CISA KEV · catalog date May 12, 2023 · first observed Jul 19, 2026
Evidence dossier
CVE-2016-3427
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77;
Exploited in the wild (CISA KEV since May 12, 2023). NVD reports CVSS 3.1 9.8. EPSS estimates 92.3% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
- State
- PUBLISHED
- Published
- Apr 21, 2016
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAoracleOriginal evidence ↗
Record text: Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
Inspect raw assertion
- Field
container- Value
- Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Oracle Java SE and JRockit Unspecified Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Oracle Java SE and JRockit Unspecified Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 92.33% probability · 99.82th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.923340000000; percentile 0.998150000000
FIRST EPSS · score date Aug 27, 2026 · 99.8th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
Inspect raw assertion
- Field
container- Value
- Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
Oracle Java SE and JRockit Unspecified Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Oracle Java SE and JRockit Unspecified Vulnerability
92.33% probability · 99.82th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.923340000000; percentile 0.998150000000
Applicability
Cited product scope
Grouped from 7 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
39 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "n/a"}]product-fdcdb328ae5a693817ced8bc365aa2cb900f7c7f407ca30bc5149de5335df6b2Linked exactInspect raw assertions
cpe:2.3:a:apache:cassandra:4.0.0:beta1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a7b8b2b7-874c-45c7-88b9-caef8f12d1ea
cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 3
- Logic
- OR
- Version bounds
- from including 3.11.0; through excluding 3.11.8
- Match ID
291dafa7-48c8-43d0-a800-fc0337764eb4
cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 2.2.0; through excluding 2.2.18
- Match ID
53ec5281-8a0b-45a9-8e05-6709516ddfcd
cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 2
- Logic
- OR
- Version bounds
- from including 3.0.0; through excluding 3.0.22
- Match ID
ae85f320-9ad4-48ca-aad6-d3436e132204
cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 2.1.0; through excluding 2.1.22
- Match ID
bbcae701-dcf8-4031-a711-218d5adfad24
product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2Linked exactInspect raw assertions
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7a5301bf-1402-4be0-a0f8-69fbe79bc6d6
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
815d70a8-47d3-459c-a32c-9feaca0659d1
cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e88a537f-f4d0-46b9-9e37-965233c2a355
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cb66db75-2b16-4ebf-9b93-ce49d8086e41
product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447eLinked exactInspect raw assertion
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c11e6fb0-c8c0-4527-9aa0-cb9b316f8f43
product-ba31f92f83b2366f63448b819634143dda1c3ee0b74f918170f5fe22e6811567Linked exactInspect raw assertion
cpe:2.3:a:netapp:e-series_santricity_management_plug-ins:-:*:*:*:*:vmware_vcenter:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
280520bc-070c-4423-a633-e6fe45e53d57
product-3e21e0f5d039c1214aa1ef3a629a8ce3abb696dfc46de0455f77d614211cbc8bLinked exactInspect raw assertion
cpe:2.3:a:netapp:e-series_santricity_storage_manager:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0d9cc59d-6182-4b5e-96b5-226fcd343916
product-e425f76755163e7ac04fb77eb752192cdfcf6897c58b892c4c04b4e260342515Linked exactInspect raw assertion
cpe:2.3:a:netapp:e-series_santricity_web_services:-:*:*:*:*:web_services_proxy:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1aeff829-a8f2-4041-8ddf-e705db3aded2
