CVE-2026-24081
Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
CVSS
7.4
High
EPSS
0.2%
p5
KEV
—
Exploit Today
2
0-100
Published: Sep 17, 2026 · Last modified: Sep 17, 2026 · CWE-126
Not enough EPSS history yet.
Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-252947.4 HIG5.2%
——2Transient DOS while parsing frame during channel usage.1dCVE-2026-252847.3 HIG1.3%
——0Information Disclosure when a pointer is reused after being deallocated.1dCVE-2026-252757.5 HIG22.7%
——7Transient DOS when processing authentication frames with invalid FILS information element header lengths.1dCVE-2026-240757.8 HIG1.5%
——0Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.1dCVE-2026-906103.3 LOW1.9%
——1A vulnerability was found in GPAC up to f1219cde. This affects the function gf_svg_attributes_copy of the file scenegraph/svg_attributes.c of the component MP4Box. Performing a manipulation results in buffer over-read. The attack is only possible with local access. The exploit has been made public and could be used. Upgrading to version abi-16.23 mitigates this issue. The patch is named afca1f1181668d85941d51ed1adf647807d5d975. Upgrading the affected component is recommended.3dCVE-2026-76653—22.6%
——7A missing
authentication vulnerability in the VPN configuration management has been
identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker
may be able to access and modify VPN configuration information without valid
credentials.
Successful
exploitation may allow a remote unauthenticated attacker to disclose and modify
VPN configuration information.7d