CVE-2026-25264High· 8.8▾ TwilightPrivilege escalation due to weak configuration during package extraction process.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Privilege escalation due to weak configuration during package extraction process.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-25265High· 8.8Privilege escalation due to weak configuration while temporary file handling.
CVE-2026-25255High· 8.8Exposed dangerous function lead to privilege escalation via gRPC server.
CVE-2026-25262Medium· 6.9Memory corruption while processing a crafted ELF file in the Primary Bootloader.
CVE-2026-25254Critical· 9.8Improper authorization leads to Remote Code Execution via SocketIO interface.
CVE-2026-24073High· 7.8Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.
CVE-2026-24074High· 7.8Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.