CVE-2026-78130
strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.
CVSS
7.5
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 11, 2026 · Last modified: Sep 11, 2026 · CWE-476
Not enough EPSS history yet.
strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-781265.9 MED—
———strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.7hCVE-2026-457477.5 HIG—
———Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields when a Lua script requested certificate information for TLS traffic where some certificate fields were absent. Crafted TLS traffic processed by a deployment using affected Lua TLS scripting could crash Suricata, resulting in denial of service. Version 7.0.16 contains a fix. As a workaround, avoid Lua scripts that call TLS certificate information helpers on untrusted traffic (`TlsGetCertInfo` function), or update scripts to handle missing certificate fields where possible.13hCVE-2026-865476.2 MED—
——0mrubyc through 4.0.0 contains a null pointer dereference vulnerability in the op_enter() handler in src/vm.c when processing untrusted bytecode. Attackers can craft malicious .mrb bytecode files with OP_ENTER instructions at the top level to crash the embedding application and cause denial of service.13hCVE-2026-663036.5 MED54.1%
——16Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.3dCVE-2026-779018.8 HIG46.4%
——14Null pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code over a network.2dCVE-2026-774897.8 HIG24.5%
——7Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally.3d