Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5264

31
FAUCET Score

CVE-2026-5264 is a heap buffer overflow vulnerability in DTLS 1.3 ACK message processing that allows a remote attacker to trigger a crash or potentially execute arbitrary code by sending a specially crafted ACK message. The specific affected products are not detailed in the available data, but this vulnerability impacts systems utilizing DTLS 1.3 protocol implementations. The vulnerability presents a moderate risk with a FAUCET Risk Score of 50.0 out of 100, though precise CVSS metrics are not yet available. The attack requires only network access with no special privileges or user interaction, making it remotely exploitable. However, the extremely low EPSS score of 0.002410000 indicates this vulnerability is currently ranked lower in probability of exploitation compared to the vast majority of known CVEs. Regarding exploitation status, there is no evidence of active real-world exploitation, as the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and remains inactive on threat intelligence hot lists. No publicly available exploit code has been documented in the accessible vulnerability databases at this time.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 5.9.1CPE match
cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*
< 5.9.1CPE matchmatch criteria
cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.3HIGH

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.45%
Probability of exploitation in next 30 days
EPSS Percentile
36.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0045 is in the 14th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

microsoft2026-Apr/CVE-2026-5264Important

DTLS 1.3 ACK heap buffer overflow

Apr 14, 2026

References

github.com / wolfssl/wolfssl/pull/10076
Issue TrackingPatch