Cwe-416 - Use After Free is a cwe tracked across 50 threat clusters and 178 intelligence report mentions on ThreatCluster. First observed April 17, 2026; most recent activity July 23, 2026.
Active exploitation of two critical vulnerabilities has been reported: CVE-2026-20230 in Cisco Unified CM and CVE-2026-20971 in Samsung KNOX. The Cisco flaw, a server-side request forgery (SSRF), poses an immediate…
On June 17, 2026, F5 released emergency patches for two critical vulnerabilities in NGINX, CVE-2026-42530 and CVE-2026-42055. These vulnerabilities affect NGINX Open Source, NGINX Plus, and related products, allowing…
A newly disclosed Linux kernel vulnerability, named Bad Epoll (CVE-2026-46242), allows unprivileged local users to escalate to root privileges on systems running kernel version 6.4 or later. This use-after-free…
Oracle has released important security updates for PHP versions 7.4 and 8.0, addressing multiple vulnerabilities including critical cross-site scripting (XSS) flaws and memory management issues. The updates fix…
Recent security updates for Python 3.10, 3.12, and 3.15 address critical vulnerabilities impacting various systems. Key vulnerabilities include CVE-2026-1502, which allows HTTP header injection, and CVE-2026-6100, which…
A critical vulnerability in Linux KVM, named Januscape (CVE-2026-53359), has been discovered after lying dormant for 16 years. This flaw allows attackers with root access in a guest virtual machine to escape to the host…
Multiple critical vulnerabilities have been identified in the freerdp component of openSUSE, affecting versions 15.4 and 15.6. The vulnerabilities include CVE-2026-25941, CVE-2026-25942, CVE-2026-25952, CVE-2026-25953,…
Recent updates for Fedora's OpenSSH and libssh libraries address critical vulnerabilities. CVE-2026-59996 and CVE-2026-60002, published on July 8, 2026, involve file misplacement and use-after-free issues in OpenSSH.…
F5 disclosed a critical vulnerability in NGINX, identified as CVE-2026-42533, which can lead to remote code execution (RCE) and denial-of-service (DoS) attacks. The flaw is a heap buffer overflow triggered by crafted…
Oracle has disclosed a critical security vulnerability in the ptrace functionality of its Linux kernels, identified as CVE-2026-46333. This vulnerability affects multiple versions of Oracle Linux, including Oracle Linux…