← Back to the live CVE advisory feed

CVE-2026-107838: Product identification pending

Severity
7.5 (HIGH)
Patch status
Unknown
Published
2026-10-09T18:17:05.640
Modified
2026-10-09T18:17:05.640

Why it matters

This matters because the issue affects identity or token handling. Successful exploitation could allow unauthorized authentication, client manipulation, or access to protected services.

Recommended admin actions

  • Review and patch based on exposure, asset criticality, and business impact.
  • Compare installed versions against the affected version range in the advisory.
  • Treat internet-facing systems as higher priority.
  • Review logs for suspicious activity related to the affected application or component.

Technical summary

RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. From version 2023.07 through version 2026.07, nanocoap_fileserver callers in sys/net/application_layer/nanocoap/fileserver.c ignore a failure returned by _resp_init() when coap_build_reply() cannot fit a response header into the response buffer. A remote client can send a CoAP request with a sufficiently large extended token when nanocoap_token_ext is enabled, causing response initialization to fail while _get_file() or _get_directory() continues with stale response state. The path then reaches _calc_szx2() and its pdu->payload_len > reserve assertion, terminating the affected service or device task. No fixed release is available as of this review.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: OCT 10, 2026 04:00 PM UTC
275 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-108263
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.9
CRITICAL
VIEW RECORD
CVE-2026-108474
Product identification pending PATCH
Reporter: CVE
9.8
CRITICAL
VIEW RECORD
CVE-2026-104732
Advanced IP Blocker
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-94589
Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection)
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-103889
3D Product configurator for WooCommerce
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-104803
WPCOM Member
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-62045
Booklovers
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-62046
Gutentype
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93927
Veto
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93929
Travesia
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93930
Tantra
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93931
Smash
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93932
Smart Casa
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93933
Rosalinda
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93934
Partiso
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93935
Let's Play
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93936
IPharm
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93937
Hygia
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93938
Hogwords
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93940
Greeny
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93941
Edema
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93942
Dwell
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93943
Convex
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93944
Camelia
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93945
Balance
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-107824
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-107845
contao PATCH
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-108261
tinacms PATCH
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-108551
openapi-typescript-codegen
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-108157
Product identification pending PATCH
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-108549
Product identification pending
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-108264
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-108265
enclave-os-mini PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-108266
rustls PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-108267
go PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-108268
enclave-os-virtual PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-108269
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-107645
Blocksy Companion
Reporter: SECURITY
9.1
CRITICAL
VIEW RECORD
CVE-2026-97670
Avada (Fusion) Builder
Reporter: SECURITY
9.1
CRITICAL
VIEW RECORD
CVE-2026-104801
PPOM – Product Addons & Custom Fields for WooCommerce
Reporter: SECURITY
9.1
CRITICAL
VIEW RECORD
CVE-2026-107807
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-107809
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-107811
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-107813
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-55797
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-104723
LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-104725
Groundhogg — CRM, Newsletters, and Marketing Automation
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-104766
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-77183
FooSales – Point of Sale (POS) for WooCommerce
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-83526
FV Player 8
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-87780
Product identification pending PATCH
Reporter: CONTACT
8.8
HIGH
VIEW RECORD
CVE-2026-105885
Product identification pending
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-104084
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-108113
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-108550
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-104082
Product identification pending
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-87781
Product identification pending PATCH
Reporter: CONTACT
8.6
HIGH
VIEW RECORD
CVE-2026-107815
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.5
HIGH
VIEW RECORD
CVE-2026-107814
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.4
HIGH
VIEW RECORD
CVE-2026-107818
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.4
HIGH
VIEW RECORD
CVE-2026-101947
Product identification pending
Reporter: HELP
8.4
HIGH
VIEW RECORD
CVE-2026-102554
Product identification pending
Reporter: CVE-COORDINATION
8.2
HIGH
VIEW RECORD
CVE-2026-90983
Product identification pending PATCH
Reporter: ILETISIM
8.2
HIGH
VIEW RECORD
CVE-2026-107837
Product identification pending
Reporter: SECURITY-ADVISORIES
8.2
HIGH
VIEW RECORD
CVE-2026-108259
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.2
HIGH
VIEW RECORD
CVE-2026-22061
Product identification pending
Reporter: SECURITY-ALERT
8.2
HIGH
VIEW RECORD
CVE-2026-108545
Product identification pending
Reporter: DISCLOSURE
8.2
HIGH
VIEW RECORD
CVE-2026-107808
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-107810
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-57458
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-62376
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-104797
Advanced Form Integration — Connect Forms to 300+ Apps
Reporter: SECURITY
8.1
HIGH
VIEW RECORD
CVE-2026-104899
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
Reporter: SECURITY
8.1
HIGH
VIEW RECORD
CVE-2026-92975
Groundhogg — CRM, Newsletters, and Marketing Automation
Reporter: SECURITY
8.1
HIGH
VIEW RECORD
CVE-2026-94256
Product identification pending PATCH
Reporter: CONTACT
8.1
HIGH
VIEW RECORD
CVE-2026-94257
Product identification pending PATCH
Reporter: CONTACT
8.1
HIGH
VIEW RECORD
CVE-2026-94538
WP File Download
Reporter: SECURITY
8.1
HIGH
VIEW RECORD
CVE-2026-104759
WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN)
Reporter: SECURITY
8.1
HIGH
VIEW RECORD
CVE-2026-107821
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8
HIGH
VIEW RECORD
CVE-2026-92705
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.8
HIGH
VIEW RECORD
CVE-2026-108159
Product identification pending
Reporter: DISCLOSURE
7.7
HIGH
VIEW RECORD
CVE-2026-108160
Product identification pending
Reporter: DISCLOSURE
7.7
HIGH
VIEW RECORD
CVE-2026-108161
Product identification pending
Reporter: DISCLOSURE
7.7
HIGH
VIEW RECORD
CVE-2026-108546
Product identification pending
Reporter: DISCLOSURE
7.7
HIGH
VIEW RECORD
CVE-2026-108553
Product identification pending
Reporter: DISCLOSURE
7.7
HIGH
VIEW RECORD
CVE-2026-108110
Product identification pending
Reporter: DISCLOSURE
7.6
HIGH
VIEW RECORD
CVE-2026-108260
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.6
HIGH
VIEW RECORD
CVE-2026-107812
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-75345
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-75346
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-75348
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-75349
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-75347
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-107826
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-107838
Product identification pending
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-107839
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-107840
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-75350
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-75351
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-62367
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.