Threats Tagged 'cwe-326'
View all threats tagged with 'cwe-326'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-326'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-65777: CWE-326: Inadequate Encryption Strength in Microsoft Windows 11 version 23H2CVE-2026-65777 0 Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network. Join the discussion | CVE Database V5 | 08/11/2026, 17:06:52 UTC Added: 08/11/2026, 17:13:20 UTC |
CVE-2026-9201: CWE-326 Inadequate Encryption Strength in IBM Langflow OSSCVE-2026-9201 0 IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component validation mechanism. When the optional hardening mode that restricts execution to trusted component templates is enabled, the application validates component code using a truncated SHA‑256 hash. Because the hash comparison relies on only a portion of the digest, an attacker can craft malicious component code that collides with a trusted template hash and bypasses validation. Successful exploitation allows the attacker to introduce and execute unauthorized Python code within the Langflow process, defeating the intended security control and potentially leading to full compromise of the affected instance. Join the discussion | CVE Database V5 | 08/05/2026, 18:26:16 UTC Added: 08/05/2026, 19:12:03 UTC |
CVE-2026-59651: CWE-326 Inadequate Encryption Strength in Legion of the Bouncy Castle Inc. BC-JAVACVE-2026-59651 0 CVE-2026-59651 is a vulnerability in Bouncy Castle for Java (BC-JAVA) affecting versions before 1.85 and LTS versions from 2.73.0 up to but not including 2.73.12. The issue involves the BKS keystore accepting a legacy version that uses a 16-bit integrity MAC key, which is considered inadequate encryption strength. This weakness could potentially undermine the integrity protection of the keystore data. Join the discussion | CVE Database V5 | 08/03/2026, 00:41:23 UTC Added: 08/03/2026, 01:03:47 UTC |
CVE-2026-4648: CWE-326: Inadequate Encryption Strength in CasfID Servicios Tecnológicos NFC WristbandsCVE-2026-4648 0 Use of an insecure cryptographic algorithm in the cashless payment system using NFC wristbands from CasfID Servicios Tecnológicos S.L.U. (version used at Resurrection Fest 2025), which employs cards based on MIFARE Classic technology (FM11RF08S). The cryptographic weakness of the authentication algorithm allows an attacker to retrieve access keys using techniques known as Backdoored Nested Attack, read the wristband’s entire contents, and clone its credentials onto a compatible rewritable card. Exploitation of this vulnerability could enable the impersonation of other attendees, the fraudulent use of the balance associated with their wristbands, and financial losses for both the affected users and the event organizers. Join the discussion | CVE Database V5 | 07/28/2026, 11:41:15 UTC Added: 07/28/2026, 11:52:52 UTC |
CVE-2026-50044: CWE-326 Inadequate Encryption Strength in Pronetiqs Panduit IntravueCVE-2026-50044 0 Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an attacker to steal admin credentials via weak hash or a pass-the-hash attack. Join the discussion | CVE Database V5 | 07/23/2026, 22:03:25 UTC Added: 07/23/2026, 22:37:36 UTC |
CVE-2024-23564: CWE-326: Inadequate Encryption Strength in HCL Software Aftermarket EPCCVE-2024-23564 0 HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response. The application includes checks in the initial requests to verify the validity of the provided UserId, but similar validation is not applied to Email requests when sending passwords to user emails. Join the discussion | CVE Database V5 | 07/17/2026, 13:25:40 UTC Added: 07/18/2026, 11:09:01 UTC |
CVE-2026-35146: CWE-326: Inadequate Encryption Strength in HCLSoftware DFXServerCVE-2026-35146 0 HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could allow a remote attacker to intercept network traffic and expose sensitive data transmitted between the user and the application. Join the discussion | CVE Database V5 | 07/16/2026, 11:01:08 UTC Added: 07/16/2026, 11:48:04 UTC |
CVE-2026-45363: CWE-287: Improper Authentication in jwt ruby-jwtCVE-2026-45363 0 ruby-jwt versions prior to 2.10.3 and 3.2.0 contain an improper authentication vulnerability in the JWT.decode method when using HS256, HS384, or HS512 algorithms. The issue arises because an empty key is accepted during HMAC verification, allowing attacker-forged tokens to be validated. This vulnerability is fixed in versions 2.10.3 and 3.2.0. Join the discussion | CVE Database V5 | 07/14/2026, 21:32:26 UTC Added: 07/14/2026, 21:48:16 UTC |
Showing 1 to 8 of 8 results