WID-SEC-W-2026-3320
Vulnerability from csaf_certbund - Published: 2026-09-10 22:00 - Updated: 2026-09-30 22:00Summary
MongoDB: Mehrere Schwachstellen
Severity
Hoch
Notes
Das BSI ist als Anbieter für die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch dafür verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgfältig im Einzelfall zu prüfen.
Produktbeschreibung: MongoDB ist ein Open-Source-Dokumentendatenbank.
Angriff: Ein Angreifer kann mehrere Schwachstellen in MongoDB ausnutzen, um Abfrage- und Zugriffsbeschränkungen zu umgehen, nicht vorgesehene Datensätze oder Dateien auszulesen, zu verändern oder zu löschen sowie unter bestimmten Voraussetzungen MongoDB-Server oder Anwendungen zum Absturz zu bringen und dadurch einen Denial-of-Service zu verursachen.
Betroffene Betriebssysteme: - Linux
- Sonstiges
- UNIX
- Windows
Affected products
Known affected
17 products
| Product | Identifier | Version | Remediation |
|---|---|---|---|
|
Open Source MongoDB Ruby Driver
Open Source / MongoDB
|
cpe:/a:mongodb:mongodb:ruby_driver
|
Ruby Driver | |
|
Open Source MongoDB Python Driver <4.18.1
Open Source / MongoDB
|
Python Driver <4.18.1 | ||
|
Open Source MongoDB Go Driver <2.9.1
Open Source / MongoDB
|
Go Driver <2.9.1 | ||
|
Open Source MongoDB Go Driver <1.17.10
Open Source / MongoDB
|
Go Driver <1.17.10 | ||
|
RESF Rocky Linux
RESF
|
cpe:/o:resf:rocky_linux:-
|
— | |
|
Open Source MongoDB Java Driver <5.11.1
Open Source / MongoDB
|
Java Driver <5.11.1 | ||
|
Open Source MongoDB Server <7.0.41
Open Source / MongoDB
|
Server <7.0.41 | ||
|
Open Source MongoDB Laravel <5.11.0
Open Source / MongoDB
|
Laravel <5.11.0 | ||
|
Fedora Linux
Fedora
|
cpe:/o:fedoraproject:fedora:-
|
— | |
|
Open Source MongoDB Server <8.3.9
Open Source / MongoDB
|
Server <8.3.9 | ||
|
Open Source MongoDB Rust Driver <3.9.1
Open Source / MongoDB
|
Rust Driver <3.9.1 | ||
|
Open Source MongoDB DB C++ Driver <4.5.3
Open Source / MongoDB
|
DB C++ Driver <4.5.3 | ||
|
Open Source MongoDB PHP Library
Open Source / MongoDB
|
cpe:/a:mongodb:mongodb:php_library
|
PHP Library | |
|
Open Source MongoDB Server <8.0.30
Open Source / MongoDB
|
Server <8.0.30 | ||
|
Open Source MongoDB C# Driver
Open Source / MongoDB
|
cpe:/a:mongodb:mongodb:c_driver
|
C# Driver | |
|
Open Source MongoDB C Driver <2.5.3
Open Source / MongoDB
|
C Driver <2.5.3 | ||
|
Open Source MongoDB Countly Server <25.03.53-LTS
Open Source / MongoDB
|
Countly Server <25.03.53-LTS |
Affected products
Known affected
17 products, the same list as for
CVE-2026-82052
Affected products
Known affected
17 products, the same list as for
CVE-2026-82052
Affected products
Known affected
17 products, the same list as for
CVE-2026-82052
Affected products
Known affected
17 products, the same list as for
CVE-2026-82052
Affected products
Known affected
17 products, the same list as for
CVE-2026-82052
Affected products
Known affected
17 products, the same list as for
CVE-2026-82052
Affected products
Known affected
17 products, the same list as for
CVE-2026-82052
Affected products
Known affected
17 products, the same list as for
CVE-2026-82052
Affected products
Known affected
17 products, the same list as for
CVE-2026-82052
Affected products
Known affected
17 products, the same list as for
CVE-2026-82052
Affected products
Known affected
17 products, the same list as for
CVE-2026-82052
Affected products
Known affected
17 products, the same list as for
CVE-2026-82052
Affected products
Known affected
17 products, the same list as for
CVE-2026-82052
Affected products
Known affected
17 products, the same list as for
CVE-2026-82052
Affected products
Known affected
17 products, the same list as for
CVE-2026-82052
Affected products
Known affected
17 products, the same list as for
CVE-2026-82052
References
31 references
{
"document": {
"aggregate_severity": {
"text": "hoch"
},
"category": "csaf_base",
"csaf_version": "2.0",
"distribution": {
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "de-DE",
"notes": [
{
"category": "legal_disclaimer",
"text": "Das BSI ist als Anbieter f\u00fcr die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch daf\u00fcr verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgf\u00e4ltig im Einzelfall zu pr\u00fcfen."
