Skip to content

CVE-2025-67726

CVE

Threat entity extracted from intelligence sources

Frequency
12
occurrences
First Seen
January 5, 2026
Last Seen
February 26, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

Tornado, a web server and tools package, has critical vulnerabilities affecting multiple Ubuntu versions including 20.04 LTS, 22.04 LTS, 24.04 LTS, 25.04, and 25.10. The vulnerabilities allow attackers to execute cross-site scripting (XSS) attacks and potentially cause denial of service (DoS) by exp...

SUSE has released updates addressing a critical buffer overflow vulnerability (CVE-2026-25506) in the munge package, affecting multiple SUSE Linux versions. The vulnerability, which was published on February 10, 2026, could allow for potential exploitation if not patched. Users are advised to apply...

SUSE and Ubuntu have released updates for python-tornado6 to address multiple vulnerabilities, including CVE-2025-67724, which allows for header injection or XSS attacks, and CVE-2025-67725, which can lead to a Denial of Service (DoS) due to quadratic complexity in string operations. These vulnerabi...

openSUSE has released an advisory regarding critical vulnerabilities in python-tornado6 affecting HTTP headers and error pages. The vulnerabilities include potential header injection and XSS attacks (CVE-2025-67724) and a DoS risk due to quadratic complexity in string operations (CVE-2025-67725). Us...

Public Exploits

Checking GitHub for proof-of-concept code…

Related Articles (12)

1 / 3