CVE-2026-18638
Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server process with a single requ
CVSS
6.5
Medio
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 11 ago 2026 · Última mod.: 11 ago 2026 · CWE-476 · CWE-703
Sin historial EPSS suficiente todavía.
Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server process with a single request, by calling SetPassword with a username that does not exist.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-656817.5 ALT—
———Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.7hCVE-2026-627026.8 MED—
———Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.7hCVE-2026-613456.5 MED—
———Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.7hCVE-2026-591386.5 MED—
———Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.7hCVE-2026-591327.5 ALT—
———Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.7hCVE-2026-484387.5 ALT—
———CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.7h