CVE-2026-10649Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-06-16); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-06-16: 1Mentions · 2026-06-18: 1Mentions · 2026-07-01: 1Mentions · 2026-07-20: 1Patch / Workaround · 2026-07-01: 1Patch / Workaround · 2026-07-20: 1Technical Details · 2026-06-16: 1Technical Details · 2026-06-18: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-20: 106-1606-1807-0107-20
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-161
Disclosure1
2026-06-181
Disclosure1
2026-07-011
Patch1
2026-07-201
Patch1
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-10649: Pacemaker: DoS via integer overflow in remote message decompression https://www.openwall.com/lists/oss-security/2026/06/16/6 By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption. Impact beyond DoS not ruled out.

    Post summary

    The text announces CVE-2026-10649, detailing an integer-overflow vulnerability in Pacemaker’s message decompression that can lead to memory corruption and DoS, with no evidence of active exploitation or available patches.

    00051306
    4.7K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    O Patch SUSE-2026-2716-1 para Pacemaker: CVE-2026-10649 (integer overflow → DoS) corrigida em SLES 15 SP6 e openSUSE Leap 15.6. Saiba mais: -> http://tinyurl.com/mrx2bcrt #SUSE https://t.co/p4Cx6RdVsP

    Post summary

    The tweet announces a SUSE patch for CVE-2026-10649, an integer overflow causing DoS in Pacemaker, and directs users to the patch URL.

    1000070
    1.5K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-10649 (CVSS 8.6) - Pacemaker integer overflow flaw allows unauthenticated remote attackers to cause DoS via crafted compressed messages. Memory corruption can crash CIB remote listener. Patch immediately. #CVE #PatchNow #ThreatIntel https://t.co/vOnFYggRl5

    Post summary

    A high‑severity integer overflow in Pacemaker can be exploited remotely for DoS; vendors are urged to apply the available patch immediately.

    0000031
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-10649 A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sendin… https://www.cve.org/CVERecord?id=CVE-2026-10649

    Post summary

    CVE-2026-10649 is disclosed as an integer overflow in Pacemaker’s remote message decompression that allows unauthenticated remote attackers to gain influence; no exploit code or active misuse is reported.

    00000160
    57.6K followersView on X

Explore more