Executive assessment
Today's brief leads with Multiple vulnerabilities in Nvidia Driver. All 7 selected findings retain their own technical scope, action, observed status, and evidence limits.
Finding 01 — Multiple vulnerabilities in Nvidia Driver
What changed: CVE coverage: CVE-2025-23280, CVE-2025-23282, CVE-2025-23300, CVE-2025-23309, CVE-2025-23330, CVE-2025-23332, CVE-2025-23345, CVE-2025-23347, CVE-2025-23352, CVE-2022-21813, CVE-2022-21814, CVE-2022-21815, CVE-2022-21816, CVE-2025-23244, CVE-2025-23245, CVE-2025-23246, CVE-2025-23276, CVE-2025-23277, CVE-2025-23278, CVE-2025-23279, CVE-2025-23281, CVE-2025-23283, CVE-2025-23284, CVE-2025-23285, CVE-2025-23286, CVE-2025-23287, CVE-2025-23288, CVE-2025-23290, CVE-2025-33217, CVE-2025-33218, CVE-2025-33219, CVE-2025-33220, CVE-2025-33237. The cited advisories disclose: enable Denial of Service.
Technical evidence: CVE-2025-23280; CVSS v3.1 7; weakness ['CWE-416']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2025-23280 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: wid.cert-bund.de](<https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2247>)
Finding 02 — Multiple vulnerabilities in Foxit PDF Reader
What changed: CVE coverage: CVE-2026-13127, CVE-2026-13128, CVE-2026-57242, CVE-2026-57252, CVE-2026-57254, CVE-2026-13129, CVE-2026-57237, CVE-2026-57238, CVE-2026-57253. The cited advisories disclose: Annotation Use-After-Free Remote Code Execution Vulnerability; Doc Object Use-After-Free Remote Code Execution Vulnerability; AcroForm Use-After-Free Remote Code Execution Vulnerability; AcroForm Use-After-Free Remote Code Execution Vulnerability; Annotation Use-After-Free Remote Code Execution Vulnerability; Annotation Use-After-Free Information Disclosure Vulnerability; Annotation Use-After-Free Information Disclosure Vulnerability; Annotation Use-After-Free Information Disclosure Vulnerability; PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability.
Technical evidence: CVE-2026-13127; CVSS v3.1 7.8; weakness ['CWE-416']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-13127 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: www.zerodayinitiative.com](<http://www.zerodayinitiative.com/advisories/ZDI-26-603/>)
Finding 03 — Multiple vulnerabilities in NVIDIA TensorRT ONNX File Parsing
What changed: CVE coverage: CVE-2026-24268, CVE-2026-24238, CVE-2026-24272. The cited advisories disclose: Heap-based Buffer Overflow Remote Code Execution Vulnerability; Improper Validation of Array Index Remote Code Execution Vulnerability; Heap-based Buffer Overflow Remote Code Execution Vulnerability.
Technical evidence: CVE-2026-24268; CVSS v3.1 7.8; weakness ['CWE-122']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-24268 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: www.zerodayinitiative.com](<http://www.zerodayinitiative.com/advisories/ZDI-26-593/>)
Finding 04 — REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS): Improper Input Validation
What changed: A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to overwrite certain files that should be restricted on an affected device. The vulnerability is due to insufficient authorization enforcement on an affected system.
Technical evidence: CVE-2020-3478; CVSS v3.1 8.1; weakness ['CWE-20']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2020-3478 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2020-3478>)
Finding 05 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kofi Mokome Message Filter for Contact Form 7 allows SQL Injection.
What changed: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kofi Mokome Message Filter for Contact Form 7 allows SQL Injection. This issue affects Message Filter for Contact Form 7: from n/a through 1.6.3.2.
Technical evidence: CVE-2025-46252; CVSS v3.1 7.6; weakness ['CWE-89']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2025-46252 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2025-46252>)
Finding 06 — Linux kernel: Out-of-bounds Write
What changed: In the Linux kernel, the following vulnerability has been resolved: Input: mms114 - reject an oversized device packet size mms114_interrupt() reads a packet of touch data from the device into a fixed-size on-stack buffer struct mms114_touch touch[MMS114_MAX_TOUCH]; which holds MMS114_MAX_TOUCH (10) events of MMS114_EVENT_SIZE (8) bytes, i.e. 80 bytes.
Technical evidence: CVE-2026-64270; CVSS v3.1 7.8; weakness ['CWE-787']; technical confidence Medium.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-64270 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-64270>)
Finding 07 — libsoup: HTTP Request Smuggling
What changed: A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and trailing invalid characters.
Technical evidence: CVE-2026-66338; CVSS v3.1 5.4; weakness ['CWE-444']; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-66338 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-66338>)