PULSE
LIVE75signals / 24h
FEED
ransomglobal secret group reclama a Pro-Tuff | Decals · US · Retail & E-Commerceransomdeadlock reclama a High Class Car Limo · US · Transportationransomanubis reclama a Eagle Crest Communities · US · Hospitalityransomglobal secret group reclama a Spergel · CA · Professional Servicesransomdeadlock reclama a West African Resources ltd · AU · Energy & Utilitiesransomdeadlock reclama a Caspian One · AZ · Energy & Utilitiesransomsection9 reclama a *****.com.pt · PT · Educationransomsection9 reclama a ********.com.uy · UY · Agriculture and Food Productionransomsection9 reclama a ****.fr · FR · Retail & E-Commerceransomsection9 reclama a ********.com · US · Otherransomsection9 reclama a ******.com.se · SE · Healthcareransomsection9 reclama a ******.com · US · Technologyransomsection9 reclama a ****.com.mc · MC · Hospitalityransomsection9 reclama a *****.ind.br · BR · Agriculture and Food Productionransomglobal secret group reclama a Pro-Tuff | Decals · US · Retail & E-Commerceransomdeadlock reclama a High Class Car Limo · US · Transportationransomanubis reclama a Eagle Crest Communities · US · Hospitalityransomglobal secret group reclama a Spergel · CA · Professional Servicesransomdeadlock reclama a West African Resources ltd · AU · Energy & Utilitiesransomdeadlock reclama a Caspian One · AZ · Energy & Utilitiesransomsection9 reclama a *****.com.pt · PT · Educationransomsection9 reclama a ********.com.uy · UY · Agriculture and Food Productionransomsection9 reclama a ****.fr · FR · Retail & E-Commerceransomsection9 reclama a ********.com · US · Otherransomsection9 reclama a ******.com.se · SE · Healthcareransomsection9 reclama a ******.com · US · Technologyransomsection9 reclama a ****.com.mc · MC · Hospitalityransomsection9 reclama a *****.ind.br · BR · Agriculture and Food Production
← All CVEs
CVE WatchJul 23, 2026

CVE-2026-41694

Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid

CVSS

3.7

Low

EPSS

0.1%

p3

KEV

Exploit Today

1

0-100

Published: Jun 10, 2026 · Last modified: Jul 23, 2026 · CWE-347

EPSS · 30d
0.1%EPSS · 30 days0.1%
2026-06-302026-07-25
Technical description

Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able to craft these SAML payloads and use the Service Provider as a decryption oracle. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-480219.1 CRI
2.5%
1In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traffic (patient consent decisions, medication data, document operations, authorization tokens, and entitlement queries) becomes readable and modifiable. The attacker can also inject arbitrary requests through the hijacked channel. This issue has been patched in version 2026-05-20.2d
CVE-2026-526863.7 LOW
1.7%
1The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.3d
CVE-2026-13089
5.4%
2OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify. When the caller does not pin an algorithm, OIDC::Lite::Model::IDToken::verify sets $self->alg($self->header->{alg}) from the token's own header and then calls decode_jwt(token, key, 1, [$self->alg]), handing JSON::WebToken an accepted-algorithm allowlist taken from the untrusted token. A token with alg=none yields ['none'], so decode_jwt returns the claims with no signature check, and a token with alg=HS256 is verified with the RP's RSA public key as the HMAC secret (RS to HS confusion). The ID Token is the OpenID Connect authentication assertion delivered to the Relying Party. Any caller that verifies an ID Token through the unpinned load(token)->verify path, or load(token, key) with only the key pinned, accepts a forged token carrying attacker-chosen claims such as sub and is authenticated as any user. Passing an explicit algorithm so $self->alg is already set bypasses the header-derived allowlist and is not affected. Note that the latest version uploaded to CPAN is 0.10. Later versions are available in the git repository.3d
CVE-2026-107236.8 MED
18.3%
5BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.4d
CVE-2026-646238.6 HIG
10.0%
3Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the default local verifier accepts any non-empty string as valid. Unauthenticated attackers can submit forged APS delegation payloads with arbitrary scopes to bypass signature verification and obtain signed permission-grant tokens for sensitive resources including SHELL_EXEC.3d
CVE-2026-498345.9 MED
1.6%
0sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1) counts verified witnesses per entry or per validation path rather than per log authority, allowing a single compromised transparency log or CT log to satisfy multi-log threshold requirements and defeat the multi-log policy. This issue is fixed in version 1.2.0.5d