OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-88807

HIGH · CVSS 8.9 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

A heap overflow vulnerability in libXrender prior to version 0.9.13 allows malicious X servers to exploit the RenderQueryPictFormats function, potentially enabling code injection into connected X clients. This poses a significant risk as it could lead to unauthorized access and control over affected systems. Organizations utilizing libXrender in their environments should prioritize patching to mitigate this high-severity threat.

CVE
CVE-2026-88807
Severity
HIGH
CVSS
8.9
EPSS
0.26%

Original NVD Description

A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients.