CVE-2026-10046Disclosure(bitdefender / napoca)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch bitdefender napoca systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the BIOS INT 0x15 / E820 memory map handler, implemented in napoca/guests/bios_handlers.c. The handler computes a destination offset into the guest RealModeMemory buffer from guest-controlled ES and EDI register values without validating that the resulting address remains within the 1MB RealModeMemory allocation. A malicious guest operating in real mode can trigger the issue by invoking INT 0x15 with AX=0xE820, EDX=0x534D4150, ECX greater than or equal to 20, EBX=0, ES=0xFFFF, and EDI=0xFFFF. This can cause a write of up to 20 bytes past the end of the RealModeMemory buffer into the hypervisor heap. The product is end-of-life and unsupported when assigned.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • napoca

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
napoca

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-20: 1Patch / Workaround · 2026-06-20: 1Technical Details · 2026-06-20: 106-20
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Disclosure

    CVE-2026-10046 Bitdefender Napoca bare-metal hypervisorの脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/06/17/cve-2026-10046-bitdefender-napoca-bare-metal-hypervisor/ #IT #Security #cybersecurity

    Post summary

    The content links to an article that explains the Bitdefender Napoca bare‑metal hypervisor vulnerability, including its impact scope and mitigation steps, but it does not mention PoC, exploit code, or active exploitation.

    0000048
    208 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbitdefendernapoca---

Explore more