PULSE
LIVE16signals / 24h
FEED
ransomorova reclama a Ganzhou Xinye Craft Co., Ltd. · HK · Manufacturingransompanzer reclama a Xpress Tech · Technologyransomqilin reclama a G.M.A. GRANDI MARCHE AUTOMOBILI - S.R.L · IT · Transportationransomqilin reclama a Crown Group · PK · Otherransomdragonforce reclama a QPC Global · GB · Otherransominterlock reclama a AngMar Companies · Not Foundransompayload reclama a B&B Hydraulik · DE · Manufacturingransompayload reclama a Stücheli Architekten · CH · Professional Servicesransompayload reclama a Baya Technologies · Technologyransomkrybit reclama a www.kilpi-koskinen.fi · FI · Otherransomkrybit reclama a www.apsanet.com.ar · AR · Professional Servicesransomqilin reclama a Service Evaluation Concepts · US · Professional Servicesransomqilin reclama a tommer construction · US · Manufacturingransomdirewolf reclama a Leafwell · US · Healthcareransomorova reclama a Ganzhou Xinye Craft Co., Ltd. · HK · Manufacturingransompanzer reclama a Xpress Tech · Technologyransomqilin reclama a G.M.A. GRANDI MARCHE AUTOMOBILI - S.R.L · IT · Transportationransomqilin reclama a Crown Group · PK · Otherransomdragonforce reclama a QPC Global · GB · Otherransominterlock reclama a AngMar Companies · Not Foundransompayload reclama a B&B Hydraulik · DE · Manufacturingransompayload reclama a Stücheli Architekten · CH · Professional Servicesransompayload reclama a Baya Technologies · Technologyransomkrybit reclama a www.kilpi-koskinen.fi · FI · Otherransomkrybit reclama a www.apsanet.com.ar · AR · Professional Servicesransomqilin reclama a Service Evaluation Concepts · US · Professional Servicesransomqilin reclama a tommer construction · US · Manufacturingransomdirewolf reclama a Leafwell · US · Healthcare
← All CVEs
CVE WatchAug 11, 2026

CVE-2026-18638

Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server process with a single requ

CVSS

6.5

Medium

EPSS

KEV

Exploit Today

0-100

Published: Aug 11, 2026 · Last modified: Aug 11, 2026 · CWE-476 · CWE-703

EPSS · 30d

Not enough EPSS history yet.

Technical description

Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server process with a single request, by calling SetPassword with a username that does not exist.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-656817.5 HIG
Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.6h
CVE-2026-627026.8 MED
Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.6h
CVE-2026-613456.5 MED
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.6h
CVE-2026-591386.5 MED
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.6h
CVE-2026-591327.5 HIG
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.6h
CVE-2026-484387.5 HIG
CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.6h
CVE-2026-18638 — Any authenticated Velociraptor user — including one holding only the readerrole · Pulse | Pulse