AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-56000

HIGH · CVSS 7.8 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

Local attackers with access to an X connection can exploit a Heap Use After Free vulnerability in the xorg-server and xwayland versions prior to 21.2.24 and 24.1.13, respectively. This flaw allows for potential arbitrary code execution, posing a significant risk to system integrity and confidentiality. Organizations using these affected versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-56000
Severity
HIGH
CVSS
7.8
EPSS
0.22%

Original NVD Description

Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.

Related CVEs

Other vulnerabilities affecting the same vendor(s)