Twelve New Vulnerabilities Disclosed in X.Org Server and XWayland
Article Content
- •Twelve new vulnerabilities disclosed in X.Org Server and XWayland.
- •Critical issues include use-after-free and buffer overflow vulnerabilities.
- •Users must update to xorg-server-21.1.25 and xwayland-24.1.14 to mitigate risks.
On October 7, 2026, the TrendAI Zero Day Initiative disclosed twelve new vulnerabilities affecting the X.Org Server and XWayland. These vulnerabilities include issues such as use-after-free and buffer overflows, which could potentially lead to arbitrary code execution or denial of service. The affected versions are prior to xorg-server-21.1.25 and xwayland-24.1.14. Specific CVEs include CVE-2026-88812, CVE-2026-93515, and CVE-2026-93516, among others. The vulnerabilities were found in various components of the X server, indicating a persistent security risk in the codebase. Security fixes have been released, and users are urged to update their systems immediately to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-88812 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What are the specific CVEs associated with these vulnerabilities?
What versions need to be updated?
Are these vulnerabilities currently being exploited?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…