CVE-2026-28364 - Vulnerability Details

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
February 28, 2026
Last Seen
February 28, 2026

Related Threat Clusters

  • OCaml Vulnerability CVE-2026-28364 Allows Remote Code Execution

    A vulnerability tracked as CVE-2026-28364 affects OCaml versions prior to 4.14.3 and 5.x before 5.4.1, enabling remote code execution through a multi-phase attack chain. This issue arises from a buffer over-read in the…

    2 articles · Updated February 28, 2026

Recent Intelligence Reports

  • CVE-2026-28364 In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker — Api.Msrc.Microsoft · February 28, 2026

CVSS v3.1 Breakdown