<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Use-After-Free — PoC Archive</title><link>https://poc.intelseclab.com/tags/use-after-free/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 16 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/use-after-free/index.xml" rel="self" type="application/rss+xml"/><item><title>Ubuntu Linux Kernel PPPoL2TP Use-After-Free Local Privilege Escalation (CVE-2026-68398)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-68398-ubuntu-pppol2tp-uaf-lpe/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-68398-ubuntu-pppol2tp-uaf-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-68398. Status: Patched. Affects: Linux Kernel (PPPoL2TP subsystem). Tags: linux, kernel, ubuntu, pppol2tp, l2tp, ppp, uaf, use-after-free, race-condition, lpe, privilege-escalation, kaslr-bypass, apparmor-bypass, suid, heap-spray, kmalloc-256, CVE-2026-68398.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>ubuntu</category><category>pppol2tp</category><category>l2tp</category><category>ppp</category><category>uaf</category><category>use-after-free</category><category>race-condition</category><category>lpe</category><category>privilege-escalation</category><category>kaslr-bypass</category><category>apparmor-bypass</category><category>suid</category><category>heap-spray</category><category>kmalloc-256</category><category>CVE-2026-68398</category></item><item><title>Linux Kernel — SCTPhantom: SCTP ASCONF DEL-IP Use-After-Free Local Privilege Escalation (CVE-2026-64564)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-64564-sctphantom-sctp-asconf-uaf-lpe/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-64564-sctphantom-sctp-asconf-uaf-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-64564. Status: Patched. Affects: Linux kernel, SCTP (Stream Control Transmission Protocol) ASCONF subsystem. Tags: linux, kernel, lpe, sctp, use-after-free, asconf, del-ip, heap-spray, packet-tx-ring, kaslr-bypass, credential-overwrite, debian, CWE-416, CVE-2026-64564.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>lpe</category><category>sctp</category><category>use-after-free</category><category>asconf</category><category>del-ip</category><category>heap-spray</category><category>packet-tx-ring</category><category>kaslr-bypass</category><category>credential-overwrite</category><category>debian</category><category>CWE-416</category><category>CVE-2026-64564</category></item><item><title>Linux Kernel — qdisc Rate-Table Race Condition Local Privilege Escalation (CVE-2026-68138)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-68138-linux-qdisc-ratetable-race-lpe/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-68138-linux-qdisc-ratetable-race-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-68138. Status: Patched. Affects: Linux kernel, traffic-control qdisc rate-table subsystem (qdisc_get_rtab / qdisc_put_rtab). Tags: linux, kernel, lpe, race-condition, use-after-free, qdisc, traffic-control, flower, bpf, pipe, page-cache, modprobe, CWE-362, CWE-416, CVE-2026-68138.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>lpe</category><category>race-condition</category><category>use-after-free</category><category>qdisc</category><category>traffic-control</category><category>flower</category><category>bpf</category><category>pipe</category><category>page-cache</category><category>modprobe</category><category>CWE-362</category><category>CWE-416</category><category>CVE-2026-68138</category></item><item><title>Zapscape — KVM/x86 Shadow-MMU Recursive-Zap Guest-to-Host Escape (CVE-2026-64561)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-09_cve-2026-64561-zapscape-kvm-shadow-mmu-guest-to-host/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-09_cve-2026-64561-zapscape-kvm-shadow-mmu-guest-to-host/</guid><description>High severity (CVSS 8.8) — binary · CVE-2026-64561. Status: Patched. Affects: Linux kernel, KVM/x86 shadow-MMU (nested EPT/NPT shadowing) — arch/x86/kvm/mmu/mmu.c and arch/x86/kvm/mmu/paging_tmpl.h. Tags: linux-kernel, kvm, x86, shadow-mmu, nested-virtualization, svm, npt, ept, guest-to-host-escape, vm-escape, use-after-free, CWE-416, cross-cache, kaslr-bypass, usermode-helper, virtualization.