SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-16560

MEDIUM · CVSS 5.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

A heap-buffer-overflow vulnerability exists in Directory Server (389-ds-base), where a legacy-quoted value in a distinguished name (DN) can lead to improper memory management. This flaw may result in denial of service or arbitrary memory write operations, potentially compromising system stability and security. Organizations utilizing this directory server should prioritize patching to mitigate the risk associated with this vulnerability.

CVE
CVE-2026-16560
Severity
MEDIUM
CVSS
5.3
EPSS
0.24%

Original NVD Description

A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap allocation allowing another call to refer to the same memory pointer causing a denial of service or an arbitrary memory write operation.