What is CVE-2026-49035?
CVE-2026-49035 is a heap-based buffer overflow vulnerability triggered by a crafted MMS Initiate request. Remote code execution (RCE) is possible when ASLR is disabled, while memory corruption or denial of service (DoS) may occur with ASLR enabled. Affected products should be patched or updated immediately.
Azərbaycanca: CVE-2026-49035 zəifliyi məhsulda xüsusi hazırlanmış MMS Initiate sorğusu vasitəsilə heap-based buffer overflow yaradır. ASLR deaktiv olduqda uzaqdan kod icrası (RCE) mümkündür; ASLR aktiv olduqda isə yaddaş korrupsiyası və ya xidmət rəddi (DoS) baş verə bilər. Təsirlənən məhsulu yeniləmək və ya istehsalçı tərəfindən verilən təhlükəsizlik yamalarını tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
What type of request is used to exploit CVE-2026-49035?
A crafted MMS Initiate request triggers the heap-based buffer overflow.
What impact can this vulnerability have when ASLR is enabled?
With ASLR enabled, memory corruption or denial of service (DoS) may occur.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.