Evidence dossier

CVE-2016-0984

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before…

Exploited in the wild (CISA KEV since May 25, 2022). NVD reports CVSS 3.1 8.8. EPSS estimates 54.8% exploit likelihood as of Aug 26, 2026.

81.882.8Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0975, CVE-2016-0982, and CVE-2016-0983.

State
PUBLISHED
Published
Feb 10, 2016
Updated
Oct 21, 2025
Evidence coverage
98%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    adobe

    Record text: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0975, CVE-2016-0982, and CVE-2016-0983.

    Inspect raw assertion
    Field
    container
    Value
    Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0975, CVE-2016-0982, and CVE-2016-0983.
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Adobe Flash Player and AIR Use-After-Free Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Adobe Flash Player and AIR Use-After-Free Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 54.82% probability · 98.94th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.548230000000; percentile 0.989440000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date May 25, 2022 · first observed Jul 19, 2026

Exploit likelihood54.82%

FIRST EPSS · score date Aug 26, 2026 · 98.9th percentile · first observed Aug 26, 2026

SeverityCVSS 8.8

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

adobeOriginal assertion
Record text

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0975, CVE-2016-0982, and CVE-2016-0983.

Inspect raw assertion
Field
container
Value
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0975, CVE-2016-0982, and CVE-2016-0983.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Adobe Flash Player and AIR Use-After-Free Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Adobe Flash Player and AIR Use-After-Free Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

54.82% probability · 98.94th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.548230000000; percentile 0.989440000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
30Underlying assertions
11Canonical products
9Target assertions
21Constraint assertions

Grouped from 18 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

12 scope groups

adobe · source assertedn/an/aDirect source scope
Affected: n/a
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "n/a"}]
NVD CPE · APPLICATIONadobeair_desktop_runtimeVulnerable target · 1 assertions
Any version (unconstrained) (<= 20.0.0.233)Canonical identity product-8862afa523d3ff2dc78c25c5bf5acfb5e8e6df7328b20f18db42d719d275dabaLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:adobe:air_desktop_runtime:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 20.0.0.233
    Match ID
    18ba497d-0c1d-451e-b54f-4028fd9b9f3b
NVD CPE · APPLICATIONadobeair_sdkVulnerable target · 1 assertions
Any version (unconstrained) (<= 20.0.0.233)Canonical identity product-e44dcbf8c4c122584d6ac7a190a497467e19af3f5c616ce3282a2f37f63ff2d8Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 20.0.0.233
    Match ID
    f09c5c9a-0493-4601-84ae-3a9c5985231d
NVD CPE · APPLICATIONadobeair_sdk_&_compilerVulnerable target · 1 assertions
Any version (unconstrained) (<= 20.0.0.233)Canonical identity product-22321f03f561ecf8f72f94c51abf51e8add9af519516028ad03c6e24adf2ff75Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:adobe:air_sdk_\&_compiler:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 20.0.0.233
    Match ID
    00d08966-361a-430d-9b39-ed143404ebf6
NVD CPE · APPLICATIONadobeflash_playerVulnerable target · 5 assertions
Any version (unconstrained) (<= 11.2.202.559); Any version (unconstrained) (<= 18.0.0.326); Any version (unconstrained) (<= 20.0.0.272); Any version (unconstrained) (<= 20.0.0.286)Canonical identity product-1f43dd2fb9df2cb64d1a717194e5325cf3f2d14dbb24ebbb35d9226a3dc1cbe7Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:adobe:flash_player:*:*:*:*:esr:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 18.0.0.326
    Match ID
    002cfea6-d147-44b4-90fc-0d3c68d96082
  2. cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 11.2.202.559
    Match ID
    9c8c62c1-327a-4d04-a51c-0614db4f5493
  3. cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 20.0.0.272
    Match ID
    e823e5fe-7367-41de-8cd7-842c5c2f53ce
  4. cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 20.0.0.272
    Match ID
    f40fbaab-92fc-45af-b656-e87ecc4c4816
  5. cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 20.0.0.286
    Match ID
    686929a4-eb67-47b6-87ec-453bcd13fe20
NVD CPE · APPLICATIONadobeflash_player_desktop_runtimeVulnerable target · 1 assertions
Any version (unconstrained) (<= 20.0.0.286)Canonical identity product-e88d4a258d64441204084b8bcb44aeb5ff626244a98017d14a89850fecbd9d2fLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 20.0.0.286
    Match ID
    bafa5674-4ebc-4587-87c6-22a522b487c6
NVD CPE · OPERATING SYSTEMappleiphone_osEnvironmental constraint · 2 assertions
Version not applicableCanonical identity product-665d7155d02581979844685e7fca6c2680af997f9200af455887b1c71c483272Linked exact
Scope constrained
Inspect raw assertions
  1. cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    8 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b5415705-33e5-46d5-8e4d-9ebadc8c5705
  2. cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    7 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b5415705-33e5-46d5-8e4d-9ebadc8c5705
NVD CPE · OPERATING SYSTEMapplemac_os_xEnvironmental constraint · 6 assertions
Version not applicableCanonical identity product-94613e1f5039e71a9805f20421d56ac6a61e2707d3f97a08fdf6823a65dc7b76Linked exact
Scope constrained
Inspect raw assertions
  1. cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    4 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4781bf1e-8a4e-4aff-9540-23d523ee30dd
  2. cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    6 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4781bf1e-8a4e-4aff-9540-23d523ee30dd
  3. cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    3 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4781bf1e-8a4e-4aff-9540-23d523ee30dd
  4. cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    8 · node/1 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4781bf1e-8a4e-4aff-9540-23d523ee30dd
  5. cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    5 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4781bf1e-8a4e-4aff-9540-23d523ee30dd
  6. cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    7 · node/1 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4781bf1e-8a4e-4aff-9540-23d523ee30dd
NVD CPE · OPERATING SYSTEMgoogleandroidEnvironmental constraint · 2 assertions
Version not applicableCanonical identity product-92706ad297e0bcadcd6adc374dd80eb27012c37cd92e19cf49650461139673ecLinked exact
Scope constrained
Inspect raw assertions
  1. cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    7 · node/1 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f8b9fec8-73b6-43b8-b24e-1f7c20d91d26
  2. cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    8 · node/1 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f8b9fec8-73b6-43b8-b24e-1f7c20d91d26
NVD CPE · OPERATING SYSTEMgooglechrome_osEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-b52d99a799eb1164ea8aa4323a348a4e22f9a18f12d38b746456eb597b7a5d3dLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:o:google:chrome_os:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    5 · node/1 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d32acf6f-5ff7-4815-8ead-4719f5fc9b79
NVD CPE · OPERATING SYSTEMlinuxlinux_kernelEnvironmental constraint · 2 assertions
Version not applicableCanonical identity product-0eda7a801761be4590f267cf319481c8c0aaa30546d99cc064edf77989ce05c9Linked exact
Scope constrained
Inspect raw assertions
  1. cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    703af700-7a70-47e2-bc3a-7fd03b3ca9c1
  2. cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    5 · node/1 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    703af700-7a70-47e2-bc3a-7fd03b3ca9c1
NVD CPE · OPERATING SYSTEMmicrosoftwindowsEnvironmental constraint · 8 assertions
Version not applicableCanonical identity product-6a798dc931affc038ba266631a506d54b455ffebd96b4fae68f77b6bd7aef178Linked exact
Scope constrained
Inspect raw assertions
  1. cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    6 · node/1 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a2572d17-1de6-457b-99cc-64afd54487ea
  2. cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    4 · node/1 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a2572d17-1de6-457b-99cc-64afd54487ea
  3. cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    8 · node/1 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a2572d17-1de6-457b-99cc-64afd54487ea
  4. cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    5 · node/1 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a2572d17-1de6-457b-99cc-64afd54487ea
  5. cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a2572d17-1de6-457b-99cc-64afd54487ea
  6. cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    7 · node/1 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a2572d17-1de6-457b-99cc-64afd54487ea
  7. cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a2572d17-1de6-457b-99cc-64afd54487ea
  8. cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    3 · node/1 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a2572d17-1de6-457b-99cc-64afd54487ea

