CVE-2026-15028
A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar
CVSS
3.9
Low
EPSS
0.2%
p11
KEV
—
Exploit Today
3
0-100
Published: Jul 10, 2026 · Last modified: Aug 31, 2026 · CWE-805 · CWE-122
0.2%EPSS · 30 days0.3%
2026-08-202026-09-17
A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of service, making the system unavailable, or potentially allow for arbitrary code execution, giving the attacker control over the affected system.
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:38279
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-15028
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2497970
- github.comhttps://github.com/libarchive/libarchive/issues/3251
- github.comhttps://github.com/libarchive/libarchive/pull/3253
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-814777.2 HIG—
——0Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.1dCVE-2026-814747.8 HIG—
——0Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.1dCVE-2026-202905.8 MED8.9%
——3A vulnerability in SSL/TLS certificate parsing in the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 2 Detection Engine to restart.
This vulnerability is due to incomplete validation of the SSL certificate. An attacker could exploit this vulnerability by sending a crafted SSL connection setup request to be parsed by Snort 2. A successful exploit could allow the attacker to cause the Snort 2 Detection Engine to restart unexpectedly, resulting in a denial of service (DoS) condition.2dCVE-2026-91106—50.4%
——15HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.1dCVE-2026-91105—50.4%
——15HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.1dCVE-2026-91104—52.1%
——16HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.1d