<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cve-2026-28387 on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/cve-2026-28387/</link><description>Recent content in Cve-2026-28387 on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Wed, 18 Jun 2025 08:50:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/cve-2026-28387/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-28387: Azure DANE Client Use-After-Free Flaw</title><link>https://zxcloudsecurity.co.uk/posts/azure-dane-client-use-after-free-cve-2026-28387/</link><pubDate>Thu, 18 Jun 2026 08:50:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/azure-dane-client-use-after-free-cve-2026-28387/</guid><description>CVE-2026-28387 is a use-after-free bug in DANE client code affecting Azure. Learn the risks and what cloud architects should do now.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-28387">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-28387 is a use-after-free vulnerability identified in DANE (DNS-based Authentication of Named Entities) client code, which could allow an attacker to execute arbitrary code or cause a crash by exploiting improper memory management. DANE is used to validate TLS certificates via DNSSEC, meaning this flaw sits within a trust and authentication mechanism. If exploited, the impact could range from denial of service to remote code execution depending on the context in which the vulnerable code runs.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review whether your Azure-hosted services or workloads rely on DANE client implementations and apply any available patches from Microsoft promptly. Until patched, consider whether DANE validation can be temporarily disabled or isolated at the network edge to reduce exposure.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-28387">CVE-2026-28387 Potential Use-after-free in DANE Client Code</a></p>
]]></content:encoded></item></channel></rss>