LIVE · cybersecurity feed
Live wire
vendor

Samba

10 CVEs published in the last four months. Exploited flaws first.

Critical1
High9
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-537919.1criticalrsyncrsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attacke23d ago
CVE-2026-704618.2highrsyncrsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated atta23d ago
CVE-2026-436188.1highrsyncRsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32109d ago
CVE-2026-537958.1highrsyncrsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the23d ago
CVE-2026-704638.1highrsyncrsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing.23d ago
CVE-2026-538037.8highrsyncrsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary f23d ago
CVE-2026-704557.5highrsyncrsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system 23d ago
CVE-2026-538027.1highrsyncrsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to23d ago
CVE-2026-537847.1highrsyncrsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the 23d ago
CVE-2026-295187highrsyncRsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling108d ago

Filter the full tracker by Samba