CVE-2026-43832
Full details and mitigation steps are currently restricted and will be published at a later date.
CVSS
7.5
High
EPSS
0.1%
p4
KEV
—
Exploit Today
1
0-100
Published: Jul 31, 2026 · Last modified: Jul 31, 2026 · CWE-121
Not enough EPSS history yet.
Full details and mitigation steps are currently restricted and will be published at a later date.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-678229.8 CRI—
——0Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without length restriction, leading to stack overflow.18hCVE-2026-157227.5 HIG40.7%
——12A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters. The overflow occurs during payload decoding, before any authorization check. Stack protectors limit impact to denial of service.1dCVE-2026-438317.5 HIG3.8%
——1Full details and mitigation steps are currently restricted and will be published at a later date.17hCVE-2026-438297.5 HIG3.8%
——1Full details and mitigation steps are currently restricted and will be published at a later date.17hCVE-2026-105358.4 HIG2.3%
——1IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.1dCVE-2026-11771—26.9%
——8OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server2d