<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Web Dispatcher - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/web-dispatcher/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 08 Sep 2026 01:37:56 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/web-dispatcher/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Memory Safety Vulnerability in Extended Passport Protocol Library</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-44756/</link><pubDate>Tue, 08 Sep 2026 01:37:56 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-44756/</guid><description>An unauthenticated remote code execution vulnerability (CVE-2026-44756) in the Extended Passport Protocol library allows attackers to trigger crashes or potentially execute code via malformed network headers.</description><content:encoded><![CDATA[<p>CVE-2026-44756 describes a critical memory safety vulnerability discovered within the Extended Passport Protocol (EPP) processing library. This flaw permits an unauthenticated attacker to supply a specifically crafted network request containing a malformed EPP header. When processed by the library, this malformed input can lead to undefined memory behavior and abnormal program termination. Given the nature of memory corruption vulnerabilities in protocol parsers, this issue poses a significant risk to the confidentiality, integrity, and availability of any infrastructure or application utilizing this library. The CVSS base score of 10.0 reflects the critical potential for remote exploitation and total system impact. Defenders should prioritize identifying systems using this library and applying updates as they become available from their respective software vendors.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability results in service disruption via application crashes and carries the potential for arbitrary code execution. Organizations running public-facing services that utilize the EPP parsing library are at the highest risk, as they are exposed to unauthenticated exploitation attempts over the network.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Identify all internal and external-facing applications that incorporate the Extended Passport Protocol (EPP) processing library. Monitor network traffic logs for malformed or unusually large EPP protocol headers that may indicate exploitation attempts. Patch all instances of the EPP library to the latest vendor-supplied version as soon as updates are released to address the underlying memory safety flaw.</p>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>