SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-76014

LOW · CVSS 3.3 EPSS 0.12% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A null pointer dereference vulnerability exists in the FEATURE_WGET_TIMEOUT handler of BusyBox versions up to 1.30.1, which can be triggered by manipulating the -T argument. This flaw requires local access to exploit and could lead to application crashes or denial of service. Users and administrators of affected BusyBox installations should prioritize applying the provided patch to mitigate potential risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76014
Severity
LOW
CVSS
3.3
EPSS
0.12%

Original NVD Description

A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of the file networking/wget.c of the component FEATURE_WGET_TIMEOUT Handler. Such manipulation of the argument -T leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is 83a40bf7a93c8ac093d33ab452222dd5b9eb57ff. A patch should be applied to remediate this issue.