CVE-2026-1036
published 2026-01-22CVE-2026-1036: The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability…
PriorityP433medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.25%
16.6th percentile
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_comment() function in all versions up to, and including, 1.8.36. This makes it possible for unauthenticated attackers to delete arbitrary image comments. Note: comments functionality is only available in the Pro version of the plugin.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| 10web | photo_gallery_by_10web_mobile-friendly_image_gallery | <= 1.8.36 | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fj27-mvcr-jjvm: The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca
ghsa_unreviewed·2026-01-22
CVE-2026-1036 [MEDIUM] CWE-862 GHSA-fj27-mvcr-jjvm: The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_comment() function in all versions up to, and including, 1.8.36. This makes it possible for unauthenticated attackers to delete arbitrary image comments. Note: comments functionality is only available in the Pro version of the plugin.
Red Hat
kernel: net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone
vendor_redhat·2026-08-28·CVSS 8.2
CVE-2026-80615 [HIGH] CWE-787 kernel: net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone
kernel: net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone
In the Linux kernel, the following vulnerability has been resolved:
net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone
kmalloc_flex() in metadata_dst_alloc() sets __counted_by for the
structure to the options_len, which is then initialized to zero.
Later, we're initializing the structure by copying the tunnel info
together with the options, and this triggers a warning for a potential
memcpy overflow, since the compiler estimates that the options can't
fit into the structure, even though the memory for them is actually
allocated.
memcpy: detected buffer overflow: 104 byte write of buffer size 96
WARNING: CPU: X PID: Y at lib/string_helpers.c:1036 __fortify_report
skb_tunnel_info_unclone+0
Red Hat
kernel: cxl/test: Fix __fortify_panic
vendor_redhat·2026-08-28·CVSS 5.5
CVE-2026-80639 [LOW] CWE-805 kernel: cxl/test: Fix __fortify_panic
kernel: cxl/test: Fix __fortify_panic
In the Linux kernel, the following vulnerability has been resolved:
cxl/test: Fix __fortify_panic
Fix a runtime assertion in setup_xor_mapping(). Fortify complains that it
is potentially overflowing the xormaps array per __counted_by(nr_maps).
Quiet the false positive by initializing @nr_maps earlier.
memcpy: detected buffer overflow: 32 byte write of buffer size 0
WARNING: lib/string_helpers.c:1036 at __fortify_report+0x4d/0xa0, CPU#8: modprobe/2728
Call Trace:
__fortify_panic+0xd/0xf
setup_xor_mapping+0x6c/0xa0 [cxl_translate]
[ dj: Fixed up @nr_entries to @nr_maps in commit log. ]
A flaw was found in the Linux kernel's `cxl/test` module. A buffer overflow vulnerability, a type of memory corruption, exists within the `setup_xor_mapping()` function.
Red Hat
kernel: cxl/fwctl: Fix __fortify_panic
vendor_redhat·2026-08-28·CVSS 5.5
CVE-2026-80640 [LOW] CWE-120 kernel: cxl/fwctl: Fix __fortify_panic
kernel: cxl/fwctl: Fix __fortify_panic
In the Linux kernel, the following vulnerability has been resolved:
cxl/fwctl: Fix __fortify_panic
Fix a runtime assertion in cxlctl_get_supported_features(). Fortify
complains that it is potentially overflowing the entries array per
__counted_by_le(num_entries). Quiet the false positive by initializing
@num_entries earlier.
memcpy: detected buffer overflow: 48 byte write of buffer size 0
WARNING: lib/string_helpers.c:1036 at __fortify_report+0x4d/0xa0, CPU#7: fwctl/1398
RIP: 0010:__fortify_report+0x50/0xa0
Call Trace:
__fortify_panic+0xd/0xf
cxlctl_get_supported_features.cold+0x23/0x35 [cxl_core]
A flaw was found in the Linux kernel's CXL subsystem firmware control (`cxl/fwctl`). A buffer overflow vulnerability exists in the `cxlctl_get_supported_f
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-1036 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2026-1036 [CRITICAL] CVE-2026-1036 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1036 :
WordPress vulnerability analysis and mitigation
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_comment() function in all versions up to, and including, 1.8.36. This makes it possible for unauthenticated attackers to delete arbitrary image comments. Note: comments functionality is only available in the Pro version of the plugin.
Source : NVD
## 5.3
Score
Published January 22, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
WordPress
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 29
Exploitation Probability (EPSS) 0.1
Affected
Bugzilla
CVE-2026-80640 kernel: cxl/fwctl: Fix __fortify_panic
bugzilla·2026-08-28
CVE-2026-80640 [LOW] CVE-2026-80640 kernel: cxl/fwctl: Fix __fortify_panic
CVE-2026-80640 kernel: cxl/fwctl: Fix __fortify_panic
In the Linux kernel, the following vulnerability has been resolved:
cxl/fwctl: Fix __fortify_panic
Fix a runtime assertion in cxlctl_get_supported_features(). Fortify
complains that it is potentially overflowing the entries array per
__counted_by_le(num_entries). Quiet the false positive by initializing
@num_entries earlier.
memcpy: detected buffer overflow: 48 byte write of buffer size 0
WARNING: lib/string_helpers.c:1036 at __fortify_report+0x4d/0xa0, CPU#7: fwctl/1398
RIP: 0010:__fortify_report+0x50/0xa0
Call Trace:
__fortify_panic+0xd/0xf
cxlctl_get_supported_features.cold+0x23/0x35 [cxl_core]
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026082841-CVE-2026-80640-36d9@gregkh/T
Bugzilla
CVE-2026-80639 kernel: cxl/test: Fix __fortify_panic
bugzilla·2026-08-28
CVE-2026-80639 [LOW] CVE-2026-80639 kernel: cxl/test: Fix __fortify_panic
CVE-2026-80639 kernel: cxl/test: Fix __fortify_panic
In the Linux kernel, the following vulnerability has been resolved:
cxl/test: Fix __fortify_panic
Fix a runtime assertion in setup_xor_mapping(). Fortify complains that it
is potentially overflowing the xormaps array per __counted_by(nr_maps).
Quiet the false positive by initializing @nr_maps earlier.
memcpy: detected buffer overflow: 32 byte write of buffer size 0
WARNING: lib/string_helpers.c:1036 at __fortify_report+0x4d/0xa0, CPU#8: modprobe/2728
Call Trace:
__fortify_panic+0xd/0xf
setup_xor_mapping+0x6c/0xa0 [cxl_translate]
[ dj: Fixed up @nr_entries to @nr_maps in commit log. ]
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026082840-CVE-2026-80639-9559@gregkh/T
Bugzilla
CVE-2026-80615 kernel: net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone
bugzilla·2026-08-28·CVSS 8.2
CVE-2026-80615 [HIGH] CVE-2026-80615 kernel: net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone
CVE-2026-80615 kernel: net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone
In the Linux kernel, the following vulnerability has been resolved:
net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone
kmalloc_flex() in metadata_dst_alloc() sets __counted_by for the
structure to the options_len, which is then initialized to zero.
Later, we're initializing the structure by copying the tunnel info
together with the options, and this triggers a warning for a potential
memcpy overflow, since the compiler estimates that the options can't
fit into the structure, even though the memory for them is actually
allocated.
memcpy: detected buffer overflow: 104 byte write of buffer size 96
WARNING: CPU: X PID: Y at lib/string_helpers.c:1036 __fortify_report
skb_tun
2026-01-22
Published