CVE-2026-0076
published 2026-06-01CVE-2026-0076: In validateNode of ResourceTypes.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege…
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.08%
0.2th percentile
In validateNode of ResourceTypes.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In validateNode of ResourceTypes.cpp, there is a possible out of bounds read due to an incorrect bounds check.
ghsa_unreviewed·2026-06-02
CVE-2026-0076 [MEDIUM] CWE-125 In validateNode of ResourceTypes.cpp, there is a possible out of bounds read due to an incorrect bounds check.
In validateNode of ResourceTypes.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Red Hat
vim: Vim: Information disclosure and denial of service via crafted Unicode characters in terminal emulator
vendor_redhat·2026-02-27·CVSS 4.4
CVE-2026-28420 [MEDIUM] CWE-125 vim: Vim: Information disclosure and denial of service via crafted Unicode characters in terminal emulator
vim: Vim: Information disclosure and denial of service via crafted Unicode characters in terminal emulator
Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when processing maximum combining characters from Unicode supplementary planes. Version 9.2.0076 fixes the issue.
A flaw was found in Vim. A remote attacker could exploit a heap-based buffer overflow and an out-of-bounds read vulnerability in Vim's terminal emulator. This occurs when processing specially crafted Unicode supplementary plane characters, potentially leading to information disclosure and denial of service.
Mitigation: Mitigation for this issue is either not available or the currently available options
No detection rules found.
No public exploits indexed.
Wiz
RUSTSEC-2026-0076 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
[HIGH] RUSTSEC-2026-0076 Impact, Exploitability, and Mitigation Steps | Wiz
## RUSTSEC-2026-0076 :
Rust vulnerability analysis and mitigation
HintBitUnpack
## Impact
A manipulated invalid hint can cause an out-of-bounds memory access
since the hint decoding logic may attempt to read outside the bounds
of the serialized signature, causing a runtime panic.
## Mitigation
0.0.8
Source : NVD
## 8.7
Score
Published March 4, 2026
Severity HIGH
CNA Score N/A
Affected Technologies
Rust
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libcrux-ml-dsa
Sources
NVD
Rust Has Fix Added at: Mar 24, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can fo
Wiz
CVE-2026-28420 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.4
CVE-2026-28420 [MEDIUM] CVE-2026-28420 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28420 :
Vim vulnerability analysis and mitigation
Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when processing maximum combining characters from Unicode supplementary planes. Version 9.2.0076 fixes the issue.
Source : NVD
## 4.4
Score
Published February 27, 2026
Severity MEDIUM
CNA Score 4.4
Affected Technologies
Vim
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
vim-common
vim-minimal
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.
Bugzilla
CVE-2026-28420 vim: Vim: Information disclosure and denial of service via crafted Unicode characters in terminal emulator
bugzilla·2026-02-27·CVSS 4.4
CVE-2026-28420 [MEDIUM] CVE-2026-28420 vim: Vim: Information disclosure and denial of service via crafted Unicode characters in terminal emulator
CVE-2026-28420 vim: Vim: Information disclosure and denial of service via crafted Unicode characters in terminal emulator
Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when processing maximum combining characters from Unicode supplementary planes. Version 9.2.0076 fixes the issue.
2026-06-01
Published