OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-93990

HIGH · CVSS 7.5 EPSS 0.40% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-19 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Expat versions up to 2.8.4 are vulnerable to XML injection due to improper validation of UTF-16 encoded input, specifically allowing low surrogates to follow high surrogates. This flaw can be exploited by attackers to craft malicious XML that conceals markup characters, potentially leading to unauthorized data manipulation or execution of arbitrary code. Organizations utilizing Expat for XML parsing should prioritize patching this vulnerability to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-93990
Severity
HIGH
CVSS
7.5
EPSS
0.40%

Original NVD Description

Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds.