PULSE
LIVE17signals / 24h
FEED
ransomspacebears reclama a Basso Fedele & Figli S.r.l. (Olio Basso) / Villa Raiano · IT · Agriculture and Food Productionransomgenesis reclama a **E*** · US · Not Foundransomorova reclama a Ganzhou Xinye Craft Co., Ltd. · HK · Manufacturingransompanzer reclama a Xpress Tech · Technologyransomqilin reclama a G.M.A. GRANDI MARCHE AUTOMOBILI - S.R.L · IT · Transportationransomqilin reclama a Crown Group · PK · Otherransomdragonforce reclama a QPC Global · GB · Otherransominterlock reclama a AngMar Companies · Not Foundransompayload reclama a B&B Hydraulik · DE · Manufacturingransompayload reclama a Stücheli Architekten · CH · Professional Servicesransompayload reclama a Baya Technologies · Technologyransomkrybit reclama a www.kilpi-koskinen.fi · FI · Otherransomkrybit reclama a www.apsanet.com.ar · AR · Professional Servicesransomqilin reclama a Service Evaluation Concepts · US · Professional Servicesransomspacebears reclama a Basso Fedele & Figli S.r.l. (Olio Basso) / Villa Raiano · IT · Agriculture and Food Productionransomgenesis reclama a **E*** · US · Not Foundransomorova reclama a Ganzhou Xinye Craft Co., Ltd. · HK · Manufacturingransompanzer reclama a Xpress Tech · Technologyransomqilin reclama a G.M.A. GRANDI MARCHE AUTOMOBILI - S.R.L · IT · Transportationransomqilin reclama a Crown Group · PK · Otherransomdragonforce reclama a QPC Global · GB · Otherransominterlock reclama a AngMar Companies · Not Foundransompayload reclama a B&B Hydraulik · DE · Manufacturingransompayload reclama a Stücheli Architekten · CH · Professional Servicesransompayload reclama a Baya Technologies · Technologyransomkrybit reclama a www.kilpi-koskinen.fi · FI · Otherransomkrybit reclama a www.apsanet.com.ar · AR · Professional Servicesransomqilin reclama a Service Evaluation Concepts · US · Professional Services
← All CVEs
CVE WatchAug 11, 2026

CVE-2026-18687

MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the c

CVSS

7.1

High

EPSS

KEV

Exploit Today

0-100

Published: Aug 11, 2026 · Last modified: Aug 11, 2026 · CWE-191

EPSS · 30d

Not enough EPSS history yet.

Technical description

MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privileges could submit a specially formed request that leads to a server crash or excessive internal writes, resulting in resource exhaustion and corruption of encrypted index data.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-713896.2 MED
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.11h
CVE-2026-649097.8 HIG
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.9h
CVE-2026-635157.8 HIG
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.9h
CVE-2026-628146.5 MED
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.6h
CVE-2026-627456.5 MED
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.6h
CVE-2026-627426.5 MED
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.6h