CVE-2026-50498
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVSS
7.8
Alto
EPSS
0.4%
p30
KEV
—
Exploit Today
9
0-100
Publicado: 14 jul 2026 · Última mod.: 21 jul 2026 · CWE-125 · CWE-191
0.3%EPSS · 30 días0.4%
2026-08-202026-09-17
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-92925——
——0In Redis community the cluster bus PING/PONG/MEET packet parser validated extension padding
and total length but never checked that string-carrying extensions are
properly null-terminated, allowing a crafted packet to trigger
out-of-bounds reads when the payload is later consumed as a C string. This vulnerability can potentially lead to loss of confidentiality or remote denial of service. Redis Software / Redis Enterprise are not affected by this issue.1dCVE-2026-252827.9 ALT0.9%
——0Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.1dCVE-2026-924755.3 MED3.8%
——1A weakness has been identified in GPAC 26.08-DEV. This impacts the function wait_for_header_and_parse of the file src/utils/downloader.c. This manipulation of the argument Content-Range causes out-of-bounds read. The attack requires local access. The exploit has been made available to the public and could be used for attacks. Upgrading to version abi-16.26 will fix this issue. Patch name: c74a3065038ede35c1c7b75fa493a69ef6bcdb84. It is recommended to upgrade the affected component.2dCVE-2026-91103—21.2%
——6HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.2dCVE-2026-734626.5 MED15.9%
——5On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected VLAN to cause the IGMP snooping agent to terminate unexpectedly. This results in a temporary disruption of multicast traffic management, which may cause multicast traffic to be flooded to all ports of the affected VLAN until the service recovers. Repeated exploitation could result in a prolonged loss of intended multicast forwarding behavior.2dCVE-2026-890287.5 ALT45.1%
——14MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows remote attackers to corrupt adjacent heap memory by supplying a crafted uniPwdLen value in the SMB1 SessionSetupAndX handler. An attacker can send a malformed SMB1 request with a uniPwdLen field that triggers an integer underflow, causing the resulting value to be used as the copy length in a memory copy operation into a smaller heap buffer, corrupting adjacent heap memory.2d