s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2026-39044

📛 CVE Title

(no title)

Description

The GStreamer project reports multiple security vulnerabilities fixed in the 1.28.2 release: Several security vulnerabilities were addressed, including: These could lead to application crashes, memory exhaustion, or potentially arbitrary code execution.

Overview

State
Assigner (CNA)
CVSS severity
critical
CVSS score
CVSS 9.8 / 10 9.8 9.8 / 10
CVSS vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Effective score
9.8 / 10 CRITICAL source: CNA overview
CWE(s)
Reserved
Published
Last updated
Source
https://www.tenable.com/cve/CVE-2026-39044
Linked Threat
CVE-2026-39044 — CVE-2026-39044

NVD / KEV / EPSS data refreshed 2026-06-30 02:01 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

Vendor references (0)

References embedded in the original CVE record by the assigning CNA.

None in the CVE record.

Web references (2)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

Remediations (17)

Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

  • web:cyberpress.org

    The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Microsoft SharePoint Server vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild and setting an aggressive remediation deadline for federal agencies and organizations running the platform.

    2026-07-04 21:00 UTC
  • web:msrc.microsoft.com

    The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.

    2026-07-04 21:00 UTC
  • web:www.cisa.gov

    The median time for full resolution rose to 43 days. Defenders need greater clarity and speed to patch systems in today's threat landscape. We must flip the script on patching prioritization: patch smarter, not harder.

    2026-07-04 21:00 UTC
  • web:www.cisecurity.org

    <p>Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or ...

    2026-07-04 21:00 UTC
  • web:www.crowdstrike.com

    Microsoft's March 2026 Patch Tuesday addresses 82 CVEs , featuring eight Critical vulnerabilities.

    2026-07-04 21:00 UTC
  • web:www.tenable.com

    CISA BOD 26-04 gives federal agencies new, risk-based requirements for vulnerability prioritization and remediation . Highest-risk vulns must be remediated in as few as three days.

    2026-07-04 21:00 UTC
  • web:zecurit.com

    Get the complete breakdown of Microsoft's June 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .

    2026-07-04 21:00 UTC
  • web:support.microsoft.com

    How to obtain or download the latest cumulative update package for Linux To update SQL Server 2022 on Linux to the latest CU, you must first have the Cumulative Update repository configured. Then, update your SQL Server packages by using the appropriate platform-specific update command. For installation instructions and direct links to the CU package downloads, see the SQL Server 2022 Release ...

    2026-06-30 04:56 UTC
  • web:www.cisa.gov

    The Directive consolidates, clarifies and updates the urgency of vulnerability remediation , focuses agencies patching efforts on the highest risk, and enhances efficiency for federal civilian agencies.

    2026-06-30 04:56 UTC
  • web:www.oracle.com

    Oracle Critical Patch Update Advisory - April 2026 Description A Critical Patch Update is a collection of patches for multiple security vulnerabilities. These patches address vulnerabilities in Oracle code and in third party components included in Oracle products. These patches are usually cumulative, but each advisory describes only the security patches added since the previous Critical Patch ...

    2026-06-30 04:56 UTC
  • web:www.hipaajournal.com

    CISA has released a new risk-based vulnerability remediation framework to help vendors assess vulnerabilities and prioritize patching effectively, concentrating their efforts on mitigating vulnerabilities in the most at-risk assets and addressing vulnerabilities that carry the greatest risk of exploitation.

    2026-06-30 04:56 UTC
  • web:cyberscoop.com

    CISA has issued BOD 26-04, ordering federal agencies to prioritize software vulnerabilities using four new criteria to counter accelerating AI-driven threats.

    2026-06-30 04:56 UTC
  • web:cybersecuritynews.com

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued Binding Operational Directive (BOD) 26-04, titled "Prioritizing Security Updates Based on Risk," compelling all Federal Civilian Executive Branch (FCEB) agencies to remediate the most dangerous known exploited vulnerabilities within just three calendar days.

    2026-06-30 04:56 UTC
  • web:cybersecuritynews.com

    Microsoft has released its June 2026 Patch Tuesday security updates, addressing a hefty 198 vulnerabilities across its product ecosystem. The June rollout, published on June 9, 2026 , stands out not only for its volume but also for the inclusion of three zero-day vulnerabilities that were actively exploited or publicly known before a fix was available. Administrators are urged to prioritize ...

    2026-06-30 04:56 UTC
  • web:industrialcyber.co

    New CISA BOD 26-04 calls upon agencies to prioritize exploited vulnerabilities and assess compromise before patching.

    2026-06-30 04:56 UTC
  • web:www.computerworld.com

    Microsoft says it is considering a patch for a zero-day vulnerability, dubbed YellowKey, that allows attackers with access to a Windows device to bypass Bitlocker encryption protection and read ...

    2026-06-30 04:56 UTC
  • web:portal.msrc.microsoft.com

    The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

    2026-06-30 04:56 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2026-39044.json.

Not stored.