CVE-2026-45056
📛 CVE Title
(no title)
Description
Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- critical
- CVSS score
- 9.8 / 10
- CVSS vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Effective score
- 9.8 / 10 CRITICAL source: CNA overview
- CWE(s)
- —
- Reserved
- —
- Published
- —
- Last updated
- —
- Source
- https://www.tenable.com/cve/CVE-2026-45056
- Linked Threat
- CVE-2026-45056 — CVE-2026-45056
NVD / KEV / EPSS data refreshed 2026-06-29 03:28 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (2)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://nvd.nist.gov/vuln/detail/CVE-2026-45056 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2026-45056 tenable:www.cve.org
Remediations (10)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:cyberpress.org
The remediation level is listed as Official Fix , and report confidence is Confirmed. Mitigation Security teams should prioritize patching Microsoft Office LTSC 2024 installations immediately. Given the Preview Pane attack vector, organizations using Outlook (classic) face elevated risk even without direct user interaction with malicious content.
2026-06-19 02:34 UTC -
web:cybersecuritynews.com
Microsoft has officially acknowledged a critical zero-day vulnerability in Microsoft Defender, publicly dubbed "RoguePlanet," and confirmed it is actively developing a security patch to address the flaw.
2026-06-19 02:34 UTC -
web:gbhackers.com
Microsoft has disclosed a set of critical remote code execution (RCE) vulnerabilities affecting Outlook and Word.
2026-06-19 02:34 UTC -
web:learn.microsoft.com
Windows 11, version 25H2 is now available for all eligible devices. Devices running Home and Pro editions of Windows 11 that are not managed by IT departments will receive the update to Windows 11, version 25H2 through the machine learning-based intelligent rollout.
2026-06-19 02:34 UTC -
web:nvd.nist.gov
An official website of the United States government NVD MENU
2026-06-19 02:34 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-06-19 02:34 UTC -
web:windowsforum.com
The Patch Window Is the Real Security Boundary The practical lessons from CVE - 2026 -45657 are not mysterious, but they are concrete enough to separate disciplined shops from hopeful ones. This is not a vulnerability that rewards theatrical mitigation plans. It rewards boring execution: update, reboot, verify, segment, monitor.
2026-06-19 02:34 UTC -
web:www.computerworld.com
Microsoft says it is considering a patch for a zero-day vulnerability, dubbed YellowKey, that allows attackers with access to a Windows device to bypass Bitlocker encryption protection and read ...
2026-06-19 02:34 UTC -
web:www.csoonline.com
Microsoft released emergency fixes for two zero-day vulnerabilities in the malware protection components of Microsoft Defender. The flaws allow local attackers to gain system-level privileges or ...
2026-06-19 02:34 UTC -
web:www.malwarebytes.com
Microsoft says it's working on a fix for an unpatched Defender vulnerability that can give attackers the highest level of access on Windows.
2026-06-19 02:34 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.