CVE-2026-50303
Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature
CVSS
5.5
Medio
EPSS
0.3%
p19
KEV
—
Exploit Today
6
0-100
Publicado: 14 jul 2026 · Última mod.: 22 jul 2026 · CWE-1240
0.2%EPSS · 30 días0.3%
2026-08-042026-09-01
Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-217517.4 ALT5.7%
——2HCL Hive is affected by a cryptographic primitive with a risky implementation which could allow an attacker unauthorized lateral compromise or widespread credential leakage if a single internal component is breached.5dCVE-2025-688335.3 MED4.8%
——1HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker unauthorized access to resources.5dCVE-2026-46654—1.3%
——0Plonky3 is a toolkit for polynomial IOPs (PIOPs). Prior to versions 0.4.3 and 0.5.3, an attacker controlling prover-side observations can craft distinct transcripts that produce identical challenges, breaking the binding property of Fiat-Shamir. This issue has been patched in versions 0.4.3 and 0.5.3.41dCVE-2026-291467.5 ALT94.8%
——28Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.
Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.29d