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>kvm</category><category>x86</category><category>shadow-mmu</category><category>nested-virtualization</category><category>svm</category><category>npt</category><category>ept</category><category>guest-to-host-escape</category><category>vm-escape</category><category>use-after-free</category><category>CWE-416</category><category>cross-cache</category><category>kaslr-bypass</category><category>usermode-helper</category><category>virtualization</category></item><item><title>MariaDB — Low-Privilege Remote Code Execution via ST_Area OOB Read + SYS_REFCURSOR Use-After-Free</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-09_mariadb-low-priv-rce-st-area-cursor-uaf/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-09_mariadb-low-priv-rce-st-area-cursor-uaf/</guid><description>Critical severity (CVSS 8.8) — binary · MDEV-40328 (ST_Area OOB read); cursor-array UAF has no assigned CVE yet. Status: Unpatched. Affects: MariaDB Server, ST_Area() geometry function and SYS_REFCURSOR cursor-array management. Tags: mariadb, database, rce, low-privilege, heap, oob-read, use-after-free, aslr-bypass, pie-bypass, coop, vtable, cursor, st-area, multipolygon, CWE-125, CWE-416, docker, v12-security.</description><category>binary</category><category>Critical</category><category>mariadb</category><category>database</category><category>rce</category><category>low-privilege</category><category>heap</category><category>oob-read</category><category>use-after-free</category><category>aslr-bypass</category><category>pie-bypass</category><category>coop</category><category>vtable</category><category>cursor</category><category>st-area</category><category>multipolygon</category><category>CWE-125</category><category>CWE-416</category><category>docker</category><category>v12-security</category></item><item><title>ITScape — KVM/arm64 vGIC-ITS Guest-to-Host VM Escape (CVE-2026-46316)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-27_cve-2026-46316-itscape-kvm-arm64-vgic-its-escape/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-27_cve-2026-46316-itscape-kvm-arm64-vgic-its-escape/</guid><description>Critical severity (CVSS 9.3) — binary · CVE-2026-46316 (GHSA-qcxh-2cm7-9fcc). Status: Weaponized. Affects: Linux kernel, KVM/arm64 in-kernel vGIC-ITS (Interrupt Translation Service) emulation (arch/arm64/kvm/vgic/vgic-its.c). Tags: linux-kernel, kvm, arm64, vgic-its, guest-to-host-escape, vm-escape, double-free, use-after-free, kaslr-bypass, heap-grooming, virtualization.</description><category>binary</category><category>Critical</category><category>linux-kernel</category><category>kvm</category><category>arm64</category><category>vgic-its</category><category>guest-to-host-escape</category><category>vm-escape</category><category>double-free</category><category>use-after-free</category><category>kaslr-bypass</category><category>heap-grooming</category><category>virtualization</category></item><item><title>Linux Kernel rtmutex Priority-Inheritance Stack-UAF — "GhostLock" (CVE-2026-43499, Nebula Security weaponized variant)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-08_cve-2026-43499-ghostlock-nebula-security/</link><pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-08_cve-2026-43499-ghostlock-nebula-security/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-43499 (aka "GhostLock"). Status: Weaponized (per Nebula Security disclosure); no exploit code mirrored into this repo, see Notes. Affects: Linux kernel — rtmutex priority-inheritance (futex-PI) subsystem, CONFIG_FUTEX_PI. Tags: linux-kernel, use-after-free, futex, rtmutex, priority-inheritance, lpe, local, container-escape, kernelctf, ghostlock.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>use-after-free</category><category>futex</category><category>rtmutex</category><category>priority-inheritance</category><category>lpe</category><category>local</category><category>container-escape</category><category>kernelctf</category><category>ghostlock</category></item><item><title>RediShell: Redis Lua Scripting Use-After-Free Leading to JOP-Chained Remote Code Execution (CVE-2025-49844)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-06_cve-2025-49844-redis-lua-uaf-jop-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-06_cve-2025-49844-redis-lua-uaf-jop-rce/</guid><description>Critical severity (CVSS 9.9) — binary · CVE-2025-49844. Status: Weaponized. Affects: Redis (embedded Lua scripting engine). Tags: redis, lua, use-after-free, uaf, memory-corruption, jop, jump-oriented-programming, shellcode, iced-x86, docker, cwe-416, rce.