CVE-2026-16005
Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by
CVSS
—
No CVSS
EPSS
0.1%
p0
KEV
—
Exploit Today
0
0-100
Published: Sep 8, 2026 · Last modified: Sep 8, 2026 · CWE-763
0.1%EPSS · 30 days0.1%
2026-09-082026-09-14
Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver's verification, which can corrupt data structures and cause a system crash (BSOD).Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-775007.8 HIG26.5%
——8Release of invalid pointer or reference in Windows Device Association Service allows an authorized attacker to elevate privileges locally.7dCVE-2026-748608.5 HIG28.7%
——9A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.5dCVE-2026-841318.8 HIG25.8%
——8Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.12dCVE-2023-205116.4 MED14.2%
——4Release of an invalid pointer in the AMD kernel mode driver (KMD) could allow a privileged attacker to create a double free condition potentially leading to arbitrary code execution.12dCVE-2026-19315—38.5%
——12A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.12dCVE-2026-749478.8 HIG15.7%
——5Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.26d