CVE-2026-1046
published 2026-02-16CVE-2026-1046: Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on…
PriorityP335medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.24%
14.4th percentile
Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in the Help menu Mattermost Advisory ID: MMSA-2026-00577
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mattermost | mattermost | <= 6.2.0 | — |
| mattermost | mattermost_desktop | >= 5.13.2 < 5.13.3 | 5.13.3 |
| mattermost | mattermost_desktop | >= 6.0.0 < 6.0.3 | 6.0.3 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gjx5-j34g-5g5p: Mattermost Desktop App versions <=6
ghsa_unreviewed·2026-02-16
CVE-2026-1046 [HIGH] CWE-939 GHSA-gjx5-j34g-5g5p: Mattermost Desktop App versions <=6
Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in the Help menu Mattermost Advisory ID: MMSA-2026-00577
Red Hat
fzf: fzf: Denial of Service via inefficient HTTP body processing
vendor_redhat·2026-06-30·CVSS 5.7
CVE-2026-53433 [MEDIUM] CWE-1046 fzf: fzf: Denial of Service via inefficient HTTP body processing
fzf: fzf: Denial of Service via inefficient HTTP body processing
A flaw was found in fzf, a command-line fuzzy finder. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by sending a crafted POST request with many small segments to the `--listen` mode. The inefficient HTTP body processing, which uses repeated string concatenation, leads to quadratic time complexity, causing excessive CPU usage and blocking other clients.
Statement: A flaw was found in fzf, a command-line fuzzy finder. When fzf is running in --listen mode (a non-default, opt-in feature), inefficient HTTP body processing using repeated string concatenation results in quadratic time complexity. A crafted POST request can monopolize the single-threaded HTTP server, causing denial of service. Red H
Red Hat
net/mail: golang: net/mail: Denial of Service via pathological email address parsing
vendor_redhat·2026-05-07·CVSS 7.5
CVE-2026-42499 [HIGH] CWE-1046 net/mail: golang: net/mail: Denial of Service via pathological email address parsing
net/mail: golang: net/mail: Denial of Service via pathological email address parsing
Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
A flaw was found in the `net/mail` package within the Go standard library. A remote attacker could provide specially crafted, pathological email addresses. When these malformed email addresses are parsed by the `consumePhrase` function, it can lead to excessive resource consumption due to quadratic string concatenation, resulting in a Denial of Service (DoS) condition.
Statement: This is an Important denial of service vulnerability in the `net/mail` package of the Go standard library. A remote attacker can exploit this flaw by sending specially crafted email addresses, leading to excessive reso
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More
blogs_hackernews·2026-05-11·CVSS 9.3
CVE-2026-6973 [CRITICAL] ⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More
Rough Monday.
Somebody poisoned a trusted download again, somebody else turned cloud servers into public housing, and a few crews are still getting into boxes with bugs that should’ve died years ago — the same old holes, same lazy access paths, same “how the hell is this still open” feeling. One report this week basically reads like a guy tripped over root access by accident and decided to stay there.
The weird part is how normal this all sounds now. Fake updates. Quiet backdoors. Remote tools are used like skeleton keys. Forum rats swapping st
Wiz
CVE-2026-1628 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2026-1628 [LOW] CVE-2026-1628 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1628 :
Mattermost Desktop App vulnerability analysis and mitigation
Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Mattermost app which allows a malicious server to expose preload script functionality to untrusted servers via having a user open an external link in their Mattermost server. Mattermost Advisory ID: MMSA-2026-00596
Source : NVD
## 4.6
Score
Published March 2, 2026
Severity MEDIUM
CNA Score 4.6
Affected Technologies
Mattermost Desktop App
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:mattermost:mattermost_d
Wiz
CVE-2026-1046 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2026-1046 [LOW] CVE-2026-1046 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1046 :
Mattermost Desktop App vulnerability analysis and mitigation
Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in the Help menu Mattermost Advisory ID: MMSA-2026-00577
Source : NVD
## 6.5
Score
Published February 16, 2026
Severity MEDIUM
CNA Score 7.6
Affected Technologies
Mattermost Desktop App
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 11.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:mattermost:mattermost_desktop
Sources
Windows Severity MEDIUM Has Fix Added a
Wiz
CVE-2025-13326 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2025-13326 [LOW] CVE-2025-13326 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-13326 :
Mattermost Desktop App vulnerability analysis and mitigation
Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged for Mac App Store which allows an attacker to inherit TCC permissions via copying the binary to a tmp folder.
Source : NVD
## 3.9
Score
Published December 17, 2025
Severity LOW
CNA Score 3.9
Affected Technologies
Mattermost Desktop App
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:mattermost:mattermost_desktop
Sources
Windows Severity LOW Has Fix Added at: Dec 21, 2025
## Get a CVE risk assessment
Ge
2026-02-16
Published