OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-88830

HIGH · CVSS 7.5 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

A unit confusion vulnerability in BusyBox TLS affects Microsoft Exchange, leading to a pre-authentication heap buffer overflow when handling a specially crafted ClientKeyExchange message. This flaw can be exploited by an attacker to execute arbitrary code, potentially compromising the affected system. Organizations using Exchange should prioritize patching this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-88830
Severity
HIGH
CVSS
7.5
EPSS
0.35%
Exchange

Original NVD Description

A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow when processing a crafted ClientKeyExchange message.