PULSE
LIVE21signals / 24h
FEED
ransomnova reclama a VNSO · Not Foundransomblacknevas reclama a Zuni Shopping Center, Inc. · US · Consumer Servicesransomqilin reclama a P & A Construction · US · Constructionransombraincipher reclama a windiam.com · Technologyransomqilin reclama a Primeline Logistics · IE · Transportation/Logisticsransomqilin reclama a Recsa · CR · Not Foundransomqilin reclama a Salida Union School District · US · Educationransomchaos reclama a neopharmlabs.com · US · Healthcareransomqilin reclama a Cpcg · BR · Not Foundransomqilin reclama a EFU Life Assurance · PK · Financial Servicesransomqilin reclama a Infina Health · Healthcareransomm3rx reclama a ubfreight.com · Transportation/Logisticsransomkrybit reclama a dhli.in · IN · Not Foundransomkrybit reclama a Vibonum Technologies Private Limited · IN · Technologyransomnova reclama a VNSO · Not Foundransomblacknevas reclama a Zuni Shopping Center, Inc. · US · Consumer Servicesransomqilin reclama a P & A Construction · US · Constructionransombraincipher reclama a windiam.com · Technologyransomqilin reclama a Primeline Logistics · IE · Transportation/Logisticsransomqilin reclama a Recsa · CR · Not Foundransomqilin reclama a Salida Union School District · US · Educationransomchaos reclama a neopharmlabs.com · US · Healthcareransomqilin reclama a Cpcg · BR · Not Foundransomqilin reclama a EFU Life Assurance · PK · Financial Servicesransomqilin reclama a Infina Health · Healthcareransomm3rx reclama a ubfreight.com · Transportation/Logisticsransomkrybit reclama a dhli.in · IN · Not Foundransomkrybit reclama a Vibonum Technologies Private Limited · IN · Technology
← All CVEs
CVE WatchJul 22, 2026

CVE-2026-16560

A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close th

CVSS

5.3

Medium

EPSS

KEV

Exploit Today

0-100

Published: Jul 22, 2026 · Last modified: Jul 22, 2026 · CWE-1220

EPSS · 30d

Not enough EPSS history yet.

Technical description

A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap allocation allowing another call to refer to the same memory pointer causing a denial of service or an arbitrary memory write operation.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-505028.0 HIG
45.4%
14Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.4h
CVE-2026-504057.8 HIG
11.9%
4Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.4h
CVE-2026-561557.8 HIG
30.3%
KEV59Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability 7d
CVE-2026-550067.8 HIG
12.5%
4Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.8d
CVE-2026-491707.8 HIG
84.9%
25Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.4h
CVE-2026-485817.8 HIG
12.4%
4Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.8d