CVE-2026-2009
published 2026-02-06CVE-2026-2009: A flaw has been found in SourceCodester Gas Agency Management System 1.0. This issue affects some unknown processing of the file…
PriorityP340medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.26%
18.2th percentile
A flaw has been found in SourceCodester Gas Agency Management System 1.0. This issue affects some unknown processing of the file /gasmark/php_action/createUser.php. Executing a manipulation can lead to improper access controls. It is possible to launch the attack remotely. The exploit has been published and may be used.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mayurik | gas_agency_management_system | — | — |
| sourcecodester | gas_agency_management_system | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv4.02.1LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
cisa8.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p967-c764-24hr: A flaw has been found in SourceCodester Gas Agency Management System 1
ghsa_unreviewed·2026-02-06
CVE-2026-2009 [MEDIUM] CWE-266 GHSA-p967-c764-24hr: A flaw has been found in SourceCodester Gas Agency Management System 1
A flaw has been found in SourceCodester Gas Agency Management System 1.0. This issue affects some unknown processing of the file /gasmark/php_action/createUser.php. Executing a manipulation can lead to improper access controls. It is possible to launch the attack remotely. The exploit has been published and may be used.
CISA
Microsoft DirectX NULL Byte Overwrite Vulnerability
cisa·2026-05-20·CVSS 8.8
CVE-2009-1537 [HIGH] Microsoft DirectX NULL Byte Overwrite Vulnerability
Vulnerability: Microsoft DirectX NULL Byte Overwrite Vulnerability
Affected: Microsoft DirectX
Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://learn.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-028 ; https://nvd.nist.gov/vuln/detail/CVE-2009-1537
Remediation Due Date: 2026-06-03
Citrix
Citrix Security Bulletin CTX118770
vendor_citrix·CVSS 6.5
CVE-2009-2213 [MEDIUM] Citrix Security Bulletin CTX118770
Citrix Security Bulletin CTX118770
CVE References: CVE-2009-2213, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX121172
vendor_citrix·CVSS 5.0
CVE-2009-2214 [MEDIUM] Citrix Security Bulletin CTX121172
Citrix Security Bulletin CTX121172
CVE References: CVE-2009-2214, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX120742
vendor_citrix·CVSS 10.0
CVE-2009-2452 [CRITICAL] Citrix Security Bulletin CTX120742
Citrix Security Bulletin CTX120742
CVE References: CVE-2009-2452, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-72284 kernel: KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs
bugzilla·2026-08-15·CVSS 7.1
CVE-2026-72284 [HIGH] CVE-2026-72284 kernel: KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs
CVE-2026-72284 kernel: KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs
In the Linux kernel, the following vulnerability has been resolved:
KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs
Ignore KVM's internal "service pending PV EOI" request if the vCPU has
disabled PV EOIs since the request was made. Asserting that PV EOIs are
enabled can fail if reading guest memory in pv_eoi_get_user() fails, i.e.
if pv_eoi_test_and_clr_pending() bails early, *and* the vCPU also disables
PV EOIs.
kernel BUG at arch/x86/kvm/lapic.c:3338!
Oops: invalid opcode: 0000 [#1] SMP
CPU: 4 UID: 1000 PID: 890 Comm: pv_eoi_test Not tainted 7.0.0-d585aa5894d8-vm #337 PREEMPT
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015
RIP: 0010:kvm_lapic_
Bugzilla
CVE-2026-31510 kernel: Bluetooth: L2CAP: Fix null-ptr-deref on l2cap_sock_ready_cb
bugzilla·2026-04-22
CVE-2026-31510 [MEDIUM] CVE-2026-31510 kernel: Bluetooth: L2CAP: Fix null-ptr-deref on l2cap_sock_ready_cb
CVE-2026-31510 kernel: Bluetooth: L2CAP: Fix null-ptr-deref on l2cap_sock_ready_cb
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: L2CAP: Fix null-ptr-deref on l2cap_sock_ready_cb
Before using sk pointer, check if it is null.
Fix the following:
KASAN: null-ptr-deref in range [0x0000000000000260-0x0000000000000267]
CPU: 0 UID: 0 PID: 5985 Comm: kworker/0:5 Not tainted 7.0.0-rc4-00029-ga989fde763f4 #1 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.17.0-9.fc43 06/10/2025
Workqueue: events l2cap_info_timeout
RIP: 0010:kasan_byte_accessible+0x12/0x30
Code: 79 ff ff ff 0f 1f 40 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 0f 1f 40 d6 48 c1 ef 03 48 b8 00 00 00 00 00 fc ff df b6 04 07 3c 08 0f 92 c0 c3 cc cce
veth0_macvtap: enter
2026-02-06
Published