CVE-2026-25262Medium· 6.9▾ TwilightPoC availableMemory corruption while processing a crafted ELF file in the Primary Bootloader.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 38 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
1 GitHub repo (last check)
Memory corruption while processing a crafted ELF file in the Primary Bootloader.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-25255High· 8.8Exposed dangerous function lead to privilege escalation via gRPC server.
CVE-2026-25254Critical· 9.8Improper authorization leads to Remote Code Execution via SocketIO interface.
CVE-2026-25265High· 8.8Privilege escalation due to weak configuration while temporary file handling.
CVE-2026-25264High· 8.8Privilege escalation due to weak configuration during package extraction process.
CVE-2026-94142High· 8.8A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200
CVE-2026-94129High· 8.8A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800