CVE-2026-18638
Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server process with a single requ
CVSS
6.5
Medium
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 11, 2026 · Last modified: Aug 11, 2026 · CWE-476 · CWE-703
Not enough EPSS history yet.
Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server process with a single request, by calling SetPassword with a username that does not exist.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-656817.5 HIG—
———Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.6hCVE-2026-627026.8 MED—
———Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.6hCVE-2026-613456.5 MED—
———Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.6hCVE-2026-591386.5 MED—
———Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.6hCVE-2026-591327.5 HIG—
———Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.6hCVE-2026-484387.5 HIG—
———CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.6h