Affected-product evidence

Accepted scope and product mapping

5 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-70d8e9d1eb9ce5b2e6b4c9351aebc88bced6ea77611cbc8d5cdbe8115b6faed8 · product-1f43dd2fb9df2cb64d1a717194e5325cf3f2d14dbb24ebbb35d9226a3dc1cbe7

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5015a3c3-edf3-4101-ba82-80b1f947e1876614bb3b-034c-43c8-84ac-270c9176269577bc2699-a123-45e6-8ee3-71bb9b4e18247e20b167-9d48-4f2c-bd16-de236f1fad55e1063baf-74d6-48fa-ae2a-9f43accbcd74
Mapping establishedEvidence supported

vendor-70d8e9d1eb9ce5b2e6b4c9351aebc88bced6ea77611cbc8d5cdbe8115b6faed8 · product-22321f03f561ecf8f72f94c51abf51e8add9af519516028ad03c6e24adf2ff75

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
719b8ccb-1b5c-44d7-b52a-1432023412d8
Mapping establishedEvidence supported

vendor-70d8e9d1eb9ce5b2e6b4c9351aebc88bced6ea77611cbc8d5cdbe8115b6faed8 · product-8862afa523d3ff2dc78c25c5bf5acfb5e8e6df7328b20f18db42d719d275daba

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5e0b379d-094d-4ec5-b4e5-cb485eec036d
Mapping establishedEvidence supported

vendor-70d8e9d1eb9ce5b2e6b4c9351aebc88bced6ea77611cbc8d5cdbe8115b6faed8 · product-e44dcbf8c4c122584d6ac7a190a497467e19af3f5c616ce3282a2f37f63ff2d8

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
fdef6676-38d9-47e2-8648-274563f05576
Mapping establishedEvidence supported

vendor-70d8e9d1eb9ce5b2e6b4c9351aebc88bced6ea77611cbc8d5cdbe8115b6faed8 · product-e88d4a258d64441204084b8bcb44aeb5ff626244a98017d14a89850fecbd9d2f

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
21ca4abb-f0a0-4243-819c-85f5e31fda29
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5624b79d-5351-4dc5-9ed2-3ef397d7d115

Assessments

CVSS by origin

8.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
9.3
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:M/Au:N/C:C/I:C/A:C
8.8
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

8.8Priority eligible

CISA-ADP

CVSS 3.1 · Secondary · Independent enrichment · rank 2

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Validation
Valid match
Recomputed
8.8
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.