View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

CVE-2026-86140: libxml2 strcat stack buffer overflow (CVSS 8.0)

🔓 CVEs & KEV

  • CVE-2026-86140 — xmlsoft libxml2 — CVSS 8.0 — In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-b...

  • CVE-2026-86143 — xmlsoft libxml2 — CVSS 6.9 — In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback...

  • CVE-2026-86142 — xmlsoft libxml2 — CVSS 6.9 — In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEva...

  • CVE-2026-86139 — xmlsoft libxml2 — CVSS 6.9 — In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.

  • CVE-2026-86138 — xmlsoft libxml2 — CVSS 6.9 — In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check