SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-49035

HIGH · CVSS 8.1 EPSS 0.37% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The vulnerability allows for a heap-based buffer overflow through a crafted MMS Initiate request, potentially leading to remote code execution if Address Space Layout Randomization (ASLR) is disabled. In environments where ASLR is enabled, the exploit may result in memory corruption or denial of service. Organizations using the affected products should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-49035
Severity
HIGH
CVSS
8.1
EPSS
0.37%

Original NVD Description

The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execution (RCE) has been demonstrated when ASLR is disabled; memory corruption or denial of service may occur in configurations where ASLR is enabled.