CoreWCF has 13 CVEs on record. Disclosures have slowed: 0 in the last 90 days after 13 in the 90 before. The busiest recent month was June 2026 with 13. The median CVSS is 6.5 (medium), with 1 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-347 (4) and CWE-345 (3). Most affected products: CoreWCF.Primitives (8), CoreWCF.UnixDomainSocket (2), CoreWCF.Kafka (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 0 prev 13
Products
- CoreWCF.Primitives 8
- CoreWCF.UnixDomainSocket 2
- CoreWCF.Kafka 1
- CoreWCF.NetFramingBase 1
- CoreWCF.NetNamedPipe 1
Worst active — by depth score
CVE-2026-54782Critical· 10.0CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation55CVE-2026-54784High· 7.4CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality41CVE-2026-54783High· 7.4CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages41CVE-2026-54781High· 7.4CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced41CVE-2026-54774High· 7.4CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate41
CoreWCF vulnerabilities
CVEs affecting CoreWCF, newest first. Open any entry for full detail, references, and exploit status.
13 CVEsRSS
CVE-2026-54772High· 7.5CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake
CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake
CVE-2026-54773Medium· 5.9CoreWCF: WS-Security signature substitution via document-wide Signature lookup
CoreWCF: WS-Security signature substitution via document-wide Signature lookup
CVE-2026-54774High· 7.4CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate
CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate
CVE-2026-54775Medium· 6.5CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.
CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.
CVE-2026-54776Medium· 4.4CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade
CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade
CVE-2026-54777Medium· 6.5CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance
CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance
CVE-2026-54778Medium· 6.2CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution
CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution
CVE-2026-54779Medium· 5.9CoreWCF: SAML token replay protection is inoperative
CoreWCF: SAML token replay protection is inoperative
CVE-2026-54780Low· 3.7CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass
CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass
CVE-2026-54781High· 7.4CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced
CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced
CVE-2026-54782Critical· 10.0CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation
CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation
CVE-2026-54783High· 7.4CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages
CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages
CVE-2026-54784High· 7.4CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality