CVE-2026-38969 ruby webrick through v1.9.2 WEBrick reparses trailer Content-Length into canonical request state, enabling request smuggling.
CVE-2026-38968 ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.
CVE-2026-14191 WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeader
CVE-2026-53269 netfilter: synproxy: add mutex to guard hook reference counting
CVE-2026-56000 xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent()
CVE-2026-55999 xorg-server / xwayland glamor font atlas Heap Buffer Overflow
CVE-2026-56002 libXfont2 PCF Font Parsing Heap Buffer Overflow
Information published. Continue reading CVE-2026-56002 libXfont2 PCF Font Parsing Heap Buffer Overflow
