Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39853

27
FAUCET Score

OVERVIEW CVE-2026-39853 is a stack buffer overflow vulnerability in osslsigncode versions prior to 2.12, a tool used for Authenticode signing and verification. The flaw exists in the signature verification paths for PE, MSI, CAB, and script files. During PKCS#7 signature verification, the application fails to validate the length of a digest value before copying it from a parsed SpcIndirectDataContent structure into a fixed 64-byte stack buffer, allowing an attacker to trigger a buffer overflow with a specially crafted malicious signed file. SEVERITY The vulnerability carries a CVSS 3.1 score of 7.8 (HIGH) with a local attack vector, low complexity, no privilege requirements, and user interaction needed. The impact is severe, affecting confidentiality, integrity, and availability with high severity across all three categories. Exploitation occurs when a user attempts to verify a malicious file, potentially enabling stack corruption that could lead to code execution, information disclosure, or denial of service. The EPSS score of 0.00015 indicates lower predictive likelihood of exploitation relative to other vulnerabilities. EXPLOITATION STATUS The vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and shows no active exploitation in the wild. No public exploit code has been reported, and community attention remains minimal, as reflected by the inactive Hot List status. Organizations should update osslsigncode to version 2.12 or later as a preventive measure, though immediate emergency patching is not required based on current threat intelligence.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.12CPE matchmatch criteria
cpe:2.3:a:osslsigncode_project:osslsigncode:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
5.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0016 is in the 4th percentile among its peer group of 11,617 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

microsoft2026-Apr/CVE-2026-39853Important

osslsigncode has a Stack Buffer Overflow via Unbounded Digest Copy During Signature Verification

Apr 2, 2026

References

github.com / mtrojnar/osslsigncode/commit/cbee1e723c5a8547302bd841ad9943ed8144db68
Patch
github.com / mtrojnar/osslsigncode/releases/tag/2.12
ProductRelease Notes
github.com / mtrojnar/osslsigncode/security/advisories/GHSA-hx87-8754-xvh4
Vendor Advisory