</description><category>binary</category><category>Critical</category><category>redis</category><category>lua</category><category>use-after-free</category><category>uaf</category><category>memory-corruption</category><category>jop</category><category>jump-oriented-programming</category><category>shellcode</category><category>iced-x86</category><category>docker</category><category>cwe-416</category><category>rce</category></item><item><title>Windows Push Notification Service Use-After-Free Race (CVE-2026-42978)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-42978-wpn-uaf-race/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-42978-wpn-uaf-race/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-42978. Status: PoC. Affects: Windows Push Notifications service (WpnService, wpncore.dll). Tags: windows, kernel, wpnservice, use-after-free, race-condition, toctou, privilege-escalation, etw, sysmon, patch-diffing.</description><category>binary</category><category>High</category><category>windows</category><category>kernel</category><category>wpnservice</category><category>use-after-free</category><category>race-condition</category><category>toctou</category><category>privilege-escalation</category><category>etw</category><category>sysmon</category><category>patch-diffing</category></item><item><title>PinTheft: RDS zcopy Refcount-Steal Double-Free LPE — Pure NASM Rewrite (CVE-2026-43494)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-43494-pintheft-nasm-kernel-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-43494-pintheft-nasm-kernel-lpe/</guid><description>High severity — binary · CVE-2026-43494. Status: PoC. Affects: Linux kernel (RDS zerocopy send path + io_uring fixed buffers). Tags: linux-kernel, lpe, double-free, use-after-free, rds, io_uring, page-cache-overwrite, x86_64, nasm, asm, local, root-shell.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>lpe</category><category>double-free</category><category>use-after-free</category><category>rds</category><category>io_uring</category><category>page-cache-overwrite</category><category>x86_64</category><category>nasm</category><category>asm</category><category>local</category><category>root-shell</category></item><item><title>nginx Resolver Use-After-Free in OCSP Stapling (CVE-2026-40701)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40701-nginx-resolver-ocsp-uaf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40701-nginx-resolver-ocsp-uaf/</guid><description>Medium severity (CVSS 6.3) — web · CVE-2026-40701. Status: PoC. Affects: nginx (open source). Tags: nginx, use-after-free, ocsp-stapling, resolver, memory-corruption, docker-lab, tls.</description><category>web</category><category>Medium</category><category>nginx</category><category>use-after-free</category><category>ocsp-stapling</category><category>resolver</category><category>memory-corruption</category><category>docker-lab</category><category>tls</category></item><item><title>Linux Kernel Futex-PI rtmutex remove_waiter() Use-After-Free (CVE-2026-43499)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-43499-rtmutex-remove-waiter-uaf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-43499-rtmutex-remove-waiter-uaf/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-43499. Status: PoC. Affects: Linux kernel — kernel/locking/rtmutex.c, futex-PI subsystem (futex_requeue() / rt_mutex_start_proxy_lock()). Tags: linux-kernel, android, use-after-free, futex, rtmutex, priority-inheritance, lpe, local, kernel-panic, ndk.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>android</category><category>use-after-free</category><category>futex</category><category>rtmutex</category><category>priority-inheritance</category><category>lpe</category><category>local</category><category>kernel-panic</category><category>ndk</category></item><item><title>curl SMB Connection-Reuse Use-After-Free (CVE-2026-3805)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-3805-curl-smb-use-after-free/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-3805-curl-smb-use-after-free/</guid><description>High severity — network · CVE-2026-3805. Status: PoC. Affects: curl / libcurl. Tags: curl, libcurl, use-after-free, smb, cwe-416, memory-corruption, asan.</description><category>network</category><category>High</category><category>curl</category><category>libcurl</category><category>use-after-free</category><category>smb</category><category>cwe-416</category><category>memory-corruption</category><category>asan</category></item><item><title>AppleSEPKeyStore IOKit Use-After-Free (CVE-2026-20637)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-20637-applesepkeystore-uaf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-20637-applesepkeystore-uaf/</guid><description>High severity — binary · CVE-2026-20637. Status: PoC. Affects: AppleSEPKeyStore driver (com.apple.driver.AppleSEPKeyStore, exposed as IOKit service AppleKeyStore). Tags: ios, macos, kernel, iokit, use-after-free, race-condition, aksepkeystore, xnu, kernel-panic.