product-1e7e71c5224a6f4135c855890a7cd875f6ac32bf0024c6ee2e888da0212d267eLinked exactInspect raw assertion
cpe:2.3:a:netapp:oncommand_balance:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7dcbcc5d-c396-47a8-adf4-d3a2c4377fb1
product-326f5a17c9ba94ff6d5e60b61be24e561176813b0856dc31836e10a9f580e7fcLinked exactInspect raw assertion
cpe:2.3:a:netapp:oncommand_cloud_manager:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
069d0ec4-be9d-44a9-82b0-36efa3702ea4
product-6bac5e5dc0babe5d628e246786e711716ddfb068132218ad0dd5123beb466ec4Linked exactInspect raw assertion
cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f1be6c1f-2565-4e97-92aa-16563e5660a5
product-0622850d7355e952441687d9dab9a9888a3f7429796731abeb2f2b417c9c9aa0Linked exactInspect raw assertion
cpe:2.3:a:netapp:oncommand_performance_manager:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
212e1878-1b9a-4cb4-a1ce-ead60b867161
product-e4499e4bc1e3fdada3eccdeba78f66bfafaa2616ca917f0baf4ea8490f7bf100Linked exactInspect raw assertion
cpe:2.3:a:netapp:oncommand_report:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
50e60feb-7fc2-491a-b492-5a5dc0a4821a
product-96fd4aeba8f0231e1d0f6ca7ae786e70d484258209c2dd2c10b095c6d07c6180Linked exactInspect raw assertion
cpe:2.3:a:netapp:oncommand_shift:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3bd81527-a341-42c3-9ab9-880d3db04b08
product-c8fd04cb7cbf514fd1a8bf9dafd5cd44499d96cff80cffaf10ccd171e11e4a5fLinked exactInspect raw assertions
cpe:2.3:a:netapp:oncommand_unified_manager:-:*:*:*:*:7-mode:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3fa5e22c-489b-4c5f-a5f3-c03f45ca8811
cpe:2.3:a:netapp:oncommand_unified_manager:-:*:*:*:*:clustered_data_ontap:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
95b173e0-1475-4f8d-a982-86f36be3dd4a
product-afac260708bb4bb1a51e28ce6b95f0356203366f8c8ffd2c790c3109033fc4fdLinked exactInspect raw assertion
cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5735e553-9731-4aac-bcff-989377f817b3
product-2bbc3c87cbaeb11c12dc34b42c7207fa49eea659fc62aa79757b51047802fc97Linked exactInspect raw assertion
cpe:2.3:a:netapp:storagegrid:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 12
- Logic
- OR
- Version bounds
- through including 9.0.4
- Match ID
73019fe2-f7ce-4b12-9dc1-8333f08a7d9c
product-f6df6ab8c95a532ed2dbb3be7d1d9a3fa82e2f90d8dd3e68fedb15893d69148fLinked exactInspect raw assertion
cpe:2.3:a:netapp:vasa_provider_for_clustered_data_ontap:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 13
- Logic
- OR
- Version bounds
- from including 7.2
- Match ID
13270f58-e106-48ce-9933-e68aabbbfc21
product-fb0ea92a45ee1fb244313dbcc32de14a48cb22f7c70356fe98c5d46384642096Linked exactInspect raw assertion
cpe:2.3:a:netapp:virtual_storage_console:*:*:*:*:*:vmware_vsphere:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 14
- Logic
- OR
- Version bounds
- from including 7.2
- Match ID
b7b42cb6-3c14-4183-afa8-c3682f8b54ab
product-c27aedc6088fe47e75f3a72d532ce7dcfb4a151fd6deaeecc763cf1d10026925Linked exactInspect raw assertion
cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4863be36-d16a-4d75-90d9-fd76db5b48b7
product-66ca8198d1887ac9754d1aad85d76f1edfc54c873eb2cd9bedf566863f5e07bdLinked exactInspect raw assertions
cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
03117df1-3bec-4b8d-ad63-dbbdb2126081
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a10bc294-9196-425f-9fb0-b1625465b47f
product-6c94a14e5689a64227066e3f60eeb2b8b30045bcbf08047234f29f3fdd35d120Linked exactInspect raw assertions
cpe:2.3:a:oracle:jdk:1.8.0:update77:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c6cac2ae-7fb0-40f4-9a45-533943a35772
cpe:2.3:a:oracle:jdk:1.7.0:update99:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c3d13189-1f7b-482f-abf7-cc8d563716c8
cpe:2.3:a:oracle:jdk:1.6.0:update113:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ae4602e8-1466-4148-bc89-7faffa14a886
