Skip to main content

CVE-2026-45186

libexpat before 2.8.1 vulnerability

libexpat

MSRC advisory May 19, 2026

Alert details

Source feed
Microsoft MSRC
CVE ID
CVE-2026-45186
Affected products
libexpat before 2.8.1 · libexpat libexpat before 2.8.1 · libexpat

What happened

Information published.

What it means for your business

In In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input. (CVE-2026-45186) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Sources

Related briefs

HighMicrosoft MSRC

CVE-2025-0612

Object corruption in V8 in Microsoft Edge vulnerability

Object corruption in V8 in Microsoft Edge vulnerability (CVE-2025-0612) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54128

Windows DHCP Client Remote Code Execution vulnerability

Windows DHCP Client Remote Code Execution vulnerability (CVE-2026-54128) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50387

Windows GDI Elevation of Privilege vulnerability

Windows GDI Elevation of Privilege vulnerability (CVE-2026-50387) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-88779

Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Citrix NetScaler is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-88779). Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service. CISA remediation due date: 2026-10-07. If you need help checking exposure, call (864) 335-9223.

Need help patching?

PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.