CISA KEV · catalog date Aug 12, 2025 · first observed Jul 19, 2026
Evidence dossier
CVE-2007-0671
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary…
Exploited in the wild (CISA KEV since Aug 12, 2025). NVD reports CVSS 2.0 9.3. EPSS estimates 42.1% exploit likelihood as of Aug 26, 2026.
As of Aug 27, 2026
Normalized restatement
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
- State
- PUBLISHED
- Published
- Feb 3, 2007
- Updated
- Jan 12, 2026
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAmicrosoftOriginal evidence ↗
Record text: Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
Inspect raw assertion
- Field
container- Value
- Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Microsoft Office Excel Remote Code Execution Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Microsoft Office Excel Remote Code Execution Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 42.14% probability · 98.59th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.421390000000; percentile 0.985900000000
FIRST EPSS · score date Aug 26, 2026 · 98.6th percentile · first observed Aug 26, 2026
NVD · CVSS 2.0 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
Inspect raw assertion
- Field
container- Value
- Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
Microsoft Office Excel Remote Code Execution Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Microsoft Office Excel Remote Code Execution Vulnerability
42.14% probability · 98.59th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.421390000000; percentile 0.985900000000
Applicability
Cited product scope
Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
15 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "n/a"}]product-f82e086bdc8d68f87a10bb8343a95e7e41ef64f3d69753d177cd7e35aa267fd7Linked exactInspect raw assertions
cpe:2.3:a:microsoft:access:2002:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
83dffff4-ea09-48c5-a600-a62c1a1a7360
cpe:2.3:a:microsoft:access:2003:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ec4ae5af-c83e-4802-b75c-0058742a4997
cpe:2.3:a:microsoft:access:2000:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
90d7ba07-3bca-41cf-b5d3-341e912650a2
product-1583a0890c2b29ac138d93d8997cbf1b2f38a707f8b4b5b3d38e281b544e22acLinked exactInspect raw assertions
cpe:2.3:a:microsoft:excel:2002:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
082d3262-87e3-4245-ad9c-02be0871fa3b
cpe:2.3:a:microsoft:excel:2003:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5f79e0ab-7081-4f97-bfe4-9af84f643b9a
cpe:2.3:a:microsoft:excel:2000:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f55d42d5-7371-47c2-bf55-b7f51c19b61e
product-e46a9abcf48416d41bf88f63588659e78f987bd8cd253d7bb89f21d827b1e9aeLinked exactInspect raw assertion
cpe:2.3:a:microsoft:excel_viewer:2003:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fdb0020c-a804-4003-b411-1ac7a6e7193e
product-f7c61cf32a3923054f54a414cb098cef2fcd791937f5e10bff3390aed1b5a49fLinked exactInspect raw assertions
cpe:2.3:a:microsoft:frontpage:2003:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3c79fee1-70a3-4a48-be7b-0d18f0a5fa7f
cpe:2.3:a:microsoft:frontpage:2002:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6548f837-a687-4eef-b754-daa834b34fa3
cpe:2.3:a:microsoft:frontpage:2000:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d2c6629c-bf53-49a1-b32c-a828ca0a0500
product-bad61f3b9dcd83193da259eda1fd0f34f944f8df225dc6ed50bbf6c7f4525ce3Linked exactInspect raw assertion
cpe:2.3:a:microsoft:infopath:2003:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
345bc07e-1558-4c27-bf1a-c13547d175fc
product-f4efee17050cd92d62299077c43827052b373ddcb783c02caa43c2fbb378d2f4Linked exactInspect raw assertions
cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
79ba1175-7f02-4435-aea6-1ba8aadeb7ef
cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
07d3f3e4-93fb-481a-94d9-075e726697c4
cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4891122f-ad7f-45e6-98c6-833227916f6b
