CVE-2026-3012
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrie
CVSS
8.0
High
EPSS
0.3%
p18
KEV
—
Exploit Today
5
0-100
Published: May 27, 2026 · Last modified: Jul 15, 2026 · CWE-345
0.3%EPSS · 30 days0.3%
2026-06-302026-07-20
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:22644
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:22963
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:25049
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:25979
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:28053
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:28054
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:28055
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:28056
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:28057
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:29863
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-3012
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2447319
- bugzilla.samba.orghttps://bugzilla.samba.org/show_bug.cgi?id=16003
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:22644
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:22963
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:25049
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:25979
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:28053
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:28054
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:28055
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-445844.3 MED—
——0Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the email update functionality fails to invalidate the existing verification state when a user changes their email address, allowing a verified account to retain its verified status after switching to an unverified or unowned email address. When a user updated their email address, the system did not reset or revalidate the associated email verification status. As a result, the verification column remained set to “true” even after the email address was changed. Exploitation could potentially result in: misrepresentation of email ownership, bypass of verification-based trust assumptions, and abuse of features gated behind verified status. No direct unauthorized access to other users accounts or data is possible through this issue alone. This issue has been fixed in version 1.5.0.16hCVE-2026-127244.3 MED1.0%
——0The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into the message delivered to a registered user, which can be used for phishing.17hCVE-2026-107244.8 MED1.0%
——0The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the feed by planting a shortcode in a review on the connected source.1dCVE-2026-492847.1 HIG13.7%
——4SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. Prior to 2.4.7 and 2.5.2, SimpleSAMLphp's SAML SP ACS path does not enforce the IdP selected for an SP-initiated login when unsigned Response/InResponseTo is combined with a signed assertion lacking SubjectConfirmationData/InResponseTo, allowing a response issued by one trusted IdP to be bound to SP state created for another IdP and bypass flows that route users to a specific IdP, including deployments that set enable_unsolicited to false. This issue is fixed in versions 2.4.7 and 2.5.2.18hCVE-2026-544969.3 CRI23.7%
——7ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0, the variable-base scalar multiplication gadget in halo2_gadgets/src/ecc/chip/mul/incomplete.rs used assign_advice() for the base point without a copy constraint tying it to the actual base, allowing a malicious prover to produce a valid proof for an Orchard Action with an under-constrained base point and bypass the diversified-address-integrity check that binds pk_d, g_d, ivk, the nullifier (nf), and the spend validating key (ak) to the note being spent. This issue is fixed in zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0.4dCVE-2026-492127.5 HIG7.7%
——2Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, the HMAC computed by Symfony\UX\LiveComponent\LiveComponentHydrator covered only sorted prop key/value pairs and did not include the component name, the slot identifier (props vs propsFromParent), or request context, allowing a signed blob minted for one component or slot to be replayed in another and set a read-only prop on a target component. This issue is fixed in versions 2.36.0 and 3.1.0.21h