← Back to the live CVE advisory feed

CVE-2026-19570: Product identification pending

Severity
8.8 (HIGH)
Vendor
ZEPHYRPROJECT
Patch status
Unknown
Published
2026-10-09T08:16:54.693
Modified
2026-10-09T08:16:54.693

Why it matters

This matters because the affected product may allow code execution. Prioritize systems that are internet-facing or have privileged access to other infrastructure.

Recommended admin actions

  • Review and patch based on exposure, asset criticality, and business impact.
  • Treat internet-facing systems as higher priority.
  • Review logs for suspicious activity related to the affected application or component.

Technical summary

The LE Audio Broadcast Sink in subsys/bluetooth/audio/bap_broadcast_sink.c copies subgroup metadata from a received Basic Audio Announcement (BASE) into the static Broadcast Audio Scan Service parameter structure mod_src_param without any bounds check. In base_subgroup_meta_cb() the destination element was selected as mod_src_param.subgroups[mod_src_param.num_subgroups] with no test against ARRAY_SIZE(mod_src_param.subgroups) (sized by CONFIG_BT_BAP_BASS_MAX_SUBGROUPS, default 1), and the metadata was copied with memcpy() using the raw on-air length returned by bt_bap_base_get_subgroup_codec_meta() into a metadata array sized by CONFIG_BT_AUDIO_CODEC_CFG_MAX_METADATA_SIZE (default 4). The BASE validator bt_bap_base_get_base_from_ad() only checks structural consistency and permits up to ~24 subgroups and metadata LTVs of ~240 octets. The defect is reached from the periodic advertising receive callback: pa_recv() → bt_data_parse() → pa_decode_base() → update_recv_state_base() → bt_bap_base_foreach_subgroup() → base_subgroup_meta_cb(). Every broadcast sink registers a scan-delegator receive state at creation (bt_bap_broadcast_sink_create() calls broadcast_sink_add_src()), and CONFIG_BT_BAP_BROADCAST_SINK depends on CONFIG_BT_BAP_SCAN_DELEGATOR, so the path is active in every broadcast-sink build once the device is periodic-advertising-synced. An attacker in radio range who operates a broadcast source the device syncs to — or who impersonates the advertiser address and SID of one already in use, periodic advertising data being unauthenticated — can change the BASE at will; each new BASE is re-parsed. A crafted BASE therefore writes attacker-chosen bytes past the end of a fixed static object in .bss: up to roughly 236 bytes for an oversized metadata LTV, plus whole struct bt_bap_bass_subgroup records for each subgroup beyond CONFIG_BT_BAP_BASS_MAX_SUBGROUPS. This is memory corruption of adjacent Bluetooth-audio state reachable with no pairing, bonding or GATT connection, with a potential for remote code execution in the Bluetooth RX thread; in addition, the unvalidated metadata_len is forwarded to bt_bap_scan_delegator_mod_src(), which neither clamps it nor rejects it, leading to a further copy into the receive state and to out-of-bounds memory being disclosed in the BASS receive-state notification sent to a connected Broadcast Assistant. The fix rejects a BASE carrying more subgroups than the receive state can hold (discarding the update entirely) and omits metadata that does not fit rather than copying it, and additionally honours the previously-ignored error return of the subgroup decode pass.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: OCT 09, 2026 12:00 PM UTC
515 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-96207
Microsoft Partner Center
Reporter: SECURE
10
CRITICAL
VIEW RECORD
CVE-2026-94503
Zombify
Reporter: AUDIT
10
CRITICAL
VIEW RECORD
CVE-2026-94510
Microsoft Bookings
Reporter: SECURE
9.9
CRITICAL
VIEW RECORD
CVE-2026-92555
Product identification pending PATCH
Reporter: ILETISIM
9.8
CRITICAL
VIEW RECORD
CVE-2026-16340
Product identification pending
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-14991
Product identification pending
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-15762
Product identification pending