},
{
"category": "description",
"text": "MongoDB ist ein Open-Source-Dokumentendatenbank.",
"title": "Produktbeschreibung"
},
{
"category": "summary",
"text": "Ein Angreifer kann mehrere Schwachstellen in MongoDB ausnutzen, um Abfrage- und Zugriffsbeschr\u00e4nkungen zu umgehen, nicht vorgesehene Datens\u00e4tze oder Dateien auszulesen, zu ver\u00e4ndern oder zu l\u00f6schen sowie unter bestimmten Voraussetzungen MongoDB-Server oder Anwendungen zum Absturz zu bringen und dadurch einen Denial-of-Service zu verursachen.",
"title": "Angriff"
},
{
"category": "general",
"text": "- Linux\n- Sonstiges\n- UNIX\n- Windows",
"title": "Betroffene Betriebssysteme"
}
],
"publisher": {
"category": "other",
"contact_details": "csaf-provider@cert-bund.de",
"name": "Bundesamt f\u00fcr Sicherheit in der Informationstechnik",
"namespace": "https://www.bsi.bund.de"
},
"references": [
{
"category": "self",
"summary": "WID-SEC-W-2026-3320 - CSAF Version",
"url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3320.json"
},
{
"category": "self",
"summary": "WID-SEC-2026-3320 - Portal Version",
"url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3320"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-09-10",
"url": "https://github.com/advisories/GHSA-38pq-38pp-9f4m"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-09-10",
"url": "https://github.com/advisories/GHSA-3jwc-jjcp-mq77"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-09-10",
"url": "https://github.com/advisories/GHSA-3m7r-f729-ggmf"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-09-10",
"url": "https://github.com/advisories/GHSA-4ww7-gqv6-mffc"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-09-10",
"url": "https://github.com/advisories/GHSA-8h2c-ghff-mpg9"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-09-10",
"url": "https://github.com/advisories/GHSA-fwpq-crrq-c5xc"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-09-10",
"url": "https://github.com/advisories/GHSA-gf3f-xg7m-h8wp"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-09-10",
"url": "https://github.com/advisories/GHSA-hm9m-cvww-9ffq"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-09-10",
"url": "https://github.com/advisories/GHSA-j7j2-rrxf-5xvf"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-09-10",
"url": "https://github.com/advisories/GHSA-jcw9-p6mm-h9pj"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-09-10",
"url": "https://github.com/advisories/GHSA-jgj9-g5rr-w8xg"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-09-10",
"url": "https://github.com/advisories/GHSA-m8p4-wmg5-p4x3"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-09-10",
"url": "https://github.com/advisories/GHSA-p5gh-5wmf-x9p2"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-09-10",
"url": "https://github.com/advisories/GHSA-pm5h-mrq6-hccx"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-09-10",
"url": "https://github.com/advisories/GHSA-x33j-9628-wvwc"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-09-10",
"url": "https://github.com/advisories/GHSA-x6mc-fgjf-77r7"
},
{
"category": "external",
"summary": "Fedora Security Advisory FEDORA-2026-785536C3AB vom 2026-09-15",
"url": "https://bodhi.fedoraproject.org/updates/FEDORA-2026-785536c3ab"
},
{
"category": "external",
"summary": "Fedora Security Advisory FEDORA-2026-5E35777502 vom 2026-09-15",
"url": "https://bodhi.fedoraproject.org/updates/FEDORA-2026-5e35777502"
},
{
"category": "external",
"summary": "Fedora Security Advisory FEDORA-EPEL-2026-D69C3D4D86 vom 2026-09-15",
"url": "https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-d69c3d4d86"
},
{
"category": "external",
