CVE-2026-94043
A vulnerability was determined in Free5GC up to 4.2.3. This vulnerability affects unknown code of the file /corefuzzer_deps/free5gc/NFs/amf/
CVSS
5.3
Medium
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Sep 20, 2026 · Last modified: Sep 21, 2026 · CWE-362
Not enough EPSS history yet.
A vulnerability was determined in Free5GC up to 4.2.3. This vulnerability affects unknown code of the file /corefuzzer_deps/free5gc/NFs/amf/internal/gmm/handler.go of the component Gmm Handler. This manipulation causes race condition. The attack can be initiated remotely. Patch name: e323b01464355781b8b8d5dd695e05cbc00a62f2. To fix this issue, it is recommended to deploy a patch.
- github.comhttps://github.com/free5gc/amf/commit/e323b01464355781b8b8d5dd695e05cbc00a62f2
- github.comhttps://github.com/free5gc/amf/pull/238
- github.comhttps://github.com/free5gc/free5gc/
- github.comhttps://github.com/free5gc/free5gc/issues/1109
- vuldb.comhttps://vuldb.com/cve/CVE-2026-94043
- vuldb.comhttps://vuldb.com/submit/949261
- vuldb.comhttps://vuldb.com/vuln/407972
- vuldb.comhttps://vuldb.com/vuln/407972/cti
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-715376.5 MED14.4%
——4Paymenter is a free and open-source webshop solution for management of hosting services. Prior to 1.5.7, app/Livewire/Services/Upgrade.php::doUpgrade() relies on Service::upgradable to check for a pending service upgrade and later executes $credit->increment('amount', abs($price)) without DB::transaction or lockForUpdate() spanning those operations. An authenticated customer with an active downgradable service can submit concurrent downgrade requests that each observe no pending upgrade, create separate upgrade records, and increment the same account credit balance, producing multiple spendable refunds for one downgrade. This issue is fixed in version 1.5.7.3dCVE-2026-734635.3 MED10.0%
——3On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configured, a race condition in the gNSI Authz service may cause a policy rotation to fail silently. An authenticated user whose access was revoked by the new policy may retain unauthorized access to gRPC interfaces. This does not affect Bootz.
This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.5dCVE-2026-917233.1 LOW6.4%
——2Race condition in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)3dCVE-2026-587347.0 HIG0.0%
——0In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.3dCVE-2026-587287.0 HIG0.0%
——0In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.3dCVE-2026-587247.0 HIG0.0%
——0In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.3d