SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-21088

HIGH · CVSS 7.8 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Improper input validation in the subtitle frame loading process of libsubextractor.so prior to the SMR Sep-2026 Release 1 allows local attackers to exploit this vulnerability, potentially leading to out-of-bounds memory writes. This could result in application crashes or arbitrary code execution, making it critical for organizations using affected versions to prioritize patching. Local users with access to the system should be particularly vigilant, as they can leverage this flaw to escalate privileges or compromise system integrity.

CVE
CVE-2026-21088
Severity
HIGH
CVSS
7.8
EPSS
0.11%

Original NVD Description

Improper input validation in loading a subtitle frame in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

Related CVEs

Other vulnerabilities affecting the same vendor(s)