"summary": "Fedora Security Advisory FEDORA-EPEL-2026-D66E71CDD9 vom 2026-09-15",
"url": "https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-d66e71cdd9"
},
{
"category": "external",
"summary": "Fedora Security Advisory FEDORA-EPEL-2026-77994590BF vom 2026-09-15",
"url": "https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-77994590bf"
},
{
"category": "external",
"summary": "Fedora Security Advisory FEDORA-EPEL-2026-49D3C785D9 vom 2026-09-15",
"url": "https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-49d3c785d9"
},
{
"category": "external",
"summary": "Fedora Security Advisory FEDORA-EPEL-2026-3E09CCAE3A vom 2026-09-15",
"url": "https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-3e09ccae3a"
},
{
"category": "external",
"summary": "Fedora Security Advisory FEDORA-2026-B056D7184A vom 2026-09-15",
"url": "https://bodhi.fedoraproject.org/updates/FEDORA-2026-b056d7184a"
},
{
"category": "external",
"summary": "Fedora Security Advisory FEDORA-EPEL-2026-AA805ED951 vom 2026-09-18",
"url": "https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-aa805ed951"
},
{
"category": "external",
"summary": "Fedora Security Advisory FEDORA-EPEL-2026-8775C68ED7 vom 2026-09-18",
"url": "https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-8775c68ed7"
},
{
"category": "external",
"summary": "Fedora Security Advisory FEDORA-2026-0FCC2D09C6 vom 2026-09-18",
"url": "https://bodhi.fedoraproject.org/updates/FEDORA-2026-0fcc2d09c6"
},
{
"category": "external",
"summary": "Fedora Security Advisory FEDORA-EPEL-2026-F3189AD8BC vom 2026-09-18",
"url": "https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-f3189ad8bc"
},
{
"category": "external",
"summary": "Rocky Linux Security Advisory RLSA-2026:73519 vom 2026-10-01",
"url": "https://errata.build.resf.org/RLSA-2026:73519"
}
],
"source_lang": "en-US",
"title": "MongoDB: Mehrere Schwachstellen",
"tracking": {
"current_release_date": "2026-09-30T22:00:00.000+00:00",
"generator": {
"date": "2026-10-01T10:07:06.582+00:00",
"engine": {
"name": "BSI-WID",
"version": "1.6.0"
}
},
"id": "WID-SEC-W-2026-3320",
"initial_release_date": "2026-09-10T22:00:00.000+00:00",
"revision_history": [
{
"date": "2026-09-10T22:00:00.000+00:00",
"number": "1",
"summary": "Initiale Fassung"
},
{
"date": "2026-09-14T22:00:00.000+00:00",
"number": "2",
"summary": "Neue Updates von Fedora aufgenommen"
},
{
"date": "2026-09-17T22:00:00.000+00:00",
"number": "3",
"summary": "Neue Updates von Fedora aufgenommen"
},
{
"date": "2026-09-30T22:00:00.000+00:00",
"number": "4",
"summary": "Neue Updates von Rocky Enterprise Software Foundation aufgenommen"
}
],
"status": "final",
"version": "4"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"category": "product_name",
"name": "Fedora Linux",
"product": {
"name": "Fedora Linux",
"product_id": "74178",
"product_identification_helper": {
"cpe": "cpe:/o:fedoraproject:fedora:-"
}
}
}
],
"category": "vendor",
"name": "Fedora"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "Server \u003c7.0.41",
"product": {
"name": "Open Source MongoDB Server \u003c7.0.41",
"product_id": "T059254"
}
},
{
"category": "product_version",
"name": "Server 7.0.41",
"product": {
"name": "Open Source MongoDB Server 7.0.41",
"product_id": "T059254-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:mongodb:mongodb:server__7.0.41"
}
}
},
{
"category": "product_version_range",
"name": "Server \u003c8.0.30",
"product": {
"name": "Open Source MongoDB Server \u003c8.0.30",
"product_id": "T059255"
}
},
{
"category": "product_version",
"name": "Server 8.0.30",
"product": {
"name": "Open Source MongoDB Server 8.0.30",
"product_id": "T059255-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:mongodb:mongodb:server__8.0.30"