cpe:2.3:a:microsoft:office:2004:*:*:*:*:macos:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0b191155-67f2-4c6e-bd0c-af5af6f04ba1
product-14deb9bab4421d36bf543ac7d1fd64a2d1209dfc08178095b8f5e8df6da7f9bdLinked exactInspect raw assertion
cpe:2.3:a:microsoft:onenote:2003:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
36ba88a3-a31f-4f90-8913-67d5bc00e72d
product-b312c98eb5c91fc7c3e69712233ab82c14dbc3f5723b9932de5a535b454ad87cLinked exactInspect raw assertions
cpe:2.3:a:microsoft:outlook:2003:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c3189982-f780-4ac2-9663-e6d4df9dd319
cpe:2.3:a:microsoft:outlook:2002:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3fe6eae0-5a8f-4a97-950b-879379a3c0f8
cpe:2.3:a:microsoft:outlook:2000:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d52f17ab-2c87-4c1a-91b5-267abbcf5844
product-f5544f869f38a3f8d5d104c4cee9f7ea30df3e81d445ce6ec2ae8dae7f1536b9Linked exactInspect raw assertions
cpe:2.3:a:microsoft:powerpoint:2002:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
711d9cc0-31b8-4511-a9f3-ca328a02ed84
cpe:2.3:a:microsoft:powerpoint:2003:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 21
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f5611efd-2c7c-47ba-83e5-947ea00d8e6c
cpe:2.3:a:microsoft:powerpoint:2000:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3e392539-abf6-4b5c-aec3-c54b51e0db70
product-5d859228393bc4bfc689137ab6b855be0e912332adcbd936cd1ac48eda300b02Linked exactInspect raw assertions
cpe:2.3:a:microsoft:project:2000:sr1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 22
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6f0ef69e-52ba-4d7c-b470-cb4a92da7eac
cpe:2.3:a:microsoft:project:2002:sp1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 23
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9b14ae8e-1bff-4458-87cc-357957f18f8a
cpe:2.3:a:microsoft:project:2003:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 24
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
34efaefe-2bde-4111-91f5-e9f75adfa920
product-a2f6d163b6f7cfae74c162d96e1e0e5a739e3c02595f036ab14f33eb6e6a44d6Linked exactInspect raw assertions
cpe:2.3:a:microsoft:publisher:2002:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 26
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
99ed878a-cfc5-4fd5-a403-eb16cc4f8bc0
cpe:2.3:a:microsoft:publisher:2000:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 25
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
95648599-d3b3-4043-821c-d385fb7a77cb
cpe:2.3:a:microsoft:publisher:2003:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 27
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
617e8be3-8ad0-42fc-bdee-6b1f120ae512
product-b5718aea31f83317adfbbd2f22cf1cb081941e2d6cb90fee22ceda5a6e146678Linked exactInspect raw assertions
cpe:2.3:a:microsoft:visio:2003:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 29
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
511e22c6-db04-44a0-906d-f432dd42ca5c
cpe:2.3:a:microsoft:visio:2002:sp2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 28
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d0d2c5c3-225c-49dc-b9c7-c5bc05900f2e
product-c8093d22ed2cea792c0cc0ce039b1c82530e9d7a56e9ab1184596470080024c2Linked exactInspect raw assertions
cpe:2.3:a:microsoft:word:2000:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 30
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
aebff713-0884-43bf-9ab8-777664fd64af
cpe:2.3:a:microsoft:word:2003:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 32
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
379c2a4a-78ef-473d-954b-f5dd76c3d6cf
cpe:2.3:a:microsoft:word:2002:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 31
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2d90b1e1-23cd-4595-ad78-da1758e9896d
product-c2784642373eeb668f810662116d55b2dcac8ab816783b65ebffb4d610791a73Linked exactInspect raw assertion
cpe:2.3:a:microsoft:word_viewer:2003:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 33
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1889a686-9565-4958-99bb-2ec24abdf272
