CVE-2026-3968Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in AutohomeCorp frostmourne up to 1.0. This affects the function scriptEngine.eval of the file ExpressionRule.java of the component Oracle Nashorn JavaScript Engine. Such manipulation of the argument EXPRESSION leads to code injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-12: 3Technical Details · 2026-03-12: 203-12
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Full discourse3 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-3968 📊 Severity: 6.3 🚨 Risk Level: Medium 🧩 Affects: Oracle Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3968 #CVE-2026-3968 #CVE #Medium #Oracle #CyberSecurity #InfoSec https://t.co/RnTNP4zcDy

    Post summary

    A new Oracle vulnerability (CVE‑2026‑3968) with a CVSS score of 6.3 (medium severity) has been announced; no proof‑of‑concept, exploit, or active exploitation is reported.

    0000029
    96 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3968 A vulnerability has been found in AutohomeCorp frostmourne up to 1.0. This affects the function scriptEngine.eval of the file http://ExpressionRule.java of the component Oracl… https://www.cve.org/CVERecord?id=CVE-2026-3968

    Post summary

    The sentence announces the discovery of CVE-2026-3968, noting it affects the scriptEngine.eval function in ExpressionRule.java of AutohomeCorp frostmourne, but provides no further actionable details.

    00000111
    56.7K followersView on X
  • Fernando Karl@fernandokarl
    Disclosure

    🔍 Discover the details of CVE-2026-3968! A critical vulnerability that could expose your systems to threats. Ensure your defenses are up to date and assess your risk. 👉 Read more here: https://www.tenable.com/cve/CVE-2026-3968 #Cybersecurity #VulnerabilityManagement

    Post summary

    The tweet warns about CVE-2026-3968 as a critical vulnerability and directs readers to Tenable for details, but it does not provide technical information, exploit assets, or patch guidance.

    0000045
    256 followersView on X

Explore more