}
}
},
{
"category": "product_version_range",
"name": "Server \u003c8.3.9",
"product": {
"name": "Open Source MongoDB Server \u003c8.3.9",
"product_id": "T059256"
}
},
{
"category": "product_version",
"name": "Server 8.3.9",
"product": {
"name": "Open Source MongoDB Server 8.3.9",
"product_id": "T059256-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:mongodb:mongodb:server__8.3.9"
}
}
},
{
"category": "product_version_range",
"name": "Laravel \u003c5.11.0",
"product": {
"name": "Open Source MongoDB Laravel \u003c5.11.0",
"product_id": "T059396"
}
},
{
"category": "product_version",
"name": "Laravel 5.11.0",
"product": {
"name": "Open Source MongoDB Laravel 5.11.0",
"product_id": "T059396-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:mongodb:mongodb:laravel__5.11.0"
}
}
},
{
"category": "product_version",
"name": "PHP Library",
"product": {
"name": "Open Source MongoDB PHP Library",
"product_id": "T059398",
"product_identification_helper": {
"cpe": "cpe:/a:mongodb:mongodb:php_library"
}
}
},
{
"category": "product_version_range",
"name": "Rust Driver \u003c3.9.1",
"product": {
"name": "Open Source MongoDB Rust Driver \u003c3.9.1",
"product_id": "T059399"
}
},
{
"category": "product_version",
"name": "Rust Driver 3.9.1",
"product": {
"name": "Open Source MongoDB Rust Driver 3.9.1",
"product_id": "T059399-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:mongodb:mongodb:rust_driver__3.9.1"
}
}
},
{
"category": "product_version",
"name": "C# Driver",
"product": {
"name": "Open Source MongoDB C# Driver",
"product_id": "T059400",
"product_identification_helper": {
"cpe": "cpe:/a:mongodb:mongodb:c_driver"
}
}
},
{
"category": "product_version_range",
"name": "Python Driver \u003c4.18.1",
"product": {
"name": "Open Source MongoDB Python Driver \u003c4.18.1",
"product_id": "T059404"
}
},
{
"category": "product_version",
"name": "Python Driver 4.18.1",
"product": {
"name": "Open Source MongoDB Python Driver 4.18.1",
"product_id": "T059404-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:mongodb:mongodb:python_driver__4.18.1"
}
}
},
{
"category": "product_version",
"name": "Ruby Driver",
"product": {
"name": "Open Source MongoDB Ruby Driver",
"product_id": "T059405",
"product_identification_helper": {
"cpe": "cpe:/a:mongodb:mongodb:ruby_driver"
}
}
},
{
"category": "product_version_range",
"name": "Go Driver \u003c1.17.10",
"product": {
"name": "Open Source MongoDB Go Driver \u003c1.17.10",
"product_id": "T059406"
}
},
{
"category": "product_version",
"name": "Go Driver 1.17.10",
"product": {
"name": "Open Source MongoDB Go Driver 1.17.10",
"product_id": "T059406-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:mongodb:mongodb:go_driver__1.17.10"
}
}
},
{
"category": "product_version_range",
"name": "Go Driver \u003c2.9.1",
"product": {
"name": "Open Source MongoDB Go Driver \u003c2.9.1",
"product_id": "T059407"
}
},
{
"category": "product_version",
"name": "Go Driver 2.9.1",
"product": {
"name": "Open Source MongoDB Go Driver 2.9.1",
"product_id": "T059407-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:mongodb:mongodb:go_driver__2.9.1"
}
}
},
{
"category": "product_version_range",
"name": "Java Driver \u003c5.11.1",
"product": {
"name": "Open Source MongoDB Java Driver \u003c5.11.1",
"product_id": "T059409"
}
},
{
"category": "product_version",
"name": "Java Driver 5.11.1",
"product": {
"name": "Open Source MongoDB Java Driver 5.11.1",
"product_id": "T059409-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:mongodb:mongodb:java_driver__5.11.1"
}
}
},
{
"category": "product_version_range",
"name": "DB C++ Driver \u003c4.5.3",