product-70c0761d49c3bbe44615490ef7b613557bcd3ccdfa71d09d74202c114d277fb7Linked exactInspect raw assertions
cpe:2.3:a:oracle:jre:1.6.0:update113:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f0d546f4-b709-4522-b84a-7d6c301814ba
cpe:2.3:a:oracle:jre:1.8.0:update77:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cdf71474-ffbf-44a0-a5ec-cd3e50472d97
cpe:2.3:a:oracle:jre:1.7.0:update99:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0bf73f1c-91f1-41f6-956c-4a64603dcdf0
product-c005a4511ebcb7ada0c011a0e27c624657f53767a287f0bcc8d89c62e06fd3d6Linked exactInspect raw assertion
cpe:2.3:a:oracle:jrockit:r28.3.9:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1f7acc3a-f8f4-4b53-981a-697569b172ce
product-efc63d4e81383a6772c6c41b2fb3231b349512d257b4b47a2475eb5d42511849Linked exactInspect raw assertions
cpe:2.3:o:oracle:linux:5:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
62a2ac02-a933-4e51-810e-5d040b476b7b
cpe:2.3:o:oracle:linux:6:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d7b037a8-72a6-4dff-94b2-d688a5f6f876
cpe:2.3:o:oracle:linux:7:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
44b8fedf-6cb0-46e9-9ad7-4445b001c158
product-ebce605e64c58caa7df6a30e91702332cd8c0be8f801e44353e6350e913ec5aeLinked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
133aafa7-af42-4d7b-8822-aa2e85611bf5
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ee249e1b-a1fd-4e08-aa71-a0e1f10ffe97
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
33c068a4-3780-4eab-a937-6082df847564
Affected-product evidence
Accepted scope and product mapping
38 canonical links · 1 source-reported links
vendor-6bbcd126779403146e957d68529786b086421e0676d9e90a4d53d03594694fb2 · product-029a01c72e5306f6a90d3f3e1d801b193443a479820fb49aa3e69e3266443cac
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
557d93d4-7309-4f71-965a-20908f9a1a5dvendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-0622850d7355e952441687d9dab9a9888a3f7429796731abeb2f2b417c9c9aa0
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
476f8119-0290-4858-8d86-90cd3cafeb3fvendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-1220950f14941e44f97ef359dfe4710143870ab715db6bc680fb3bcf3da40d5b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0bb93896-45a3-450a-a53e-33f37a44dacd1e14a2bd-eaf2-43ea-b972-1206441b403avendor-6bbcd126779403146e957d68529786b086421e0676d9e90a4d53d03594694fb2 · product-17c7b234c758b1e03422fb7a3c0e6749e845702036e09e2074cae66121210921
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
118745ce-6542-4849-926c-6d5352e43833vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-1e7e71c5224a6f4135c855890a7cd875f6ac32bf0024c6ee2e888da0212d267e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
04044ec6-e4bd-418e-9479-d49e71fb30bavendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-2bbc3c87cbaeb11c12dc34b42c7207fa49eea659fc62aa79757b51047802fc97
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
b71fa48b-c22b-414d-9924-917d7231494evendor-6bbcd126779403146e957d68529786b086421e0676d9e90a4d53d03594694fb2 · product-2ed4d80ed12721f6ebc20d0939cfdb7f085ade620bbe2f57d6dcaea9c2741a25
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
80e211c6-b54b-4df4-86a5-ae3ac9fc21b3vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-326f5a17c9ba94ff6d5e60b61be24e561176813b0856dc31836e10a9f580e7fc
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a88172ed-50fa-42ff-a033-b2f38c888b15vendor-66ae8c5e06427f7450637d18322b0dc411c0b469d940341cf076a620d444fe3c · product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5db42797-d228-4f23-bd58-e3331d8b9658vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-3e21e0f5d039c1214aa1ef3a629a8ce3abb696dfc46de0455f77d614211cbc8b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
477a83d5-8fcf-496b-85e2-21f420d6652evendor-6bbcd126779403146e957d68529786b086421e0676d9e90a4d53d03594694fb2 · product-4f2240e45c4385f8980643ce838561b90551012dc317022ee66a7d71a9db8e28
