Skip to content

CVE-2026-42246

CVE

Threat entity extracted from intelligence sources

Frequency
7
occurrences
First Seen
June 15, 2026
Last Seen
October 1, 2026
API
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

Two critical vulnerabilities were discovered in Ruby's Net::IMAP library affecting Ubuntu 18.04 and 16.04 LTS. CVE-2026-42246 allows remote attackers to perform machine-in-the-middle attacks by bypassing TLS encryption. CVE-2026-42257 enables attackers to inject arbitrary IMAP commands due to improp...

Recent updates for Oracle Linux address critical vulnerabilities in Ruby affecting versions 2.5, 3.3, and 4.0. Key issues include a code execution flaw (CVE-2026-41316) and denial of service vulnerabilities (CVE-2026-42245, CVE-2026-33210) that could be exploited via crafted IMAP responses and forma...

On October 1, 2026, Oracle released security updates for Ruby in Oracle Linux 9 and 10, addressing multiple memory exhaustion vulnerabilities. The most significant flaw, CVE-2026-80212, affects Ruby versions 3.0.7 and 4.0.6, allowing for potential denial of service through unknown DNS resource types...

Public Exploits

Checking GitHub for proof-of-concept code…