CVE-2026-37539Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Buffer overflow vulnerability in cannelloni v2.0.0 in CAN frame parsing in parser.cpp in function parseCANFrame, and decoder.cpp in function decodeFrame allowing remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted CAN FD frames.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-05-12)
  • 7 total mentions across 3 days

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-05-01: 2Mentions · 2026-05-02: 1Mentions · 2026-05-12: 4Technical Details · 2026-05-01: 2Technical Details · 2026-05-12: 305-0105-0205-12
Signal classification2 categories
Disclosure
571.4%
General
228.6%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-012
Disclosure2
2026-05-021
Disclosure1
2026-05-124
Disclosure2General2
Full discourse7 posts
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in cannelloni (CVE-2026-37539) https://vuldb.com/vuln/360766

    Post summary

    A new critical vulnerability (CVE-2026-37539) affecting the Cannelloni component has been reported, but the posted information lacks technical details or evidence of exploitation.

    0101068
    2.1K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-37539 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory Buffer overflow vulnerability in cannelloni v2.0.0 in CAN frame parsing in parser.cpp in function parseCANFrame, and decoder.cpp in function…

    Post summary

    A critical buffer overflow vulnerability (CVE-2026-37539) was disclosed in cannelloni v2.0.0’s CAN frame parsing functions with a CVSS 9.8 score, but no PoC, exploit, or remediation details are provided.

    1000033
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-37539 (CVSS 9.8) — multiple products. CVE: CVE-2026-37539 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    Critical vulnerability CVE-2026-37539 disclosed with a CVSS score of 9.8, indicating high severity.

    1000031
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    --- Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation. CVE: CVE-2026-37539 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The message lists a newly identified critical vulnerability (CVE-2026-37539) with its CVSS rating, but offers no technical context, mitigation guidance, PoC, or exploit details.

    1000032
    210 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-37539 Buffer overflow vulnerability in cannelloni v2.0.0 in CAN frame parsing in parser.cpp in function parseCANFrame, and decoder.cpp in function decodeFrame allowing remo… https://www.cve.org/CVERecord?id=CVE-2026-37539

    Post summary

    The text announces a buffer overflow vulnerability in cannelloni v2.0.0 with a brief technical description and a link to the CVE record, but it provides no evidence of exploits, active use, patches, or counter‑claims.

    00010149
    57.4K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-37539-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The text references a CVE advisory via a URL but offers no explicit details, PoC, exploit code, patch information, or evidence of active exploitation.

    0000022
    210 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-37539 Buffer overflow vulnerability in cannelloni v2.0.0 in CAN frame parsing in parser.cpp in function parseCANFrame, and decoder.cpp in function decodeFrame allowing remo… https://www.cve.org/CVERecord?id=CVE-2026-37539 ----- Traducción: Vulnerabilidad de … http://infoflow.cloud`

    Post summary

    CVE-2026-37539 describes a buffer overflow in cannelloni v2.0.0’s CAN frame parsing functions, with details linked to the CVE record. No exploit or patch information is provided.

    0000026
    75 followersView on X

Explore more