CVE-2026-86137: Medium severity libxml2 libxml2 vulnerability
Published Sep 5, 2026
·Updated
In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.
Affected Software
4 affected componentsFixes available
libxml2 libxml2<2.15.4
Xmlsoft Libxml2<2.15.4
Microsoft azl3 libxml2 2.11.5-10<2.11.5-11
2.11.5-11
Microsoft azl3 libxml2 2.11.5-11<2.11.5-11
2.11.5-11
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.11.5-11
Event History
Sep 5, 2026
CVE Published
via MITRE·04:19 AM
Data Sourced
via MITRE·04:19 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 AM
RemedyDescriptionSeverityWeaknessAffected Software
Sep 6, 2026
Data Sourced
via Microsoft·11:37 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·11:37 AM
DescriptionSeverity
Updated
via Microsoft·11:37 AM
Affected Software
Frequently Asked Questions
1
Which installations are affected?
Installations using libxml2 versions earlier than 2.15.4 are affected. Updating to 2.15.4 or later addresses the issue.
2
What access does an attacker need?
The vulnerability is locally exploitable and has high attack complexity. It does not require privileges or user interaction according to the provided vector.
3
What is the expected security impact?
The reported impact is limited to availability; confidentiality and integrity are not affected. The severity is rated low, with a CVSS score of 2.9.