<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cryptographic-Message-Syntax on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/cryptographic-message-syntax/</link><description>Recent content in Cryptographic-Message-Syntax on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Mon, 16 Jun 2025 09:14:59 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/cryptographic-message-syntax/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-34182: Azure CMS AuthEnvelopedData Forgery Flaw</title><link>https://zxcloudsecurity.co.uk/posts/azure-cms-authenvelopeddata-forged-messages-cve-2026-34182/</link><pubDate>Tue, 16 Jun 2026 09:14:59 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/azure-cms-authenvelopeddata-forged-messages-cve-2026-34182/</guid><description>CVE-2026-34182 allows forged CMS AuthEnvelopedData messages to be accepted as valid, threatening message integrity in Azure environments. Patch now.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34182">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-34182 is a vulnerability in CMS (Cryptographic Message Syntax) AuthEnvelopedData processing that may allow an attacker to submit forged encrypted messages that are incorrectly accepted as valid. This undermines the integrity guarantees of authenticated encryption, potentially enabling an attacker to bypass message authentication checks. The flaw is particularly concerning in any Azure service or component that relies on CMS for secure message handling.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review any Azure workloads or integrations that consume CMS AuthEnvelopedData — such as certificate-based messaging, encrypted payloads, or PKI workflows — and apply Microsoft&rsquo;s patch promptly. Until patched, consider adding upstream validation controls or signature verification layers to reduce exposure.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34182">CVE-2026-34182 CMS AuthEnvelopedData Processing May Accept Forged Messages</a></p>
]]></content:encoded></item></channel></rss>