Affected-product evidence
Accepted scope and product mapping
14 canonical links · 1 source-reported links
vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-14deb9bab4421d36bf543ac7d1fd64a2d1209dfc08178095b8f5e8df6da7f9bd
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ae860f93-6a8f-4614-8f8a-985ea2da3a0cvendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-1583a0890c2b29ac138d93d8997cbf1b2f38a707f8b4b5b3d38e281b544e22ac
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
91e70424-a18d-496c-aeac-e510a796c105c71703ea-60da-4389-859e-cb4deb0b4e0cfbd8e2b1-234c-4f13-8b20-6a72951ae3b1vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-5d859228393bc4bfc689137ab6b855be0e912332adcbd936cd1ac48eda300b02
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2075e33a-ebc8-418b-a275-a48614f3a547aa2ff3c7-a9f3-43b2-aa57-c9626f276711daa9aa5d-4f36-4c2e-81f3-21d8a0e0ddb4vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-a2f6d163b6f7cfae74c162d96e1e0e5a739e3c02595f036ab14f33eb6e6a44d6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
514d7369-6cba-416e-b426-5de2a993a60353d30d05-0173-4385-b1b1-ed564379cba560bf18b7-c844-48aa-86b1-8a526a4b430avendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-b312c98eb5c91fc7c3e69712233ab82c14dbc3f5723b9932de5a535b454ad87c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1b77db0c-cd5e-47ed-8346-d4dd8c797b6a423a78b9-8ecb-41c4-ae34-a8221d6980a1dd194fbc-d20e-45cc-a4a7-de70958bd094vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-b5718aea31f83317adfbbd2f22cf1cb081941e2d6cb90fee22ceda5a6e146678
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6a6257f9-c729-4c1a-beaa-713c24ff5d4aa435e820-cb46-4c30-bbc1-29af7bdb4fc9vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-bad61f3b9dcd83193da259eda1fd0f34f944f8df225dc6ed50bbf6c7f4525ce3
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1c5a8a01-ef5d-4745-9065-96d4c0b6f27dvendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-c2784642373eeb668f810662116d55b2dcac8ab816783b65ebffb4d610791a73
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
130f3e5a-b042-4624-9747-63516459822evendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-c8093d22ed2cea792c0cc0ce039b1c82530e9d7a56e9ab1184596470080024c2
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4767680c-5e5a-4d95-9d1c-b8fa67b3e86f7e3c9ff3-fd30-460f-ba5f-1431896cc5ffc185874c-e982-4c63-8e5c-6953a93356e2vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-e46a9abcf48416d41bf88f63588659e78f987bd8cd253d7bb89f21d827b1e9ae
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a93e3d05-c38b-42b9-90cd-df37686c5e34vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-f4efee17050cd92d62299077c43827052b373ddcb783c02caa43c2fbb378d2f4
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
037ab729-834a-4dc3-b112-efac6e6a9e4086a4de7b-7ef5-49a0-88a6-83e2710336caae92a450-5ad5-46dd-99ce-d151135850dbdd616b7e-12da-4e8c-b3cd-62e1cbe810d8vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-f5544f869f38a3f8d5d104c4cee9f7ea30df3e81d445ce6ec2ae8dae7f1536b9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
15f48547-60c9-4f76-9dcc-5ca9e898a0e59e584ba5-8b2e-4416-9593-5023f31d9677e1c4a13b-a069-46d5-a292-26df1f3bb3bcvendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-f7c61cf32a3923054f54a414cb098cef2fcd791937f5e10bff3390aed1b5a49f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6ee0ad20-23f1-4e5d-974b-95e68139c753b9992353-c1d5-446d-82b5-a9a626607da7f5fdb377-73e4-442b-85cf-73b2cecfc343vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-f82e086bdc8d68f87a10bb8343a95e7e41ef64f3d69753d177cd7e35aa267fd7
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
75fdf3bd-7e2f-4fa5-be49-ac414e6ccd6e84bf55cb-76da-4e2b-9e30-ef3e1ac744cae232d027-3c3c-4c81-a322-8d78ae94619dCanonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
849883b0-035b-4354-bba4-4bbbbfecfd73Assessments
CVSS by origin
AV:N/AC:M/Au:N/C:C/I:C/A:CCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 8.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.