← Back to CVE intelligence
CVE intelligence

CVE-2026-93312

Vulnerability intelligence

Published Sep 18, 2026Sources checked Oct 7, 2026
4.3MEDIUMCVSS out of 10
What this means

Review the available evidence

CVE-2026-93312 and is rated Medium severity with a CVSS score of 4.3. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.

CISA KEVNot listedBased on the latest collected catalog
EPSS0.6%Estimated 30-day exploitation probability
Ransomware useNot markedCISA KEV ransomware field
Threat actors0Source-linked actor relationships
Overview

What is CVE-2026-93312?

A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 26.08.0 is recommended to address this issue. Patch name: 5e49250f13b0390edeb3f90eb4c02c9941f97067. Upgrading the affected component is advised.

Source: NVD