CRITICAL 9.8 Microsoft
CVE-2024-36048
QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.
Microsoft Security Update 2026-Aug: QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.
Affected Products
- cbl2 qt5-qtbase 5.12.11-16
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-36048
- https://nvd.nist.gov/vuln/detail/CVE-2024-36048
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-08-06 via Microsoft. Affected: cbl2 qt5-qtbase 5.12.11-16.
Risk Timeline
CVE Disclosed2026-08-06 · 3 days ago
Remediation Resources
Official Advisory
msrc.microsoft.com/update-guide/vulnerability/CVE-2024-36048NVD / MITRE
nvd.nist.gov/vuln/detail/CVE-2024-36048Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2025-49844 PoC | Redis Lua Use-After-Free may lead to remote code execution | CRITICAL | 9.9 |
| CVE-2026-33937 | Handlebars.js has JavaScript Injection via AST Type Confusion | CRITICAL | 9.8 |
| CVE-2026-3381 | Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure ver | CRITICAL | 9.8 |
| CVE-2026-4176 | Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from | CRITICAL | 9.8 |
| CVE-2025-68615 | Net-SNMP snmptrapd crash | CRITICAL | 9.8 |
| CVE-2025-0665 | eventfd double close | CRITICAL | 9.8 |
vulnfeed aggregates 8893 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.