</description><category>binary</category><category>High</category><category>ios</category><category>macos</category><category>kernel</category><category>iokit</category><category>use-after-free</category><category>race-condition</category><category>aksepkeystore</category><category>xnu</category><category>kernel-panic</category></item><item><title>AppleM2ScalerCSCDriver Shared Scheduler Use-After-Free (CVE-2026-43655)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-43655-apple-m2-scalercscdriver-uaf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-43655-apple-m2-scalercscdriver-uaf/</guid><description>High severity — binary · CVE-2026-43655. Status: PoC. Affects: Apple AppleM2ScalerCSCDriver kext / IOSurfaceAcceleratorClient user-client (iOS, iPadOS, macOS on Apple M2-family scaler hardware). Tags: use-after-free, ios, ipados, macos, kernel, iokit, iosurface, kext, sandbox-escape-adjacent, memory-corruption.</description><category>binary</category><category>High</category><category>use-after-free</category><category>ios</category><category>ipados</category><category>macos</category><category>kernel</category><category>iokit</category><category>iosurface</category><category>kext</category><category>sandbox-escape-adjacent</category><category>memory-corruption</category></item><item><title>AppleJPEGDriver startDecoder Timeout Use-After-Free (CVE-2026-20687)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-20687-applejpegdriver-uaf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-20687-applejpegdriver-uaf/</guid><description>High severity — binary · CVE-2026-20687. Status: PoC. Affects: AppleJPEGDriver kernel extension. Tags: ios, kernel, applejpegdriver, use-after-free, mte, iokit, kernel-panic, camera.</description><category>binary</category><category>High</category><category>ios</category><category>kernel</category><category>applejpegdriver</category><category>use-after-free</category><category>mte</category><category>iokit</category><category>kernel-panic</category><category>camera</category></item><item><title>Redis Vector Set Duplicate HNSW Node ID RCE</title><link>https://poc.intelseclab.com/pocs/network/2026-07-03_redis-vector-set-hnsw-id-rce/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-03_redis-vector-set-hnsw-id-rce/</guid><description>Critical severity — network · None assigned as of 2026-07-03. Status: Weaponized. Affects: Redis server, Vector Set module (modules/vector-sets). Tags: redis, vector-set, hnsw, rce, deserialization, use-after-free, heap-corruption, rdb-restore.</description><category>network</category><category>Critical</category><category>redis</category><category>vector-set</category><category>hnsw</category><category>rce</category><category>deserialization</category><category>use-after-free</category><category>heap-corruption</category><category>rdb-restore</category></item><item><title>libssh2 Publickey Subsystem List Parser Heap Corruption to Code Execution</title><link>https://poc.intelseclab.com/pocs/network/2026-07-03_libssh2-publickey-list-parser-oob/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-03_libssh2-publickey-list-parser-oob/</guid><description>Critical severity — network · None assigned as of 2026-07-03. Status: Weaponized. Affects: libssh2, publickey subsystem list parser (src/publickey.c). Tags: libssh2, ssh, publickey-subsystem, heap-overflow, use-after-free, integer-overflow, windows, rce, memory-corruption.</description><category>network</category><category>Critical</category><category>libssh2</category><category>ssh</category><category>publickey-subsystem</category><category>heap-overflow</category><category>use-after-free</category><category>integer-overflow</category><category>windows</category><category>rce</category><category>memory-corruption</category></item><item><title>Ladybird Browser WebAssembly ESM Host-Function Use-After-Free RCE</title><link>https://poc.intelseclab.com/pocs/web/2026-07-03_ladybird-wasm-esm-host-function-rce/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-03_ladybird-wasm-esm-host-function-rce/</guid><description>Critical severity — web · None assigned as of 2026-07-03. Status: Weaponized. Affects: Ladybird web browser (WebContent process, LibWeb / LibWasm). Tags: ladybird, browser, webassembly, wasm-gc, use-after-free, memory-corruption, rce, javascript-engine, sandbox-escape.