CVE-2026-26072: Linuxfoundation Everest

Medium severity, CVSS 4.2. EPSS: 0.1% chance of exploitation in the next 30 days.

EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::map<std::optional>` concurrent access (container/optional corruption possible). The trigger is EV SoC update with powermeter periodic update and unplugging/SessionFinished status. Version 2026.02.0 patches the issue.

Affected products

Published 2026-03-26. Last modified 2026-06-17.