OCaml Vulnerability CVE-2026-28364 Allows Remote Code Execution

OCaml Vulnerability CVE-2026-28364 Allows Remote Code Execution

First seen 1 Mar 2026, 03:10 UTC Api.Msrc.MicrosoftWindowsforum 63.7

Article Content

Browse articles
ThreatCluster

A vulnerability tracked as CVE-2026-28364 affects OCaml versions prior to 4.14.3 and 5.x before 5.4.1, enabling remote code execution through a multi-phase attack chain. This issue arises from a buffer over-read in the Marshal deserialization process due to missing bounds validation in the readblock() function. Patches have been released to address this vulnerability.

Timeline

2026-02-27
CVE-2026-28364 published
2026-02-28
Patches 4.14.3 and 5.4.1 released to block RCE
2026-02-28
Articles published detailing the vulnerability