Product
A heap-based buffer overflow in the Cyrus SASL DIGEST-MD5 plugin, tracked as CVE-2026-107161, allows remote malicious servers to cause memory corruption in client applications.