CVE-2026-4012General

LOWCVSS 1.9 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in rxi fe up to ed4cda96bd582cbb08520964ba627efb40f3dd91. The impacted element is the function read_ of the file src/fe.c. This manipulation with the input 1 causes out-of-bounds read. The attack requires local access. The exploit has been publicly disclosed and may be utilized. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-12); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Mentions · 2026-04-16: 1Patch / Workaround · 2026-04-16: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 1Technical Details · 2026-04-16: 103-1203-1304-16
Signal classification3 categories
General
133.3%
Disclosure
133.3%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-121
General1
2026-03-131
Disclosure1
2026-04-161
Patch1
Full discourse3 posts
  • Systemctl status active 🟢@TheNetworkGhost
    Patch

    Palo Alto Networks, Prisma Cloud üzerinde "unauthenticated" veri sızıntısına yol açabilecek bir zafiyeti (CVE-2026-4012) yamaladı! ☁️🔒 Saldırganlar, bulut envanterinize yetkisiz erişim sağlayabiliyor. Hibrit bulut yöneten ekiplerin konsollarını acilen kontrol etmesi şart. Bulutun anahtarı, yanlış ellerde büyük risk! 🔑⚠️ Kaynak: https://security.paloaltonetworks.com/ #PaloAltoNetworks #CloudSecurity #PrismaCloud #CyberSecurity #Infosec

    Post summary

    Palo Alto Networks released a patch for CVE‑2026‑4012, a vulnerability that could allow unauthenticated data leakage in Prisma Cloud, and urged teams to check their cloud inventories.

    0003054
    76 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4012 A vulnerability was determined in rxi fe up to ed4cda96bd582cbb08520964ba627efb40f3dd91. The impacted element is the function read_ of the file src/fe.c. This manipulat… https://www.cve.org/CVERecord?id=CVE-2026-4012

    Post summary

    A new CVE-2026-4012 vulnerability has been disclosed, affecting the read_ function in the src/fe.c file of the rxi fe project, with technical details available on the CVE record.

    00000164
    56.7K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-4012 📊 Severity: 3.3 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4012 #CVE-2026-4012 #CVE #Low  #CyberSecurity #InfoSec https://t.co/L1vWzxn1eS

    Post summary

    The tweet only announces a low‑severity CVE with no further exploit, patch, or detailed technical information.

    0000030
    96 followersView on X

Explore more