CVE-2026-54122
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.
CVSS
8.4
High
EPSS
0.4%
p30
KEV
—
Exploit Today
9
0-100
Published: Jul 14, 2026 · Last modified: Jul 16, 2026 · CWE-122
0.3%EPSS · 30 days0.4%
2026-08-202026-09-17
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-814777.2 HIG—
——0Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.1dCVE-2026-814747.8 HIG—
——0Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.1dCVE-2026-91106—50.4%
——15HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.1dCVE-2026-91105—50.4%
——15HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.1dCVE-2026-91104—52.1%
——16HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.1dCVE-2026-91098—50.4%
——15HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.1d