VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
17,661 CVE recordsPage 14 of 1178
ReviewCritical
CVE-2026-58062

Legion of the Bouncy Castle Inc. BC-JAVA, BC-LTS-JAVA, BC-FJA

In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-58061

Legion of the Bouncy Castle Inc. BC-JAVA, BC-LTS-JAVA, BC-FJA

In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-58060

Legion of the Bouncy Castle Inc. BC-JAVA, BC-LTS-JAVA, BC-FJA

In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-58059

Legion of the Bouncy Castle Inc. BC-JAVA, BC-LTS-JAVA, BC-FJA

In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-20483

MediaTek, Inc. MediaTek chipset

In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11087526; Issue ID: MSV-8243.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-20479

MediaTek, Inc. MediaTek chipset

In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00741071; Issue ID: MSV-7620.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-20465

MediaTek, Inc. MediaTek chipset

In wlan AP driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00489200; Issue ID: MSV-7834.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-8763

Legion of the Bouncy Castle Inc. BC-JAVA, BC-LTS-JAVA, BC-FJA

In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-59649

Legion of the Bouncy Castle Inc. BC-JAVA, BC-LTS-JAVA, BC-FJA

In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-59646

Legion of the Bouncy Castle Inc. BC-JAVA, BC-LTS-JAVA, BC-FJA

In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series).

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-59645

Legion of the Bouncy Castle Inc. BC-JAVA, BC-LTS-JAVA, BC-FJA

In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcutil-fips 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).

The CVSS severity warrants an early asset and exposure review.