"product": {
"name": "Open Source MongoDB DB C++ Driver \u003c4.5.3",
"product_id": "T059410"
}
},
{
"category": "product_version",
"name": "DB C++ Driver 4.5.3",
"product": {
"name": "Open Source MongoDB DB C++ Driver 4.5.3",
"product_id": "T059410-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:mongodb:mongodb:db_c_driver__4.5.3"
}
}
},
{
"category": "product_version_range",
"name": "C Driver \u003c2.5.3",
"product": {
"name": "Open Source MongoDB C Driver \u003c2.5.3",
"product_id": "T059411"
}
},
{
"category": "product_version",
"name": "C Driver 2.5.3",
"product": {
"name": "Open Source MongoDB C Driver 2.5.3",
"product_id": "T059411-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:mongodb:mongodb:c_driver__2.5.3"
}
}
},
{
"category": "product_version_range",
"name": "Countly Server \u003c25.03.53-LTS",
"product": {
"name": "Open Source MongoDB Countly Server \u003c25.03.53-LTS",
"product_id": "T059413"
}
},
{
"category": "product_version",
"name": "Countly Server 25.03.53-LTS",
"product": {
"name": "Open Source MongoDB Countly Server 25.03.53-LTS",
"product_id": "T059413-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:mongodb:mongodb:countly_server__25.03.53-lts"
}
}
}
],
"category": "product_name",
"name": "MongoDB"
}
],
"category": "vendor",
"name": "Open Source"
},
{
"branches": [
{
"category": "product_name",
"name": "RESF Rocky Linux",
"product": {
"name": "RESF Rocky Linux",
"product_id": "T054581",
"product_identification_helper": {
"cpe": "cpe:/o:resf:rocky_linux:-"
}
}
}
],
"category": "vendor",
"name": "RESF"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2026-82052",
"product_status": {
"known_affected": [
"T059405",
"T059404",
"T059407",
"T059406",
"T054581",
"T059409",
"T059254",
"T059396",
"74178",
"T059256",
"T059399",
"T059410",
"T059398",
"T059255",
"T059400",
"T059411",
"T059413"
]
},
"release_date": "2026-09-10T22:00:00.000+00:00",
"title": "CVE-2026-82052"
},
{
"cve": "CVE-2026-87803",
"product_status": {
"known_affected": [
"T059405",
"T059404",
"T059407",
"T059406",
"T054581",
"T059409",
"T059254",
"T059396",
"74178",
"T059256",
"T059399",
"T059410",
"T059398",
"T059255",
"T059400",
"T059411",
"T059413"
]
},
"release_date": "2026-09-10T22:00:00.000+00:00",
"title": "CVE-2026-87803"
},
{
"cve": "CVE-2026-88022",
"product_status": {
"known_affected": [
"T059405",
"T059404",
"T059407",
"T059406",
"T054581",
"T059409",
"T059254",
"T059396",
"74178",
"T059256",
"T059399",
"T059410",
"T059398",
"T059255",
"T059400",
"T059411",
"T059413"
]
},
"release_date": "2026-09-10T22:00:00.000+00:00",
"title": "CVE-2026-88022"
},
{
"cve": "CVE-2026-88023",
"product_status": {
"known_affected": [
"T059405",
"T059404",
"T059407",
"T059406",
"T054581",
"T059409",
"T059254",
"T059396",
"74178",
"T059256",
"T059399",
"T059410",
"T059398",
"T059255",
"T059400",
"T059411",
"T059413"
]
},
"release_date": "2026-09-10T22:00:00.000+00:00",
"title": "CVE-2026-88023"
},
{
"cve": "CVE-2026-88024",
"product_status": {
"known_affected": [
"T059405",
"T059404",
"T059407",
"T059406",
"T054581",
"T059409",
"T059254",
"T059396",
"74178",
"T059256",
"T059399",
"T059410",
"T059398",
"T059255",
"T059400",
"T059411",
"T059413"
]
},
"release_date": "2026-09-10T22:00:00.000+00:00",
"title": "CVE-2026-88024"
},
{
"cve": "CVE-2026-88025",
"product_status": {
"known_affected": [
"T059405",
"T059404",
"T059407",
"T059406",
"T054581",
"T059409",
"T059254",
"T059396",
"74178",
"T059256",
"T059399",
"T059410",
"T059398",
"T059255",
"T059400",
"T059411",
"T059413"
]
},
"release_date": "2026-09-10T22:00:00.000+00:00",
"title": "CVE-2026-88025"
},
{
"cve": "CVE-2026-88026",
"product_status": {
"known_affected": [
