OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102728

HIGH · CVSS 7.5 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability exists in the TLS/DTLS handshake parsers of NetX Secure, where client-side implementations read fields from server-supplied messages without proper length validation, leading to potential out-of-bounds reads. This flaw can be exploited by a malicious or malformed server during a handshake, potentially allowing an attacker to access sensitive data or cause application instability. Organizations using NetX Secure for TLS/DTLS communications should prioritize addressing this issue to mitigate risks associated with remote exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102728
Severity
HIGH
CVSS
7.5
EPSS
0.24%

Original NVD Description

Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that the message is long enough to contain them. Both are bounded out-of-bounds reads on a remotely reachable path, both are reached from a TLS or DTLS client connecting to a malicious or malformed server, and both have the same shape: the bounds check exists and returns the correct status, but it runs after the read it is meant to guard.