Junglewise Threat Intelligence

CVE-2026-72986: Graphic Fonts heap-based buffer overflow

CVE-2026-72986 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Graphic Fonts contains a heap-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code over the network without authentication. Successful exploitation could lead to complete system compromise, including unauthorized access to sensitive data and business systems.

Technical details

The vulnerability is a heap-based buffer overflow in Graphic Fonts that can be triggered remotely without authentication. The root cause involves improper bounds checking when processing font data, allowing an attacker to overflow heap memory and overwrite critical data structures. An attacker can send a specially crafted network packet to trigger the overflow and execute arbitrary code with the privileges of the affected process. No authentication or user interaction is required for exploitation via the network attack vector.

Affected products

  • Graphic Fonts

Timeline

  • 2026-09-08: disclosed

References