CVE-2026-6071

A remote code execution security issue exists in the affected products when parsing DOE files that could allow a remote attacker to write past the end of an allocated object and execute code within the context of the current process. To exploit this vulnerability, a legitimate user must visit a malicious page or open a malicious file.

  • Published Sep 3, 2026
  • CVSS 7.5 high
  • 0.5% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-6071 at the National Vulnerability Database