CYBER CODE RED

Get real-time updates on Telegram

P5Verified

CVE-2024-12224, CVE-2026-25541, CVE-2026-25727 +16 more CVEs: Affected product not specified by the source

CVE-2024-12224, CVE-2026-25541, CVE-2026-25727, CVE-2026-41676, CVE-2026-41677, CVE-2026-41678, CVE-2026-41681, CVE-2026-41898, CVE-2026-42327, CVE-2026-44662, CVE-2026-45784, CVE-2026-66746, CVE-2026-66754, CVE-2026-67181, CVE-2026-67182, CVE-2026-93599, CVE-2026-93600, CVE-2026-93601, CVE-2026-93602 affects sccache. EPSS 0.00221 (percentile 0.11469), scored 2026-10-05. Fixed version: d5a84c928603ef84fff8a3e0f33b4e119f1f01a2. Fixed version: 0.18.0~2-160000.1.1. Fixed version: 0.18.0~2-160000.1.1.

CVE-2024-12224

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality, integrity and availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-25541

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (Microsoft Security Response Center, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

Microsoft Security Response Center’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-25727

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (Microsoft Security Response Center, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Microsoft Security Response Center’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-41676

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-41677

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality and availability impact as low; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-41678

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-41681

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-41898

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality impact as high; integrity impact as none; availability impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-42327

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality and availability impact as none; integrity impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-44662

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality impact as none; integrity and availability impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-45784

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality impact as none; integrity and availability impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-66746

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Network (remote) · No privileges required · Passive user interaction

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality and integrity impact as low; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-66754

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-67181

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality and availability impact as none; integrity impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-67182

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality and availability impact as none; integrity impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-93599

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (Microsoft Security Response Center, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

Microsoft Security Response Center’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-93600

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (Microsoft Security Response Center, CVSS 3.1): Network (remote) · High privileges required · No user interaction required

What an attacker can do

Microsoft Security Response Center’s CVSS 3.1 assessment rates confidentiality and availability impact as none; integrity impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-93601

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (Microsoft Security Response Center, CVSS 3.1): Network (remote) · High privileges required · No user interaction required

What an attacker can do

Microsoft Security Response Center’s CVSS 3.1 assessment rates confidentiality and availability impact as none; integrity impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-93602

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (Microsoft Security Response Center, CVSS 3.1): Network (remote) · High privileges required · No user interaction required

What an attacker can do

Microsoft Security Response Center’s CVSS 3.1 assessment rates confidentiality and availability impact as none; integrity impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

Published

CVE
CVE-2026-41676, CVE-2026-41677, CVE-2026-41678, CVE-2026-41681, CVE-2026-41898, CVE-2026-42327, CVE-2026-44662, CVE-2026-45784, CVE-2026-66746, CVE-2026-66754, CVE-2026-67181, CVE-2026-67182, CVE-2026-93599, CVE-2026-93600, CVE-2026-93601, CVE-2026-93602
Product
sccache
CCR priority
0.1 /100 (P5)
CVSS 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N · OSV.dev
EPSS
0.00221 · percentile 0.11469 · 2026-10-05
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2024-12224.html