PatchSiren

National Security Agency CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH National Security Agency CVE published 2026-08-03

CVE-2026-18718

Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer. An attacker can execute arbitrary binaries by supplying a malicious Ghidra project with a crafted Swift tool directory path. When a victim opens the project, SwiftDemanglerAnalyzer restores the persisted Swift binary directory from project state and SwiftNativeDemangler executes the resolved binary without integrity [truncated]