← Back to the live CVE advisory feed

CVE-2026-53671: prevail

Severity
9.3 (CRITICAL)
Vendor
VBPF
Affected versions
< 0.2.4
Fixed version
0.2.4.
Patch status
Patched
Published
2026-09-02T18:20:00.293
Modified
2026-09-02T18:20:00.293

Why it matters

Critical vulnerability requiring immediate validation against your environment.

Recommended admin actions

  • Prioritize validation immediately due to critical CVSS severity.
  • Compare installed versions against the affected version range in the advisory.

Technical summary

PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, the abstract transformer in prevail treats writes through a T_CTX-typed base register as a silent no-op: do_mem_store in src/crab/ebpf_transformer.cpp only models T_STACK stores, and the checker's T_CTX bounds arm never tests AccessType::write. An attacker can craft an eBPF program that overwrites a context field (e.g., ctx->data), reload that field typed as T_PACKET, and dereference an attacker-controlled address — and prevail will report the program as safe. This issue has been patched in version 0.2.4.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: SEP 03, 2026 04:00 PM UTC
275 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-53611
looking-glass PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-20212
Cisco NX-OS Software
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-20274
Cisco IOS XR Software
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-20279
Cisco IOS XR Software
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-19117
Secret Server (On-Prem)
Reporter: 1443CD92-D354-46D2-9290-D812316CA43A
9.8
CRITICAL
VIEW RECORD
CVE-2026-53649
joro PATCH
Reporter: SECURITY-ADVISORIES
9.6
CRITICAL
VIEW RECORD
CVE-2026-78069
J2Store extension for Joomla
Reporter: SECURITY
9.5
CRITICAL
VIEW RECORD
CVE-2026-82180
Eclipse Arrowhead
Reporter: EMO
9.5
CRITICAL
VIEW RECORD
CVE-2026-85216
misp
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
9.5
CRITICAL
VIEW RECORD
CVE-2026-76174
Ocsreports
Reporter: CVE-COORDINATION
9.4
CRITICAL
VIEW RECORD
CVE-2026-53670
prevail PATCH
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-53671
prevail PATCH
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-78080
JooDatabase Lite extension for Joomla
Reporter: SECURITY
9.3
CRITICAL
VIEW RECORD
CVE-2026-85154
AVideo
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-85181
cat
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-85183
taipy
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-78689
NGINX JavaScript
Reporter: F5SIRT
9.2
CRITICAL
VIEW RECORD
CVE-2026-76178
Ocsreports
Reporter: CVE-COORDINATION
9.2
CRITICAL
VIEW RECORD
CVE-2026-66786
Red Hat Advanced Cluster Management for Kubernetes 2.17 PATCH
Reporter: SECALERT
9.1
CRITICAL
VIEW RECORD
CVE-2026-80515
Eclipse Arrowhead
Reporter: EMO
8.9
HIGH
VIEW RECORD
CVE-2026-85109
HG10
Reporter: CNA
8.9
HIGH
VIEW RECORD
CVE-2026-18329
NGINX JavaScript
Reporter: F5SIRT
8.8
HIGH
VIEW RECORD
CVE-2026-84645
Product identification pending
Reporter: JENKINSCI-CERT
8.8
HIGH
VIEW RECORD
CVE-2026-84647
Product identification pending
Reporter: JENKINSCI-CERT
8.8
HIGH
VIEW RECORD
CVE-2026-84648
Product identification pending
Reporter: JENKINSCI-CERT
8.8
HIGH
VIEW RECORD
CVE-2026-84649
Product identification pending
Reporter: JENKINSCI-CERT
8.8
HIGH
VIEW RECORD
CVE-2026-84650
Product identification pending
Reporter: JENKINSCI-CERT
8.8
HIGH
VIEW RECORD
CVE-2026-84668
Product identification pending
Reporter: JENKINSCI-CERT
8.8
HIGH
VIEW RECORD
CVE-2026-84669
Product identification pending
Reporter: JENKINSCI-CERT
8.8
HIGH
VIEW RECORD
CVE-2026-84670
Product identification pending
Reporter: JENKINSCI-CERT
8.8
HIGH
VIEW RECORD
CVE-2026-84671
Product identification pending
Reporter: JENKINSCI-CERT
8.8
HIGH
VIEW RECORD
CVE-2026-84672
Product identification pending
Reporter: JENKINSCI-CERT
8.8
HIGH
VIEW RECORD
CVE-2026-84673
Product identification pending
Reporter: JENKINSCI-CERT
8.8
HIGH
VIEW RECORD
CVE-2026-20275
Cisco IOS XR Software
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-20278
Cisco IOS XR Software
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-20280
Cisco IOS XR Software
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-53706
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-78064
J2Store extension for Joomla
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-80465
Product identification pending
Reporter: PRODUCTCERT
8.8
HIGH
VIEW RECORD
CVE-2026-85199
Product identification pending PATCH
Reporter: EMO
8.8
HIGH
VIEW RECORD
CVE-2026-66842
BIG-IP
Reporter: F5SIRT
8.7
HIGH
VIEW RECORD
CVE-2026-77180
NGINX Ingress Controller
Reporter: F5SIRT
8.7
HIGH
VIEW RECORD
CVE-2026-78222
NGINX JavaScript
Reporter: F5SIRT
8.7
HIGH
VIEW RECORD
