SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-85509

CRITICAL · CVSS 9.8 EPSS 0.39%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A stack-based buffer overflow vulnerability exists in FreeIPMI versions prior to 1.6.19, specifically in the _read_fru_data function, which can be exploited when a Baseboard Management Controller (BMC) returns more data than expected. This critical flaw (CVSS 9.8) could allow an attacker to execute arbitrary code, potentially compromising the affected system. Organizations utilizing FreeIPMI should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-85509
Severity
CRITICAL
CVSS
9.8
EPSS
0.39%

Original NVD Description

FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.