CVE-2026-44628
An unauthenticated attacker can crash the worklist server with a single crafted query when the server has a valid Called AE Title / storage
CVSS
7.5
Alto
EPSS
0.4%
p32
KEV
—
Exploit Today
10
0-100
Publicado: 30 jun 2026 · Última mod.: 1 jul 2026 · CWE-843
0.4%EPSS · 30 días0.4%
2026-07-012026-07-21
An unauthenticated attacker can crash the worklist server with a single crafted query when the server has a valid Called AE Title / storage directory, the expected lockfile, and at least one matching worklist record.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-646089.8 CRÍ—
——0Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual data, so input with an inconsistent schema can cause type confusion and out-of-bounds memory access. Only the C++ implementation is affected; other language implementations of Apache Fory are not.
This issue affects Apache Fory C++: from 0.14.0 before 1.4.0.
Users are recommended to upgrade to version 1.4.0, which fixes the issue.4hCVE-2026-157768.8 ALT25.0%
——8Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)6dCVE-2026-585417.8 ALT21.0%
——6Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.5dCVE-2026-571087.5 ALT61.3%
——18Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.1dCVE-2026-550257.8 ALT22.4%
——7Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.6dCVE-2026-550247.8 ALT31.6%
——9Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.6d