CVE-2026-86140: Buffer Overflow
Published Sep 5, 2026
·Updated
In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.
Affected Software
3 affected componentsFixes available
libxml2 libxml2<2.15.4
Xmlsoft Libxml2<2.15.4
Microsoft azl3 libxml2 2.11.5-10<2.11.5-11
2.11.5-11
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.11.5-11
Event History
Sep 5, 2026
CVE Published
via MITRE·04:26 AM
Data Sourced
via MITRE·04:26 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 AM
RemedyDescriptionSeverityWeaknessAffected Software
Sep 6, 2026
Data Sourced
via Microsoft·11:36 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·11:36 AM
Affected Software
Updated
via Microsoft·11:36 AM
DescriptionSeverity
Frequently Asked Questions
1
Which deployments are affected?
libxml2 versions before 2.15.4 are affected. Systems using version 2.15.4 or later are not identified as affected by the provided data.
2
What access does an attacker need?
The listed attack vector is local. The vulnerability is rated as requiring no privileges and no user interaction.
3
What could successful exploitation impact?
The severity vector indicates high confidentiality and integrity impact, with low availability impact.
4
How can I determine whether I need to remediate?
Identify the libxml2 version installed or bundled with the affected application. Remediate installations running a version earlier than 2.15.4.