CVE-2026-46728High· 8.2▾ TwilightDas U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.
u-boot >= 2013.07, < 2026.04u-boot = 2026.04Upgrade past the affected range:
u-boot 2026.04Connected by shared product, vendor, weakness, or advisory.
CVE-2026-94111Medium· 6.6Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension origin with 32 characters in range a-p
CVE-2026-92701Critical· 9.1Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments
CVE-2026-92702Critical· 9.1Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments
CVE-2026-77339Medium· 5.1Process Compose is a scheduler and orchestrator for non-containerized applications
CVE-2026-12284Low· 3.7Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a malicious or compromised Mattermost server (or a user with script access to a connected server view) to disconnect an …
CVE-2026-75025Medium· 4.7Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue where Mattermost Desktop did not sufficiently restrict server-rendered content from accessing local or private network resources