<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Kerberos on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/kerberos/</link><description>Recent content in Kerberos on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Fri, 13 Jun 2025 08:42:15 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/kerberos/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-5545: Azure HTTP Negotiate Connection Reuse Flaw</title><link>https://zxcloudsecurity.co.uk/posts/azure-http-negotiate-connection-reuse-cve-2026-5545/</link><pubDate>Sat, 13 Jun 2026 08:42:15 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/azure-http-negotiate-connection-reuse-cve-2026-5545/</guid><description>CVE-2026-5545 affects HTTP Negotiate connection reuse in Azure, potentially enabling session hijacking and unauthorised access. Patch now.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5545">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-5545 is a vulnerability involving the incorrect reuse of HTTP Negotiate authentication connections, which could allow an attacker to hijack or impersonate authenticated sessions. This type of flaw can lead to unauthorised access to resources by exploiting the way authentication tokens are shared across connections. It is particularly concerning in environments where multiple users or services share HTTP connections.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review any services or middleware that use HTTP Negotiate (Kerberos/NTLM) authentication and ensure connection pooling is configured to enforce strict session isolation. Apply the relevant Microsoft patches promptly and consider monitoring for anomalous authentication patterns that could indicate session hijacking.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5545">CVE-2026-5545 wrong reuse of HTTP Negotiate connection</a></p>
]]></content:encoded></item></channel></rss>