CRITICAL 9.8 Microsoft

CVE-2024-36048

QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.

Microsoft Security Update 2026-Aug: QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.

Affected Products

References

Published: 2026-08-06 · Source: Microsoft · Feed updated: 2026-08-10
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-08-06 via Microsoft. Affected: cbl2 qt5-qtbase 5.12.11-16.

Risk Timeline

CVE Disclosed2026-08-06 · 3 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2025-49844 PoCRedis Lua Use-After-Free may lead to remote code executionCRITICAL9.9
CVE-2026-33937Handlebars.js has JavaScript Injection via AST Type ConfusionCRITICAL9.8
CVE-2026-3381Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure verCRITICAL9.8
CVE-2026-4176Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from CRITICAL9.8
CVE-2025-68615Net-SNMP snmptrapd crashCRITICAL9.8
CVE-2025-0665eventfd double closeCRITICAL9.8
vulnfeed aggregates 8893 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.