</description><category>web</category><category>Critical</category><category>ladybird</category><category>browser</category><category>webassembly</category><category>wasm-gc</category><category>use-after-free</category><category>memory-corruption</category><category>rce</category><category>javascript-engine</category><category>sandbox-escape</category></item><item><title>c-ares TCP ares_getaddrinfo() Use-After-Free Code Execution</title><link>https://poc.intelseclab.com/pocs/network/2026-07-03_c-ares-tcp-getaddrinfo-uaf/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-03_c-ares-tcp-getaddrinfo-uaf/</guid><description>High severity — network · None assigned as of 2026-07-03. Status: PoC. Affects: c-ares (async DNS resolver library). Tags: c-ares, use-after-free, dns, resolver, tcp, heap-corruption, code-execution, edns.</description><category>network</category><category>High</category><category>c-ares</category><category>use-after-free</category><category>dns</category><category>resolver</category><category>tcp</category><category>heap-corruption</category><category>code-execution</category><category>edns</category></item><item><title>PinTheft: RDS Double-Free → LPE</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-20_pintheft-rds-double-free/</link><pubDate>Wed, 20 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-20_pintheft-rds-double-free/</guid><description>High severity — binary. Status: Weaponized. Affects: Linux kernel (RDS subsystem + io_uring). Tags: LPE, double-free, use-after-free, Linux kernel, RDS, io_uring, page-cache-overwrite, x86_64, local.</description><category>binary</category><category>High</category><category>LPE</category><category>double-free</category><category>use-after-free</category><category>Linux kernel</category><category>RDS</category><category>io_uring</category><category>page-cache-overwrite</category><category>x86_64</category><category>local</category></item><item><title>Chrome WebGPU Use-After-Free (CVE-2026-5281)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-18_chrome-webgpu-use-after-free/</link><pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-18_chrome-webgpu-use-after-free/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-5281. Status: Weaponized. Affects: Google Chrome / Chromium WebGPU (Dawn backend). Tags: use-after-free, WebGPU, Chrome, Dawn, GPU, browser, unauthenticated.</description><category>web</category><category>High</category><category>use-after-free</category><category>WebGPU</category><category>Chrome</category><category>Dawn</category><category>GPU</category><category>browser</category><category>unauthenticated</category></item><item><title>Chrome CSSFontFeatureValuesMap Use-After-Free (CVE-2026-2441)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-16_chrome-cssfontfeaturevaluesmap-use-after-free/</link><pubDate>Sat, 16 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-16_chrome-cssfontfeaturevaluesmap-use-after-free/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-2441. Status: Weaponized. Affects: Google Chrome / Chromium-based browsers (Blink CSS engine). Tags: use-after-free, Chrome, Blink, CSSOM, renderer-rce, unauthenticated, drive-by.</description><category>web</category><category>High</category><category>use-after-free</category><category>Chrome</category><category>Blink</category><category>CSSOM</category><category>renderer-rce</category><category>unauthenticated</category><category>drive-by</category></item><item><title>HTTP Protocol Stack Remote Code Execution Vulnerability (CVE-2021-31166)</title><link>https://poc.intelseclab.com/pocs/network/2026-05-15_cve-2021-31166-http-sys-uaf/</link><pubDate>Fri, 15 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-05-15_cve-2021-31166-http-sys-uaf/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2021-31166. Status: Weaponized. Affects: Microsoft Windows HTTP Protocol Stack (http.sys). Tags: HTTP.sys, use-after-free, RCE, Windows, kernel, unauthenticated.</description><category>network</category><category>Critical</category><category>HTTP.sys</category><category>use-after-free</category><category>RCE</category><category>Windows</category><category>kernel</category><category>unauthenticated</category></item></channel></rss>