CVE-2026-32208 Microsoft Entra ID Spoofing Vulnerability Microsoft Security 1 Juli 2026 om 16:00 Corrected the CVE description and title. This is an informational change only.
CVE-2026-41992 Global Buffer Overflow in GNU gzip Microsoft Security 1 Juli 2026 om 10:40 Information published.
CVE-2026-57062 CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182. Microsoft Security 1 Juli 2026 om 10:40 Information published.
CVE-2026-13595 Util-linux: util-linux: heap use-after-free in libblkid nested partition probing Microsoft Security 1 Juli 2026 om 10:06 Information published.
CVE-2026-11625 Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes Microsoft Security 1 Juli 2026 om 10:06 Information published.
CVE-2026-58050 libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation Microsoft Security 1 Juli 2026 om 10:06 Information published.
CVE-2026-58051 libssh2 - Free of Uninitialized Pointer in publickey List Cleanup Microsoft Security 1 Juli 2026 om 10:06 Information published.
CVE-2026-7531 Use-after-free in PQC hybrid key-share handling Microsoft Security 1 Juli 2026 om 10:06 Information published.
CVE-2026-6412 Continued acceptance of SHA-1/MD5 digests in certificate processing Microsoft Security 1 Juli 2026 om 10:06 Information published.
CVE-2026-6092 Encrypt-then-MAC could fall back to MAC-then-Encrypt when HAVE_ENCRYPT_THEN_MAC is configured Microsoft Security 1 Juli 2026 om 10:06 Information published.
CVE-2026-11310 X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoring Microsoft Security 1 Juli 2026 om 10:06 Information published.
CVE-2026-10097 ML-KEM-1024 x64 AVX2 incomplete cipher text comparison enables IND-CCA2 break and static private-key recovery Microsoft Security 1 Juli 2026 om 10:06 Information published.
CVE-2026-10098 OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status Microsoft Security 1 Juli 2026 om 10:06 Information published.
CVE-2026-8720 HMAC-BLAKE2 final discards message when key length exceeds block size Microsoft Security 1 Juli 2026 om 10:05 Information published.
CVE-2026-12340 Out-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computation Microsoft Security 1 Juli 2026 om 10:05 Information published.
CVE-2026-10512 X25519 x86_64 assembly final reduction leaves non-canonical field element Microsoft Security 1 Juli 2026 om 10:05 Information published.
CVE-2026-10592 Wildcard DNS SAN bypasses CA name-constraint checks Microsoft Security 1 Juli 2026 om 10:05 Information published.
CVE-2026-6091 Partial-chain verification accepts untrusted intermediate as trust anchor Microsoft Security 1 Juli 2026 om 10:05 Information published.
CVE-2026-6325 Out-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms list Microsoft Security 1 Juli 2026 om 10:05 Information published.
CVE-2026-55958 Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessage Microsoft Security 1 Juli 2026 om 10:05 Information published.
CVE-2026-6731 X.509 name constraint bypass via Subject CN treated as a DNS name Microsoft Security 1 Juli 2026 om 10:05 Information published.
CVE-2026-7511 PKCS7_verify signer confusion allows forged signatures to be accepted Microsoft Security 1 Juli 2026 om 10:05 Information published.
CVE-2026-6330 ML-KEM ARM64 NEON ciphertext comparison only compares half of the input Microsoft Security 1 Juli 2026 om 10:04 Information published.
CVE-2026-6331 HMAC zero-length tag forgery in EVP_DigestVerifyFinal Microsoft Security 1 Juli 2026 om 10:04 Information published.
CVE-2026-6094 Heap buffer overread in wc_PKCS7_DecodeEnvelopedData parsing crafted PKCS7 EnvelopedData Microsoft Security 1 Juli 2026 om 10:04 Information published.
CVE-2026-6678 Integer underflow in wc_PKCS7_DecryptOri handling crafted Other Recipient Info Microsoft Security 1 Juli 2026 om 10:04 Information published.
CVE-2026-55961 wolfSSL_PKCS7_verify() reports success for degenerate (certs-only) PKCS#7 with no signer Microsoft Security 1 Juli 2026 om 10:04 Information published.
CVE-2026-6329 PKCS#12 MAC verification uses attacker-controlled comparison length Microsoft Security 1 Juli 2026 om 10:04 Information published.
CVE-2026-11999 X.509 trust-chain bypass via path-depth exhaustion in wolfSSL_X509_verify_cert() Microsoft Security 1 Juli 2026 om 10:04 Information published.
CVE-2026-55962 TLS 1.3 post-handshake authentication: server accepts Finished without client Certificate/CertificateVerify Microsoft Security 1 Juli 2026 om 10:04 Information published.