CWE-1240
CVEs classified under CWE-1240, newest first.
3 CVEsRSS
CVE-2026-59651High· 7.5In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key
In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.16%via NVD
CVE-2026-50303Medium· 5.5Windows Key Guard Security Feature Bypass Vulnerability
Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally.
▾ SunlitMicrosoft · Windows 10 Version 1809EPSS 0.27%via CVEORG
CVE-2026-29146High· 7.5Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 thr…
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 thr…
▾ Twilightapache · tomcatEPSS 8.8%via NVD