Exploits for CVE-2016-4463 and CVE-2017-2636 Released

Exploits for CVE-2016-4463 and CVE-2017-2636 Released

First seen 8 Sep 2026, 02:01 UTC Sploitus 36.9

Article Content

Browse articles
ThreatCluster

Recent articles detail exploits for two CVEs: CVE-2016-4463 and CVE-2017-2636. The first exploit targets Xerces versions 3.1.3 and below, with indications that Java OpenSAML may also be vulnerable. The second exploit provides a workaround to blacklist the `n_hdlc` module on Red Hat Enterprise Linux versions 6 and 7, including CentOS and CloudLinux. The CVE-2016-4463 exploit was intended for submission to Exploit-DB but lacks testing due to the absence of reliable applications. CVE-2017-2636 was published on March 7, 2017, with a public proof-of-concept released shortly after. Both vulnerabilities could pose risks to systems still running affected versions, necessitating immediate attention from security professionals.

Key Points: • CVE-2016-4463 exploits Xerces versions 3.1.3 and below. • CVE-2017-2636 provides a workaround for Red Hat Enterprise Linux 6 and 7. • Both vulnerabilities require urgent attention to mitigate potential risks.

Ask AI about this cluster

Timeline

2017-03-07
CVE-2017-2636 published
CVE-2017-2636 was published, detailing vulnerabilities in the `n_hdlc` module.
Sploitus
2017-03-10
First public PoC for CVE-2017-2636
A proof-of-concept for CVE-2017-2636 was made publicly available shortly after its publication.
Sploitus
2026-09-07
Exploit for CVE-2016-4463 released
An exploit for CVE-2016-4463 targeting Xerces versions 3.1.3 and below was reported.
Sploitus
2026-09-08
Exploit for CVE-2017-2636 documented
A documented workaround for CVE-2017-2636 was established to blacklist the `n_hdlc` module.
Sploitus