CVE-2024-26305Critical· 9.8▾ MidnightThere is a buffer overflow vulnerability in the underlying Utility daemon that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP p…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 22.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
15%
There is a buffer overflow vulnerability in the underlying Utility daemon that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
sd-wan = 8.6.0.4-2.2.0.0sd-wan = 8.6.0.4-2.2.0.7sd-wan = 8.7.0.0-2.3.0.0sd-wan = 8.7.0.0-2.3.0.9arubaos >= 6.5.4.0, < 8.10.0.12arubaos >= 8.11.0.0, < 8.11.2.2arubaos >= 10.4.0.0, < 10.4.1.1arubaos >= 10.5.0.0, < 10.5.1.1Upgrade past the affected range:
arubaos 10.5.1.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-48863High· 7.5A flaw was found in libsolv
CVE-2026-50259High· 7.8A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland
CVE-2026-50258High· 7.8A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland
CVE-2026-50256High· 7.8A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland
CVE-2026-1761High· 8.6A flaw was found in libsoup
CVE-2026-24882High· 8.4In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.