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-14269
Product identification pending
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-14502
DataPower Gateway 10.6CD
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-14992
Product identification pending
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93034
SGLang
Reporter: CRET
9.8
CRITICAL
VIEW RECORD
CVE-2026-84272
Guardium Data Protection
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-78401
Product identification pending
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-78406
Product identification pending
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-107722
fast-jwt PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-75875
Guardium Data Protection
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-80381
Guardium Data Protection
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-84249
Guardium Data Protection
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-77900
Azure App Service for Linux
Reporter: SECURE
9.8
CRITICAL
VIEW RECORD
CVE-2026-88131
Microsoft Dataverse
Reporter: SECURE
9.8
CRITICAL
VIEW RECORD
CVE-2026-69435
Azure SRE Agent
Reporter: SECURE
9.6
CRITICAL
VIEW RECORD
CVE-2026-107406
ADC PATCH
Reporter: 50A63C94-1EA7-4568-8C11-EB79E7C5A2B5
9.5
CRITICAL
VIEW RECORD
CVE-2026-103663
Ollama PATCH
Reporter: CVD
9.4
CRITICAL
VIEW RECORD
CVE-2026-106126
Tenable Identity Exposure (SaaS)
Reporter: VULNREPORT
9.4
CRITICAL
VIEW RECORD
CVE-2026-14990
Product identification pending
Reporter: PSIRT
9.3
CRITICAL
VIEW RECORD
CVE-2026-107640
Product identification pending
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-9209
mJobTime
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-107699
Product identification pending
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-107700
Product identification pending
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-107703
@enmaso/node-convert
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-107704
image_optimizer
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-104075
TVU Receiver / Transceiver PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-104076
TVU Receiver / Transceiver PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-84244
Guardium Data Protection
Reporter: PSIRT
9.3
CRITICAL
VIEW RECORD
CVE-2026-107779
skyeye
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-107780
skyeye
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-107726
hazelcast PATCH
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-5759
FalkorDB PATCH
Reporter: 33C584B5-0579-4C06-B2A0-8D8329FCAB9C
9.3
CRITICAL
VIEW RECORD
CVE-2026-107908
FalkorDB PATCH
Reporter: 33C584B5-0579-4C06-B2A0-8D8329FCAB9C
9.3
CRITICAL
VIEW RECORD
CVE-2026-107935
Red Hat Build of Podman Desktop
Reporter: SECALERT
9.3
CRITICAL
VIEW RECORD
CVE-2026-93947
Traveler PATCH
Reporter: AUDIT
9.3
CRITICAL
VIEW RECORD
CVE-2026-96327
WPLMS PATCH
Reporter: AUDIT
9.3
CRITICAL
VIEW RECORD
CVE-2026-96328
JNews – Pay Writer PATCH
Reporter: AUDIT
9.3
CRITICAL
VIEW RECORD
CVE-2026-96330
tagDiv Opt-In Builder PATCH
Reporter: AUDIT
9.3
CRITICAL
VIEW RECORD
CVE-2026-96331
Ajax Search Pro PATCH
Reporter: AUDIT
9.3
CRITICAL
VIEW RECORD
CVE-2026-96809
EduAdmin Booking PATCH
Reporter: AUDIT
9.3
CRITICAL
VIEW RECORD
CVE-2026-7827
FalkorDB PATCH
Reporter: 33C584B5-0579-4C06-B2A0-8D8329FCAB9C
9.2
CRITICAL
VIEW RECORD
CVE-2026-107910
FalkorDB PATCH
Reporter: 33C584B5-0579-4C06-B2A0-8D8329FCAB9C
9.2
CRITICAL
VIEW RECORD
CVE-2026-19218
Product identification pending PATCH
Reporter: ILETISIM
9.1
CRITICAL
VIEW RECORD
CVE-2026-95210
Product identification pending
Reporter: CVE
9.1
CRITICAL
VIEW RECORD
CVE-2026-107781
skyeye
Reporter: DISCLOSURE
9.1
CRITICAL
VIEW RECORD
CVE-2026-16823
Product identification pending
Reporter: PSIRT
9.1
CRITICAL
VIEW RECORD
CVE-2026-16916
Product identification pending
Reporter: PSIRT
9.1
CRITICAL
VIEW RECORD
CVE-2026-19491
Product identification pending
Reporter: PSIRT
9.1
CRITICAL
VIEW RECORD
CVE-2026-79842
