CVE-2026-48618Patch

LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-07-02)
  • 7 total mentions across 6 days

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-06-19: 1Mentions · 2026-06-21: 1Mentions · 2026-06-22: 1Mentions · 2026-06-26: 1Mentions · 2026-07-01: 1Mentions · 2026-07-02: 2Patch / Workaround · 2026-06-19: 1Patch / Workaround · 2026-06-21: 1Patch / Workaround · 2026-06-22: 1Technical Details · 2026-06-19: 1Technical Details · 2026-06-21: 1Technical Details · 2026-06-26: 106-1906-2106-2206-2607-0107-02
Signal classification3 categories
Patch
342.9%
Disclosure
342.9%
General
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-06-191
Patch1
2026-06-211
Patch1
2026-06-221
Patch1
2026-06-261
Disclosure1
2026-07-011
General1
2026-07-022
Disclosure2
Full discourse7 posts
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Node.js ❗ CVE-2026-48933 ❗ CVE-2026-48618 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-node-js-2/ https://t.co/HuO8PJ3WnA

    Post summary

    The tweet announces two new Node.js CVEs (CVE-2026-48933 and CVE-2026-48618) and directs readers to a CERT page for further information.

    01020278
    6.7K followersView on X
  • Stuart 🇨🇷@stooee_
    Disclosure

    After analyzing 44% of vulnerabilities from past week, CVE-2026-48618 has 9 articles published from different internet sources, no other cve has these many articles. More information here: https://cves.st00ee.com/ #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    Post summary

    The tweet announces CVE‑2026‑48618, noting many related articles, but does not provide technical details, exploits, or patch information.

    0000050
    75 followersView on X
  • Stuart 🇨🇷@stooee_
    General

    After analyzing 33% of vulnerabilities from past week, CVE-2026-48618 has 8 articles published from different internet sources, no other cve has these many articles. More information here: https://cves.st00ee.com/ #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    Post summary

    The post highlights that CVE-2026-48618 attracted more media attention than other recent CVEs but offers no specific exploit, Patch, or technical details.

    0000050
    75 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-48618 TLS Wildcard Authentication Bypass via Unicode Dot Separator in N... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-48618 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    This tweet announces CVE‑2026‑48618, identifying it as a TLS wildcard authentication bypass caused by a Unicode dot separator, and provides a link for further details, but offers no PoC, exploit code, or evidence of active exploitation.

    00000121
    4.1K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Node.js、2026年6月のセキュリティリリースで12件の脆弱性を修正(CVE-2026-48933,CVE-2026-48618)他 https://rocket-boys.co.jp/security-measures-lab/nodejs-vulnerabilities-cve-2026-48933-cve-2026-48618/ #セキュリティ対策Lab #security #securitynews

    Post summary

    Node.js released a security update in June 2026 that fixes 12 vulnerabilities, including CVE-2026-48933 and CVE-2026-48618, as announced in the referenced security lab article.

    00000117
    436 followersView on X
  • Diego Artiles@dartilesm
    Patch

    🚨 Node.js patched all active LTS lines on June 18. CVE-2026-48618: IPv6 dots bypass TLS wildcard certs. CVE-2026-48933: WebCrypto AES crash, remote process abort. Patch to 22.23.0 / 24.17.0 / 26.3.1. How long before your team ships this?

    Post summary

    Node.js LTS lines were patched on June 18, fixing CVE-2026-48618 (IPv6 dots TLS wildcard bypass) and CVE-2026-48933 (WebCrypto AES crash), with the applicable upgrade to v22.23.0, v24.17.0, or v26.3.1.

    0000045
    49 followersView on X
  • Can Artuc@canartuc
    Patch

    Node.js shipped 22.23.0, 24.17.0 and 26.3.1 on June 18, fixing 13 CVEs. Two are rated HIGH: CVE-2026-48933, a WebCrypto AES integer overflow that aborts the process, and CVE-2026-48618, a TLS wildcard-depth check fooled by a Unicode dot separator. Which release line do you run?

    Post summary

    Node.js announced a release on June 18 that patches 13 CVEs, including two high‑severity ones (CVE‑2026‑48933 and CVE‑2026‑48618), focusing on the availability of the fixes.

    0000047
    171 followersView on X

Explore more