A vulnerability classified as problematic has been found in libexpat project libexpat up to 2.8.3. This affects the function storeAtts of the file xmlparse.c of the component Parser. This manipulation of the argument N causes observable response discrepancy. This vulnerability appears as CVE-2026-66046. The attack may be initiated remotely. There... Weiterlesen
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2026-66046 | libexpat project up to 2.8.3 Parser xmlparse.c storeAtts N response discrepancy (Nessus ID 350928)
A vulnerability classified as problematic has been found in libexpat project libexpat up to 2.8.3. This affects the function storeAtts of the file xmlparse.c of the component Parser. This manipulation of the argument N causes observable…
Reagiere als Erste:r — dein Feedback zählt!
2. Cyber Threat Intelligence & Forensik
IoC Intelligence (1 Indikatoren)
CVE-2026-66046
Exploit & Remediation Lifecycle Timeline
CVE-2026-66046Entdeckung & Meldung
Schwachstelle identifiziert & registriert
Sicherheits-Advisory
Offizielle Warnung & CVE-Zuweisung
Exploit / PoC
Öffentlicher Nachweis/Code verfügbar (Exploit-DB/EUVD)
In-the-Wild Ausnutzung
Keine Massenausnutzung gemeldet
Patch & Schutzmaßnahmen
Upstream-Patch-Referenz vorhanden (Commit-/Advisory-Link)
Exploit Weaponization & Public PoC Radar
CRITICAL WEAPONIZED · Index 75/100Exploit-DB
Kein EDB-EintragInteraktion
0-ClickAuthentifizierung
Nicht erforderlich3. Compliance, SLA & Vendor Adherence
BSI-Warnung (Deutschland)CVE-2026-66046
expat: Schwachstelle ermöglicht Denial of Service mittel18.08.2026CISA-SSVC-Triage (vulnrichment)CVE-2026-66046
Exploitation: none (Keine bekannte Ausnutzung)Automatable: yes (Automatisierbar)Technical Impact: partial (Teilweise)
Quelle: CISA-ADP vulnrichment · Stand 2026-08-20T13:48:24.577412Z · CISA Coordinator
Advisory Radar
Workaround & Virtual-Patching empfohlen
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Öffentliche PoCs existieren. Isolieren Sie das System oder wenden Sie Micro-Segmentierungsregeln an, bis offizielle Patches vorliegen.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com
1 öffentliche Exploit-Referenz(en) detektiert (VulnCheck Exploit Intelligence).
PoC einsehen