CVE-2024-26507High· 7.8▾ MidnightPoC availableAn issue in FinalWire AIRDA Extreme, AIDA64 Engineer, AIDA64 Business, AIDA64 Network Audit through 7.00.6742 allows a local attacker to escalate privileges via the DeviceIoControl call associated with MmMapIoSpace, IoAllocateMdl, MmBuil…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 42.9 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
An issue in FinalWire AIRDA Extreme, AIDA64 Engineer, AIDA64 Business, AIDA64 Network Audit through 7.00.6742 allows a local attacker to escalate privileges via the DeviceIoControl call associated with MmMapIoSpace, IoAllocateMdl, MmBuildMdlForNonPagedPool, or MmMapLockedPages components.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102269Medium· 4.8PyJWT is a Python implementation of JSON Web Token standards
CVE-2026-100902Medium· 6.5A vulnerability was determined in Barco ClickShare CX-20 Gen2 up to 02.26.00.0007
CVE-2026-100699Medium· 5.3Nodemailer is a Node.js email-sending library
CVE-2026-41293High· 7.3tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated (CVE-2026-41293)
CVE-2026-27889High· 7.5NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system
CVE-2026-42579High· 7.5Netty is an asynchronous, event-driven network application framework