<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cve-2026-45446 on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/cve-2026-45446/</link><description>Recent content in Cve-2026-45446 on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Fri, 20 Jun 2025 08:42:18 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/cve-2026-45446/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-45446: AES-GCM-SIV Empty Message Tag Flaw</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-45446-aes-gcm-siv-empty-message-tag-processing-vulnerability/</link><pubDate>Sat, 20 Jun 2026 08:42:18 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-45446-aes-gcm-siv-empty-message-tag-processing-vulnerability/</guid><description>CVE-2026-45446 exposes a tag processing flaw in AES-GCM-SIV and AES-SIV modes for empty messages, risking authentication bypass and data forgery.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45446">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-45446 is a vulnerability affecting AES-GCM-SIV and AES-SIV encryption modes, where empty messages are processed with incorrect authentication tags. This flaw could allow an attacker to bypass integrity checks on empty ciphertexts, potentially enabling undetected data tampering or forgery in systems relying on these encryption schemes.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Audit any Azure services or application code that uses AES-GCM-SIV or AES-SIV encryption, particularly where empty message handling is a possibility — apply Microsoft&rsquo;s recommended patches or mitigations promptly and review cryptographic library dependencies for affected versions.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45446">CVE-2026-45446 Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes</a></p>
]]></content:encoded></item></channel></rss>