CVE-2026-34761
Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, Ella Core panics when processing a NGAP handover failure messa
CVSS
5.8
Medio
EPSS
0.3%
p24
KEV
—
Exploit Today
7
0-100
Publicado: 2 abr 2026 · Última mod.: 24 jul 2026 · CWE-476
0.3%EPSS · 30 días0.3%
2026-08-142026-09-11
Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, Ella Core panics when processing a NGAP handover failure message. An attacker able to cause a gNodeB to send NGAP handover failure messages to Ella Core can crash the process, causing service disruption for all connected subscribers. This issue has been patched in version 1.8.0.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-781307.5 ALT23.5%
——7strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.1dCVE-2026-781265.9 MED34.7%
——10strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.1dCVE-2026-457477.5 ALT27.1%
——8Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields when a Lua script requested certificate information for TLS traffic where some certificate fields were absent. Crafted TLS traffic processed by a deployment using affected Lua TLS scripting could crash Suricata, resulting in denial of service. Version 7.0.16 contains a fix. As a workaround, avoid Lua scripts that call TLS certificate information helpers on untrusted traffic (`TlsGetCertInfo` function), or update scripts to handle missing certificate fields where possible.2dCVE-2026-865476.2 MED2.9%
——1mrubyc through 4.0.0 contains a null pointer dereference vulnerability in the op_enter() handler in src/vm.c when processing untrusted bytecode. Attackers can craft malicious .mrb bytecode files with OP_ENTER instructions at the top level to crash the embedding application and cause denial of service.2dCVE-2026-663036.5 MED54.2%
——16Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.4dCVE-2026-779018.8 ALT46.5%
——14Null pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code over a network.4d