CVE-2026-16560
A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close th
CVSS
5.3
Medium
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Jul 22, 2026 · Last modified: Jul 22, 2026 · CWE-1220
Not enough EPSS history yet.
A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap allocation allowing another call to refer to the same memory pointer causing a denial of service or an arbitrary memory write operation.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-505028.0 HIG45.4%
——14Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.4hCVE-2026-504057.8 HIG11.9%
——4Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.4hCVE-2026-561557.8 HIG30.3%
KEV—59Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability 7dCVE-2026-550067.8 HIG12.5%
——4Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.8dCVE-2026-491707.8 HIG84.9%
——25Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.4hCVE-2026-485817.8 HIG12.4%
——4Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.8d