SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-21095

CRITICAL · CVSS 9.8 EPSS 0.46%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

A heap-based buffer overflow vulnerability in the DNG decoder of libimagecodec.quram.so prior to the SMR Sep-2026 Release 1 enables remote attackers to execute arbitrary code on affected systems. Organizations utilizing this library should prioritize patching to mitigate the risk of exploitation, given the critical severity rating of 9.2. Immediate action is essential for those managing applications that rely on this component to safeguard against potential remote attacks.

CVE
CVE-2026-21095
Severity
CRITICAL
CVSS
9.8
EPSS
0.46%

Original NVD Description

Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

Related CVEs

Other vulnerabilities affecting the same vendor(s)