SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86314

MEDIUM · CVSS 6.2 EPSS 0.13% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

An integer overflow vulnerability in the Memory::init() function of F5's Walrus allows remote attackers to exploit crafted WebAssembly modules, leading to out-of-bounds heap reads and potential denial of service. Organizations utilizing affected versions of Walrus should prioritize patching this vulnerability to mitigate risks associated with remote exploitation and service disruption.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86314
Severity
MEDIUM
CVSS
6.2
EPSS
0.13%
F5

Original NVD Description

Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds heap read and denial of service via a crafted WebAssembly module in which a 32-bit unsigned addition wraps around and bypasses the bounds check. This issue affects Walrus: ff3bf5ff5c4878f8e5572c9593d303f6bc997443.