Skip to main content

CVE-2021-26623

7.8
HIGHCVSS v3.1 Base Score
1.33%
LOW RiskEPSS (80th percentile)

A remote code execution vulnerability due to incomplete check for 'xheader_decode_path_record' function's parameter length value in the ark library. Remote attackers can induce exploit malicious code using this function.

Published: 4/1/2022
Modified: 11/21/2024
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2 Score

7.5

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Score (Exploitation Probability)

1.33%LOW Exploitation Risk
80th percentile

This vulnerability has a 1.33% probability of being exploited in the next 30 days, ranking higher than 80% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-125, CWE-787)

CVE-2026-0300CRITICAL 9.8

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.

5/6/2026
CVE-2026-3055CRITICAL 9.8

Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread

3/23/2026
CVE-2026-3909HIGH 8.8

Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

3/13/2026
CVE-2021-47781CRITICAL 9.8

Cmder Console Emulator 1.3.18 contains a buffer overflow vulnerability that allows attackers to trigger a denial of service condition through a maliciously crafted .cmd file. Attackers can create a specially constructed .cmd file with repeated characters to overwhelm the console emulator's buffer and crash the application.

1/15/2026
CVE-2026-22859CRITICAL 9.1

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, the URBDRC client does not perform bounds checking on server‑supplied MSUSB_INTERFACE_DESCRIPTOR values and uses them as indices in libusb_udev_complete_msconfig_setup, causing an out‑of‑bounds read. This vulnerability is fixed in 3.20.1.

1/14/2026

Similar SeverityHIGH