"T059405",
"T059404",
"T059407",
"T059406",
"T054581",
"T059409",
"T059254",
"T059396",
"74178",
"T059256",
"T059399",
"T059410",
"T059398",
"T059255",
"T059400",
"T059411",
"T059413"
]
},
"release_date": "2026-09-10T22:00:00.000+00:00",
"title": "CVE-2026-88026"
},
{
"cve": "CVE-2026-88027",
"product_status": {
"known_affected": [
"T059405",
"T059404",
"T059407",
"T059406",
"T054581",
"T059409",
"T059254",
"T059396",
"74178",
"T059256",
"T059399",
"T059410",
"T059398",
"T059255",
"T059400",
"T059411",
"T059413"
]
},
"release_date": "2026-09-10T22:00:00.000+00:00",
"title": "CVE-2026-88027"
},
{
"cve": "CVE-2026-88028",
"product_status": {
"known_affected": [
"T059405",
"T059404",
"T059407",
"T059406",
"T054581",
"T059409",
"T059254",
"T059396",
"74178",
"T059256",
"T059399",
"T059410",
"T059398",
"T059255",
"T059400",
"T059411",
"T059413"
]
},
"release_date": "2026-09-10T22:00:00.000+00:00",
"title": "CVE-2026-88028"
},
{
"cve": "CVE-2026-88029",
"product_status": {
"known_affected": [
"T059405",
"T059404",
"T059407",
"T059406",
"T054581",
"T059409",
"T059254",
"T059396",
"74178",
"T059256",
"T059399",
"T059410",
"T059398",
"T059255",
"T059400",
"T059411",
"T059413"
]
},
"release_date": "2026-09-10T22:00:00.000+00:00",
"title": "CVE-2026-88029"
},
{
"cve": "CVE-2026-88030",
"product_status": {
"known_affected": [
"T059405",
"T059404",
"T059407",
"T059406",
"T054581",
"T059409",
"T059254",
"T059396",
"74178",
"T059256",
"T059399",
"T059410",
"T059398",
"T059255",
"T059400",
"T059411",
"T059413"
]
},
"release_date": "2026-09-10T22:00:00.000+00:00",
"title": "CVE-2026-88030"
},
{
"cve": "CVE-2026-88031",
"product_status": {
"known_affected": [
"T059405",
"T059404",
"T059407",
"T059406",
"T054581",
"T059409",
"T059254",
"T059396",
"74178",
"T059256",
"T059399",
"T059410",
"T059398",
"T059255",
"T059400",
"T059411",
"T059413"
]
},
"release_date": "2026-09-10T22:00:00.000+00:00",
"title": "CVE-2026-88031"
},
{
"cve": "CVE-2026-88032",
"product_status": {
"known_affected": [
"T059405",
"T059404",
"T059407",
"T059406",
"T054581",
"T059409",
"T059254",
"T059396",
"74178",
"T059256",
"T059399",
"T059410",
"T059398",
"T059255",
"T059400",
"T059411",
"T059413"
]
},
"release_date": "2026-09-10T22:00:00.000+00:00",
"title": "CVE-2026-88032"
},
{
"cve": "CVE-2026-88033",
"product_status": {
"known_affected": [
"T059405",
"T059404",
"T059407",
"T059406",
"T054581",
"T059409",
"T059254",
"T059396",
"74178",
"T059256",
"T059399",
"T059410",
"T059398",
"T059255",
"T059400",
"T059411",
"T059413"
]
},
"release_date": "2026-09-10T22:00:00.000+00:00",
"title": "CVE-2026-88033"
},
{
"cve": "CVE-2026-88034",
"product_status": {
"known_affected": [
"T059405",
"T059404",
"T059407",
"T059406",
"T054581",
"T059409",
"T059254",
"T059396",
"74178",
"T059256",
"T059399",
"T059410",
"T059398",
"T059255",
"T059400",
"T059411",
"T059413"
]
},
"release_date": "2026-09-10T22:00:00.000+00:00",
"title": "CVE-2026-88034"
},
{
"cve": "CVE-2026-88035",
"product_status": {
"known_affected": [
"T059405",
"T059404",
"T059407",
"T059406",
"T054581",
"T059409",
"T059254",
"T059396",
"74178",
"T059256",
"T059399",
"T059410",
"T059398",
"T059255",
"T059400",
"T059411",
"T059413"
]
},
"release_date": "2026-09-10T22:00:00.000+00:00",
"title": "CVE-2026-88035"
},
{
"cve": "CVE-2026-88036",
"product_status": {
"known_affected": [
"T059405",
"T059404",
"T059407",
"T059406",
"T054581",
"T059409",
"T059254",
"T059396",
"74178",
"T059256",
"T059399",
"T059410",
"T059398",
"T059255",
"T059400",
"T059411",
"T059413"
]
},
"release_date": "2026-09-10T22:00:00.000+00:00",
"title": "CVE-2026-88036"
}
]
}
Loading…
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…