BlackTreeCVE IntelligenceMicrosoft · MSRC-2026-09-other-https-learn-microsoft-com-en-us-azure-azure-linux-tutorial-azure-linux-upgrade
Linked CVE review
Deploy Microsoft Other update for 21495-17084
- Linked CVEs
- 6
- Confirmed exploited
- 0
- PoC or lab evidence
- 2
- Maximum CVSS
- 6.9
Confirmed exploitation, public exploit material, EPSS probability and CVSS severity answer different questions. “No confirmation recorded” means the checked sources do not currently confirm exploitation. It is not proof that exploitation has not occurred.
| CVE and description | Severity | Exploit reality | Forecast and access | Remediation |
|---|---|---|---|---|
CVE-2026-86137 PoC or lab evidence In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexpIn libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp. | 2.9 · CVSS 3.1 · LowSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.Public exploit referencedA structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised. | EPSS: 0.19% · 8.4th percentileForecast date: 2026-10-08LOCAL · HIGH complexity · NONE privileges · NONE user interaction | Within 7 daysLow technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.Patch available. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ |
CVE-2026-86143 PoC or lab evidence xmlsoft libxml2: Integer Coercion ErrorIn xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback. | 6.9 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.Public exploit referencedA structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised. | EPSS: 0.19% · 8.3th percentileForecast date: 2026-10-08LOCAL · HIGH complexity · NONE privileges · NONE user interaction | Within 7 daysMedium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.Patch available. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 |
CVE-2026-86144 Scheduled assessment xmlsoft libxml2: Incorrect Resource Transfer Between SpheresIn xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow). | 5.6 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.19% · 7.6th percentileForecast date: 2026-10-08LOCAL · HIGH complexity · NONE privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 |
CVE-2026-86139 Scheduled assessment In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflowIn libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow. | 6.9 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.17% · 5.3th percentileForecast date: 2026-10-08LOCAL · HIGH complexity · NONE privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ |
CVE-2026-86141 Scheduled assessment xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checkingxmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking. | 2.9 · CVSS 3.1 · LowSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.17% · 5.3th percentileForecast date: 2026-10-08LOCAL · HIGH complexity · NONE privileges · NONE user interaction | ScheduledLow technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ |
CVE-2026-86138 Scheduled assessment In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflowIn libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow. | 6.9 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.13% · 2.4th percentileForecast date: 2026-10-08LOCAL · HIGH complexity · NONE privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 |