Skip to content

CVE-2026-32935

CVE

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
March 28, 2026
Last Seen
September 29, 2026
API
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A critical information disclosure vulnerability (CVE-2026-32935) was identified in the phpseclib library, affecting Fedora 42 and 43. The vulnerability allows attackers to exploit a padding oracle timing attack when using AES in CBC mode, potentially disclosing sensitive information. The issue was p...

Multiple vulnerabilities were discovered in phpseclib, a library for arbitrary-precision integer arithmetic. Notably, CVE-2026-32935 involves a lack of constant-time padding validation in AES CBC mode, potentially allowing remote attackers to obtain sensitive information. CVE-2026-40194 highlights a...

Public Exploits

Checking GitHub for proof-of-concept code…