OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-94286

HIGH · CVSS 7.1 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

An out-of-bounds read vulnerability in the RECORD reply parser of libXtst prior to version 1.2.6 allows malicious X servers to exploit this flaw, potentially leading to crashes of connected X clients. Organizations using affected versions of libXtst should prioritize patching this vulnerability to mitigate the risk of service disruptions and ensure the stability of their X client applications.

CVE
CVE-2026-94286
Severity
HIGH
CVSS
7.1
EPSS
0.18%

Original NVD Description

An out-of-bounds read in libXtst's RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to crash attached X clients.