HIG
1.1%
——0Out-of-bounds read vulnerability in Altera Trusted Firmware on HPS allows Privilege Escalation and Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0.3d
CVE-2026-968919.8 CRI
49.3%
——15A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the argument peer_hostname  leads to out-of-bounds write. The attack may be initiated remotely.4d