Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40572

30
FAUCET Score

OVERVIEW: CVE-2026-40572 affects NovumOS versions prior to 0.24, a custom 32-bit operating system written in Zig and x86 Assembly. The vulnerability exists in Syscall 15 (MemoryMapRange), which fails to validate that user-mode processes cannot map virtual address ranges containing critical kernel structures such as the IDT, GDT, TSS, and page tables. A local attacker can exploit this insufficient input validation to map and modify kernel interrupt handlers, achieving privilege escalation from user mode to kernel context. SEVERITY: This vulnerability carries a CRITICAL CVSS v3.1 score of 9.0, with an attack vector of local, low complexity, and no privilege or user interaction requirements. The impact is system-wide, with high confidentiality and integrity compromises possible through kernel-level access. The attack poses significant risk as it enables complete system compromise through elevation to kernel privilege levels. EXPLOITATION STATUS: There is no evidence of active exploitation in the wild; the vulnerability does not appear on the CISA Known Exploited Vulnerabilities list and remains inactive on the Hot List. While the EPSS score of 0.00012 indicates this is a low-probability target for exploitation attempts in the broader CVE landscape, the critical nature of the vulnerability and straightforward exploitation path suggest organizations running affected NovumOS versions should prioritize patching to version 0.24 immediately.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.24CPE matchmatch criteria
cpe:2.3:o:minecanton209:novumos:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.0CRITICAL

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.5
Impact Score
5.8
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.21%
Probability of exploitation in next 30 days
EPSS Percentile
11.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0021 is in the 62nd percentile among its peer group of 79 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.3 Mastodon, and 1.0 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryvendor investigatingvia nvd_reference
View patch

References

github.com / MinecAnton209/NovumOS/releases/tag/v0.24
Release Notes
github.com / MinecAnton209/NovumOS/security/advisories/GHSA-rg7m-6vh7-f4v2
ExploitVendor Advisory