PULSE
FEED
ransomthegentlemen reclama a LegalWise · ZA · Professional Servicesransomthegentlemen reclama a Samwumed · KR · Healthcareransomthegentlemen reclama a Edcon · ZA · Manufacturingransomthegentlemen reclama a Defencebit · GB · Government & Defenseransomthegentlemen reclama a Datacomm Services · US · Technologyransomthegentlemen reclama a Webb Electric Company of Florida · US · Energy & Utilitiesransomthegentlemen reclama a Solaria · ID · Energy & Utilitiesransomthegentlemen reclama a Auren · ES · Professional Servicesransomthegentlemen reclama a QUALITY SPORT Topsport Italia · IT · Retail & E-Commerceransomthegentlemen reclama a Europrim · FR · Healthcareransomthegentlemen reclama a Telrad Networks · IL · Technologyransomthegentlemen reclama a Groupe APROSEP · SN · Otherransomthegentlemen reclama a Drinks Wines Spirits · TW · Retail & E-Commerceransomthegentlemen reclama a Custom Rx Shoppe · US · Healthcareransomthegentlemen reclama a LegalWise · ZA · Professional Servicesransomthegentlemen reclama a Samwumed · KR · Healthcareransomthegentlemen reclama a Edcon · ZA · Manufacturingransomthegentlemen reclama a Defencebit · GB · Government & Defenseransomthegentlemen reclama a Datacomm Services · US · Technologyransomthegentlemen reclama a Webb Electric Company of Florida · US · Energy & Utilitiesransomthegentlemen reclama a Solaria · ID · Energy & Utilitiesransomthegentlemen reclama a Auren · ES · Professional Servicesransomthegentlemen reclama a QUALITY SPORT Topsport Italia · IT · Retail & E-Commerceransomthegentlemen reclama a Europrim · FR · Healthcareransomthegentlemen reclama a Telrad Networks · IL · Technologyransomthegentlemen reclama a Groupe APROSEP · SN · Otherransomthegentlemen reclama a Drinks Wines Spirits · TW · Retail & E-Commerceransomthegentlemen reclama a Custom Rx Shoppe · US · Healthcare
← All CVEs
CVE WatchSep 30, 2026

CVE-2026-103110

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code

CVSS

9.8

Critical

EPSS

—

KEV

—

Exploit Today

—

0-100

Published: Sep 30, 2026 · Last modified: Sep 30, 2026 · CWE-787

EPSS · 30d

Not enough EPSS history yet.

Technical description

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Conferencing Node.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-1031117.6 HIG
—
———PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.4h
CVE-2026-1031097.7 HIG
—
———Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service. A crafted media stream may result in a controlled abort during processing, and has the potential to achieve memory corruption.6h
CVE-2026-81433—
—
——0A stack-based buffer overflow vulnerability in WatchGuard Fireware OS's DHCP fingerprinting daemon (fingerd) allows an unauthenticated attacker with adjacent network access to execute arbitrary code or crash the process by sending a specially crafted DHCP packet.9h
CVE-2026-742257.1 HIG
—
——0U-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp6_parse_options() that fails to validate SERVERID and CLIENTID option lengths from DHCPv6 packets. Attackers on the local network can send crafted DHCPv6 ADVERTISE or REPLY packets during netboot to corrupt memory and crash the bootloader.11h
CVE-2026-719744.8 MED
—
——0U-Boot before 2026.10-rc3 contains an out-of-bounds write vulnerability in read_slotted_partition() that fails to validate image size against partition bounds. Attackers with physical access can supply crafted boot media with oversized headers to write past the load buffer into bootloader memory on devices without Android Verified Boot protection.11h
CVE-2026-719725.9 MED
—
——0U-Boot through 2026.10-rc5 contains an out-of-bounds write vulnerability in the video_display_rle8_bitmap function in drivers/video/video_bmp.c. Attackers can supply a crafted RLE8-compressed BMP image to corrupt memory adjacent to the framebuffer and crash the bootloader.11h