- Source class
- Nvd cpe vulnerable target
- Assertions
- 6
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0ffdae47-5c29-4520-96ed-764c387c6de327e3b279-5115-4b65-bb0b-d6126062da8853528b35-5248-441e-8e14-308fc04697ca79fb6d8c-0d36-4c35-a1be-87d210becc8bc0bce028-1df5-4b67-90d3-e452bb043f1bdb6f50fa-6855-4128-887c-cb5696d53c9bvendor-f98e1750e4b030e2bb71130d14421ff255427227a8b696c92978cf6c77fc265d · product-66ca8198d1887ac9754d1aad85d76f1edfc54c873eb2cd9bedf566863f5e07bd
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
dd53ddda-d853-401a-bc0e-bd08f040a955ff42e75a-0341-4b1b-80d7-54f1e92aa897vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-6bac5e5dc0babe5d628e246786e711716ddfb068132218ad0dd5123beb466ec4
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7af0f0a5-e328-4a50-9361-6fd07645ab62vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-6c94a14e5689a64227066e3f60eeb2b8b30045bcbf08047234f29f3fdd35d120
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3d229488-dec0-4850-8893-f4b81c04cec8a0c6201e-4d54-4fba-a066-ded42827c6e5af3b7761-55e0-48da-8d52-337d6f4a462evendor-6bbcd126779403146e957d68529786b086421e0676d9e90a4d53d03594694fb2 · product-6fe21abd2669255eab9cb18837ddcf63aa787fce42fdad30fa2dd0c4a530da25
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7a4766b8-ab29-45f1-8ae1-98cc5e8fa7davendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-70c0761d49c3bbe44615490ef7b613557bcd3ccdfa71d09d74202c114d277fb7
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
07ef57e2-781b-4a66-87f5-64ba3abad50c24fa0854-5ef0-411d-b1e2-70e053008313cbf02366-f879-42e4-b3a2-e1370bfe8265vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-7120df83a9b73aae2817084ac2070ecc7d1fbfcada23076a424824e660688aae
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
05fab6ed-e56a-489a-82e3-af51cb44227712ddc465-f1d6-40a3-82ec-f233a5d471415f941556-b1b9-4ac1-8234-2d28a8ca372baaf4189a-6f88-4f06-b494-b7dd265c5875c38fe233-238d-4edc-a93b-a083b6042a0evendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-8270111f4cc417bcdc58b8fcee5af06573840731d43a3d04b238435408400874
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5fdd3e7a-b338-4e85-b0f6-66210853eb3e72647177-e2e3-4493-a6af-e6d0e6d43b97vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378
- Source class
- Nvd cpe vulnerable target
- Assertions
- 7
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
02e7be8a-0f4f-4aeb-81e2-bf5e706a88310d0050af-c15a-463e-824f-d795fc17d5c02afd403e-ea72-4c8a-b361-f8bb3fb0765d59e84ec3-f45c-4f4e-a664-25cdfcaeb81581d14c7d-e26b-4fcc-b809-a5d240c74177bd23bcb0-6e33-4166-8f05-5b080097a925dd64390d-0969-4dec-9c32-9a26406e7868vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-8db20157ede2f731f576213a7e555a24d2424bb17aed8e43ad9b77c3587f9dea
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5b42544f-9da2-412d-8dd8-5455419608836590576b-e1eb-4a2f-a167-2374dc9d71ea78bef63b-be22-4c10-8585-afb30f38b13avendor-6bbcd126779403146e957d68529786b086421e0676d9e90a4d53d03594694fb2 · product-908c58b965f5cdd7f6621821fd6c68d62c5a5ce89de01a9e91af7286e0b17d41
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
078342f9-0d2f-4187-93d7-8e753a79e66ca8839bde-6002-45c7-b0c7-fa86c3ada96cvendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-96fd4aeba8f0231e1d0f6ca7ae786e70d484258209c2dd2c10b095c6d07c6180
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
44f1fe2d-5140-42cd-a064-b982a6dc7a61vendor-c57a6167e95991f72f9616ac32b40463ac13c5f4929fcce3efc058b09a445b54 · product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5d3f4e27-700c-4d44-a02d-7e27278f94b55e4f1eac-fbad-479b-a017-88c1ed5a501ab2029322-1b79-4405-86e1-d76e1f747367e7fc9a25-7b09-420e-8b9e-ec8dd8f272ebvendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-afac260708bb4bb1a51e28ce6b95f0356203366f8c8ffd2c790c3109033fc4fd