CVE-2026-79756
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-84851
Product identification pending PATCH
Reporter: FF89BA41-3AA1-4D27-914A-91399E9639E5
8.7
HIGH
VIEW RECORD
CVE-2026-77999
J2Store extension for Joomla
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-85155
AVideo
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-85169
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-85174
siyuan PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-85175
siyuan PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-71404
Product identification pending PATCH
Reporter: MEISSNER
8.7
HIGH
VIEW RECORD
CVE-2026-85176
dbgate
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-85180
ollama
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-85212
CRMEB
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-66362
NGINX Gateway Fabric
Reporter: F5SIRT
8.6
HIGH
VIEW RECORD
CVE-2026-20276
Cisco IOS XR Software
Reporter: PSIRT
8.6
HIGH
VIEW RECORD
CVE-2026-82524
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-84452
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.6
HIGH
VIEW RECORD
CVE-2026-76175
Ocsreports
Reporter: CVE-COORDINATION
8.6
HIGH
VIEW RECORD
CVE-2026-76176
Ocsreports
Reporter: CVE-COORDINATION
8.6
HIGH
VIEW RECORD
CVE-2026-84830
Product identification pending PATCH
Reporter: VULNERABILITY
8.6
HIGH
VIEW RECORD
CVE-2026-84832
Product identification pending PATCH
Reporter: VULNERABILITY
8.6
HIGH
VIEW RECORD
CVE-2026-85031
CP450
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-76642
util-linux
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-9853
Product identification pending
Reporter: CYBERSECURITY
8.5
HIGH
VIEW RECORD
CVE-2026-9854
Product identification pending
Reporter: CYBERSECURITY
8.5
HIGH
VIEW RECORD
CVE-2025-12737
WSO2 Open Banking AM
Reporter: ED10EEF1-636D-4FBE-9993-6890DFA878F8
8.4
HIGH
VIEW RECORD
CVE-2026-85179
label-studio
Reporter: DISCLOSURE
8.4
HIGH
VIEW RECORD
CVE-2026-45730
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.3
HIGH
VIEW RECORD
CVE-2026-82404
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.3
HIGH
VIEW RECORD
CVE-2026-85091
Product identification pending
Reporter: DISCLOSURE
8.3
HIGH
VIEW RECORD
CVE-2026-85178
helicone
Reporter: DISCLOSURE
8.3
HIGH
VIEW RECORD
CVE-2026-85211
label-studio
Reporter: DISCLOSURE
8.3
HIGH
VIEW RECORD
CVE-2026-20277
Cisco IOS XR Software
Reporter: PSIRT
8.2
HIGH
VIEW RECORD
CVE-2021-38489
InsydeH2O
Reporter: 8338D8CB-57F7-4252-ABC0-96FD13E98D21
8.2
HIGH
VIEW RECORD
CVE-2026-84381
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-84665
Product identification pending
Reporter: JENKINSCI-CERT
8
HIGH
VIEW RECORD
CVE-2026-52831
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8
HIGH
VIEW RECORD
CVE-2026-52833
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8
HIGH
VIEW RECORD
CVE-2026-79755
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8
HIGH
VIEW RECORD
CVE-2026-49832
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8
HIGH
VIEW RECORD
CVE-2026-78408
Product identification pending
Reporter: SECALERT
7.9
HIGH
VIEW RECORD
CVE-2026-78410
Product identification pending
Reporter: SECALERT
7.8
HIGH
VIEW RECORD
CVE-2026-84837
Product identification pending
Reporter: SECALERT
7.8
HIGH
VIEW RECORD
CVE-2026-84838
Product identification pending
Reporter: SECALERT
7.8
HIGH
VIEW RECORD
CVE-2026-73600
Product identification pending
Reporter: SECURITY_ALERT
7.8
HIGH
VIEW RECORD
CVE-2023-20576
Product identification pending
Reporter: PSIRT
7.7
HIGH
VIEW RECORD
CVE-2026-84831
Product identification pending PATCH
Reporter: VULNERABILITY
7.7
HIGH
VIEW RECORD
CVE-2026-85168
Product identification pending PATCH
Reporter: DISCLOSURE
7.7
HIGH
VIEW RECORD
CVE-2026-75033
Product identification pending PATCH
Reporter: MEISSNER
7.7
HIGH
VIEW RECORD
CVE-2026-85182
vhr
Reporter: DISCLOSURE
7.7
HIGH
VIEW RECORD
CVE-2026-53635
openedx-platform PATCH
Reporter: SECURITY-ADVISORIES
7.6
HIGH
VIEW RECORD
CVE-2026-85221
misp
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
7.6
HIGH
VIEW RECORD
CVE-2026-20281
Cisco Session Initiation Protocol (SIP) Software
Reporter: PSIRT
7.5
HIGH
VIEW RECORD
CVE-2026-77124
Nexus Repository 3
Reporter: 103E4EC9-0A87-450B-AF77-479448DDEF11
7.5
HIGH
VIEW RECORD
CVE-2026-84382
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-56855
Product identification pending
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-78662
Product identification pending
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-84292
Product identification pending PATCH
Reporter: CE714D77-ADD3-4F53-AFF5-83D477B104BB
7.5
HIGH
VIEW RECORD
CVE-2026-84394
fast-uri PATCH
Reporter: CE714D77-ADD3-4F53-AFF5-83D477B104BB
7.5
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.