HPE Intelligent Management Center (iMC)
Reporter: SECURITY-ALERT
9.1
CRITICAL
VIEW RECORD
CVE-2026-106155
Product identification pending PATCH
Reporter: SECURITY
8.9
HIGH
VIEW RECORD
CVE-2026-19083
Product identification pending PATCH
Reporter: ILETISIM
8.8
HIGH
VIEW RECORD
CVE-2026-62142
WP 2FA PATCH
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-105436
MainWP Child PATCH
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-107375
generator-jhipster PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-107701
Product identification pending
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-18740
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-19482
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-89091
Product identification pending
Reporter: SECALERT
8.8
HIGH
VIEW RECORD
CVE-2026-7826
Product identification pending PATCH
Reporter: 33C584B5-0579-4C06-B2A0-8D8329FCAB9C
8.8
HIGH
VIEW RECORD
CVE-2026-107909
Product identification pending PATCH
Reporter: 33C584B5-0579-4C06-B2A0-8D8329FCAB9C
8.8
HIGH
VIEW RECORD
CVE-2026-19569
Product identification pending
Reporter: VULNERABILITIES
8.8
HIGH
VIEW RECORD
CVE-2026-19570
Product identification pending
Reporter: VULNERABILITIES
8.8
HIGH
VIEW RECORD
CVE-2026-96671
Featured Image from URL PATCH
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-102784
Gridbox extension for Joomla
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-44031
DCMTK PATCH
Reporter: 33C584B5-0579-4C06-B2A0-8D8329FCAB9C
8.7
HIGH
VIEW RECORD
CVE-2026-105830
commonmark PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-107639
ILIAS PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-107378
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-93858
Product identification pending
Reporter: CVE
8.7
HIGH
VIEW RECORD
CVE-2026-106433
Product identification pending
Reporter: CNA
8.7
HIGH
VIEW RECORD
CVE-2026-101024
Product identification pending
Reporter: ICS-CERT
8.7
HIGH
VIEW RECORD
CVE-2026-107725
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-105672
Tapo C325WB v2
Reporter: F23511DB-6C3E-4E32-A477-6AA17D310630
8.7
HIGH
VIEW RECORD
CVE-2026-105674
Tapo C325WB v2
Reporter: F23511DB-6C3E-4E32-A477-6AA17D310630
8.7
HIGH
VIEW RECORD
CVE-2026-83943
Product identification pending
Reporter: SECURE
8.7
HIGH
VIEW RECORD
CVE-2026-16159
Product identification pending
Reporter: PSIRT
8.6
HIGH
VIEW RECORD
CVE-2026-16163
Product identification pending
Reporter: PSIRT
8.6
HIGH
VIEW RECORD
CVE-2026-81932
Product identification pending
Reporter: PSIRT
8.6
HIGH
VIEW RECORD
CVE-2026-104077
Product identification pending PATCH
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-107322
Product identification pending PATCH
Reporter: FF89BA41-3AA1-4D27-914A-91399E9639E5
8.5
HIGH
VIEW RECORD
CVE-2026-107707
Intego Antivirus
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-107782
Product identification pending PATCH
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-11318
Product identification pending
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-105269
Product identification pending
Reporter: ICS-CERT
8.5
HIGH
VIEW RECORD
CVE-2026-94663
ProfileGrid PATCH
Reporter: AUDIT
8.5
HIGH
VIEW RECORD
CVE-2026-95599
Product identification pending
Reporter: AUDIT
8.5
HIGH
VIEW RECORD
CVE-2026-95607
Product identification pending
Reporter: AUDIT
8.5
HIGH
VIEW RECORD
CVE-2026-95610
Product identification pending
Reporter: AUDIT
8.5
HIGH
VIEW RECORD
CVE-2026-96329
Product identification pending
Reporter: AUDIT
8.5
HIGH
VIEW RECORD
CVE-2026-104078
Product identification pending PATCH
Reporter: DISCLOSURE
8.4
HIGH
VIEW RECORD
CVE-2026-84250
Product identification pending
Reporter: PSIRT
8.4
HIGH
VIEW RECORD
CVE-2026-107732
sumatrapdf
Reporter: SECURITY-ADVISORIES
8.4
HIGH
VIEW RECORD
CVE-2026-105833
Product identification pending PATCH
Reporter: DISCLOSURE
8.3
HIGH
VIEW RECORD
CVE-2026-107705
Product identification pending
Reporter: DISCLOSURE
8.3
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.