CVE-2026-9080
Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl
CVSS
7.3
High
EPSS
0.3%
p22
KEV
—
Exploit Today
7
0-100
Published: Jul 3, 2026 · Last modified: Jul 7, 2026 · CWE-416
0.3%EPSS · 30 days0.5%
2026-08-102026-09-07
Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-853607.0 HIG—
———Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.5hCVE-2026-839978.1 HIG—
———Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.5hCVE-2026-839797.8 HIG—
———Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.5hCVE-2026-839687.8 HIG—
———Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.5hCVE-2026-839407.0 HIG—
———Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.5hCVE-2026-819547.8 HIG—
———Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.5h