PatchDayAlert
Daily Digest · 2 min read · 5 CVEs · Issue 44 By PatchDayAlert

OpenSSL CMS forgery bug scores 9.1, plus a buffer overflow in Apache mod_proxy_html

CVE-2026-34182 lets attackers forge S/MIME and CMS-signed messages that pass validation. Apache's mod_proxy_html has a remotely exploitable buffer overflow (CVSS 7.5), and there's a Linux kernel privesc in the Topcliff SPI driver. Nothing exploited in the wild yet, but that OpenSSL one needs patching fast.

Patch now
0
Within 24h
2
This week
3
Exploited
0
OpenSSLNode.JsQEMUEDK2Azure LinuxLinuxCloudLinux KernelLibnfsTensorBoardPythonApache HTTP Server

Heads up: OpenSSL dropped a CVSS 9.1 CMS forgery bug (CVE-2026-34182) that lets attackers forge signed or enveloped messages that pass validation. If you process S/MIME email or run code-signing workflows, that's a real problem. Nobody's exploiting it yet, but the impact ceiling is high, so don't wait on this one.


Today's CVEs

Sorted by urgency

02

CVE-2026-46301

MSRC
7.8
CVSS EPSS 0.17%
Patch this week HIGH
Linux KernelAzure LinuxLinuxCloud

A use-after-free bug in the Linux kernel's Topcliff PCH SPI driver can be triggered during device unbind. A local attacker with access to trigger driver unbind operations could escalate privileges or crash the system. This only affects you if you're running hardware that uses the Topcliff PCH SPI controller, which is uncommon outside certain embedded Intel platforms.

Affected estate
Anyone running Azure Linux 3.0 with kernel 6.6.139.1-1, especially on hardware using Intel Topcliff PCH SPI
How to check
Run `uname -r` and check if it matches 6.6.139.1-1. Also check `lsmod | grep spi_topcliff_pch` to see if the affected driver is loaded.
Included because
CVSS 7.8; local privilege escalation; requires specific hardware driver to be loaded
Action
Run `tdnf update kernel` and schedule a reboot.
Why it matters
A local privilege escalation via a use-after-free could give an attacker full kernel control.
Source
NVD

Evidence trail

03

CVE-2026-53689

MSRC
7.1
CVSS EPSS 0.19%
Patch this week HIGH
LibnfsAzure LinuxLinuxCloud

A vulnerability in libnfs 5.0.2 on Azure Linux 3.0. Details are sparse (no description provided), but the CVSS 7.1 score suggests a significant impact, likely involving NFS client-side operations. If you mount NFS shares using libnfs, treat this as a real risk until more details surface.

Affected estate
Anyone running Azure Linux 3.0 with libnfs 5.0.2-1, particularly systems that mount or interact with NFS shares
How to check
Run `tdnf list installed libnfs` and confirm the version.
Included because
CVSS 7.1; limited detail increases uncertainty; common NFS client library
Action
Run `tdnf update libnfs` to install the patched version.
Why it matters
libnfs bugs can affect any workload mounting NFS shares, and the lack of a public description makes risk assessment harder.
Source
NVD

Evidence trail

04

CVE-2026-12143

MSRC
7.5
CVSS EPSS 0.33%
Patch this week HIGH
TensorBoardPythonAzure LinuxLinuxCloud

The form-data library fails to escape carriage returns, line feeds, and quotes in multipart field names and filenames. An attacker who controls input to a form-data request can inject arbitrary HTTP headers (CRLF injection), potentially smuggling requests or poisoning responses. This surfaces in the python-tensorboard package on Azure Linux 3.0, which bundles or depends on the vulnerable library.

Affected estate
Anyone running Azure Linux 3.0 with python-tensorboard 2.16.2-6, or any workload that uses the affected form-data dependency
How to check
Run `tdnf list installed python-tensorboard` and confirm the version. Also check `pip show tensorboard` if installed via pip.
Included because
CVSS 7.5; network-exploitable; CRLF injection in a common library pattern
Action
Run `tdnf update python-tensorboard` to install the fixed version.
Why it matters
CRLF injection can be chained into request smuggling or session hijacking if the service handles untrusted input in multipart form fields.
Source
NVD

Evidence trail

05

CVE-2026-34355

MSRC
7.5
CVSS EPSS 0.56%
Patch within 24h HIGH
Apache HTTP ServerAzure LinuxLinuxCloud

A buffer overflow in Apache HTTP Server's mod_proxy_html module lets a remote attacker send crafted content through the reverse proxy that overflows a buffer. If you use mod_proxy_html to rewrite HTML in proxied responses, this is exploitable over the network without authentication. No exploitation in the wild yet, but buffer overflows in internet-facing web servers deserve fast attention.

Affected estate
Anyone running Azure Linux 3.0 with httpd 2.4.67-1, especially if mod_proxy_html is enabled on internet-facing Apache instances
How to check
Run `httpd -v` to confirm the version and `httpd -M | grep proxy_html` to check if the module is loaded.
Included because
CVSS 7.5; unauthenticated; internet-facing; buffer overflow in widely deployed web server
Action
Run `tdnf update httpd` and restart the service with `systemctl restart httpd`.
Why it matters
A buffer overflow in an internet-facing reverse proxy module can lead to remote code execution with no authentication required.
Source
NVD

Evidence trail


One email, every Wednesday morning.

Subscribe