CVE-2026-86547
mrubyc through 4.0.0 contains a null pointer dereference vulnerability in the op_enter() handler in src/vm.c when processing untrusted bytec
CVSS
6.2
Medium
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Sep 9, 2026 · Last modified: Sep 9, 2026 · CWE-476
Not enough EPSS history yet.
mrubyc through 4.0.0 contains a null pointer dereference vulnerability in the op_enter() handler in src/vm.c when processing untrusted bytecode. Attackers can craft malicious .mrb bytecode files with OP_ENTER instructions at the top level to crash the embedding application and cause denial of service.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-663036.5 MED54.1%
——16Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.2dCVE-2026-779018.8 HIG46.4%
——14Null pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code over a network.1dCVE-2026-774897.8 HIG24.5%
——7Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally.2dCVE-2026-729497.5 HIG65.0%
——19Null pointer dereference in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to deny service over a network.2dCVE-2026-729396.5 MED64.7%
——19Null pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service over a network.2dCVE-2026-705755.3 MED55.3%
——17Null pointer dereference in Windows Schannel allows an authorized attacker to deny service over a network.2d