CVE-2026-26824Medium· 6.5▾ TwilightPoC availablelibxls through version 1.6.3 contains a use of uninitialized memory vulnerability in the OLE container parser. Memory allocated for the Master Sector Allocation Table (MSAT) in read_MSAT() is not fully initialized before being consumed b…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 35.8 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 23.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
libxls through version 1.6.3 contains a use of uninitialized memory vulnerability in the OLE container parser. Memory allocated for the Master Sector Allocation Table (MSAT) in read_MSAT() is not fully initialized before being consumed by ole2_validate_sector_chain(), which may result in application crashes or potential information disclosure when processing a crafted XLS file
libxls <= 1.6.3Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-26825Medium· 5.3A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files
CVE-2026-91963Medium· 6.5FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel
CVE-2026-5888Medium· 6.5Uninitialized Use in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page
CVE-2026-76919Medium· 5.3Use of Uninitialized Variable in Wireshark
CVE-2026-58731Medium· 6.2In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data
CVE-2026-58721Medium· 4.4In multiple locations, there is a possible information disclosure due to uninitialized memory use