This weekly blog post is from via our unique intelligence collection pipelines. We are your eyes and ears online, including the Dark Web.
There are thousands of vulnerability discussions each week. SOS Intelligence gathers a list of the most discussed Common Vulnerabilities and Exposures (CVE) online for the previous week.
We make every effort to ensure the accuracy of the data presented. As this is an automated process some errors may creep in.
If you are feeling generous please do make us aware of anything you spot, feel free to follow us on Twitter @sosintel and DM us. Thank you!
1. CVE-2026-31431
In the Linux kernel, the following vulnerability has been resolved:
crypto: algif_aead – Revert to operating out-of-place
This mostly reverts commit 72548b093ee3 except for the copying of
the associated data.
There is no benefit in operating in-place in algif_aead since the
source and destination come from different mappings. Get rid of
all the complexity added for in-place operation and just copy the
AD directly.
https://nvd.nist.gov/vuln/detail/CVE-2026-31431
2. CVE-2026-45185
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
https://nvd.nist.gov/vuln/detail/CVE-2026-45185
3. CVE-2025-50708
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
https://nvd.nist.gov/vuln/detail/CVE-2025-50708
4. CVE-2024-34102
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
https://nvd.nist.gov/vuln/detail/CVE-2024-34102
5. CVE-2024-38063
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
https://nvd.nist.gov/vuln/detail/CVE-2024-38063
6. CVE-2024-49113
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
https://nvd.nist.gov/vuln/detail/CVE-2024-49113
7. CVE-2026-32746
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
https://nvd.nist.gov/vuln/detail/CVE-2026-32746
8. CVE-2025-0368
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
https://nvd.nist.gov/vuln/detail/CVE-2025-0368
9. CVE-2022-21227
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
https://nvd.nist.gov/vuln/detail/CVE-2022-21227
10. CVE-2021-40539
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
https://nvd.nist.gov/vuln/detail/CVE-2021-40539


Recent Comments