CVE WATCH / VULNERABILITY DETAIL
CVE-2026-107614
MEDIUMCVSS 6.1NVD feed
Published 8 October 2026 · tracked since 9 October 2026
Description
An integer underflow in WinCursorShapeUtils::trimTransparent() in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to crash the server, and potentially read out-of-bounds memory, by causing a cursor shape with a width or height of zero to be processed on the DXGI
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-14990 CRITICAL 9.3
- CVE-2026-107613 MEDIUM 5.9
- CVE-2026-107615 HIGH 7.8
- CVE-2026-107611 HIGH 7.1
- CVE-2026-107612 HIGH 7.8
- CVE-2026-103663
- CVE-2026-62127 MEDIUM 6.5
- CVE-2026-44033 MEDIUM 5.5
- CVE-2026-44036 MEDIUM 5.5
- CVE-2026-44037 MEDIUM 5.5