CVE-2025-26790

Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memory read during processing of a document file by the antivirus engine.

  • Published Sep 14, 2026
  • CVSS 3.7 low
  • 0.3% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2025-26790 at the National Vulnerability Database