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
77fb8a73-c333-421c-a062-4e95a6d229d0vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-b2aa744c9fb2b4ef0e3b842acbf37879ad4ac43af291292cfb0906170b204ab9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0ac3d06d-bf5b-4982-828a-564be92db5ec391d11a3-4af1-46a7-96f1-b4b429e7107bcff47eee-a1a4-43e0-bf58-e95d1489ecebvendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-ba31f92f83b2366f63448b819634143dda1c3ee0b74f918170f5fe22e6811567
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
11e6f1f8-aac2-4f5a-844f-1fc74e673967vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-bc6ac9f1e87a668175a638bad6013a05d2210c8abe7977a8f8f0948257ba71da
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0eb34211-77e6-431b-ad7d-675000eeeaae4c913c4f-4f56-48d2-8e2c-3ffcc61ca3c17ab1238c-eeee-47af-9819-d16a52907cd5d8646bb2-ac11-4e25-84b1-599021ccd8bbvendor-6bbcd126779403146e957d68529786b086421e0676d9e90a4d53d03594694fb2 · product-bd4950335ff1f3f03b9dd6fa5c596f7c67c9ea6d150272de074ec3767af3532a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
076891ce-1183-41e7-a036-13fcb8f0be895d94457f-6648-4dd1-87f7-74543a385af7vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-c005a4511ebcb7ada0c011a0e27c624657f53767a287f0bcc8d89c62e06fd3d6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
b9f0ee83-1a4d-48f8-ad5c-57de8b4364ffvendor-f98e1750e4b030e2bb71130d14421ff255427227a8b696c92978cf6c77fc265d · product-c27aedc6088fe47e75f3a72d532ce7dcfb4a151fd6deaeecc763cf1d10026925
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
64eef596-9688-4a82-ae54-3812bff16c99vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-c8fd04cb7cbf514fd1a8bf9dafd5cd44499d96cff80cffaf10ccd171e11e4a5f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
63c56115-c001-4e0a-8811-f6c233afae7ebae41780-f7ae-4e29-9f46-19bd0763106bvendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-e425f76755163e7ac04fb77eb752192cdfcf6897c58b892c4c04b4e260342515
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
8bf730a1-0ecd-4561-a13a-a458942918d4vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-e4499e4bc1e3fdada3eccdeba78f66bfafaa2616ca917f0baf4ea8490f7bf100
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6baa73cf-fdd2-4498-a261-6ab9afdac8afvendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-ebce605e64c58caa7df6a30e91702332cd8c0be8f801e44353e6350e913ec5ae
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0bbaad5f-17d6-4c35-85ec-1b668e6f6fdb9f379978-5106-4a01-991f-61e49e10bae8d88a5710-8136-4c4d-9ab5-11cee961077fvendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-efc63d4e81383a6772c6c41b2fb3231b349512d257b4b47a2475eb5d42511849
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0374158b-9c41-456c-b318-05af7b11bc4c6ecb63a1-28cd-4b91-882e-e26c4c5df59b969b4a54-3ade-4ed8-9e70-8a205f712f28vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-f6df6ab8c95a532ed2dbb3be7d1d9a3fa82e2f90d8dd3e68fedb15893d69148f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f1fef2cd-221c-4be1-80a7-4d7e347c6823vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-fb0ea92a45ee1fb244313dbcc32de14a48cb22f7c70356fe98c5d46384642096
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1d8bb742-b7a4-4732-8e8b-90c1bcc8bb35vendor-8771dac0ae5eeec984ca23e4bbe5a243fb7896ad7c1c4afc6acd3abe53fdd152 · product-fdcdb328ae5a693817ced8bc365aa2cb900f7c7f407ca30bc5149de5335df6b2
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
16c8dda2-8a37-4734-aed3-5ee6422548e73421c6f7-5967-4e14-b9cf-c7800e2380f7892e7db5-66a1-472c-af07-33fcb3a87f8b8eb98377-7bdb-42d1-8b61-7265d5dc44f9fefd6882-239a-4c06-b6d3-48e0fe9fca0eCanonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4cb00903-f687-48c5-829b-7b19d7c87d96Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 9.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.