CVE-2026-16459
Last modified
CVE-2026-16459 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and prior to 2.1.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.. EPSS estimates a 0.07% chance of exploitation in the next 30 days.
Description
Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and prior to 2.1.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Oberon microsystems AG | Oberon PSA Crypto | >= 1.0.0, < 2.1.1 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-16459?
How severe is CVE-2026-16459?
How do I fix CVE-2026-16459?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-16450A vulnerability was identified in zsadmin2025 ZS-Admin up to…4.3
- CVE-2026-16451A security flaw has been discovered in zsadmin2025 ZS-Admin …6.3
- CVE-2026-16454In Eclipse hawkBit versions 1.0.3 and prior, a privilege esc…4.3
- CVE-2026-16455In Teltonika Networks RUTOS devices running versions 7.07.1 …6.9
- CVE-2026-16456A flaw was found in the `odh-model-controller`. An authentic…6.5
- CVE-2026-16458Padding oracle attack vulnerability in Oberon microsystem AG…5.9
- CVE-2026-1646The Advance Block Extend plugin for WordPress is vulnerable …6.4
- CVE-2026-16461A stack-based buffer overflow was found in rpcbind's rpcinfo…6.5
- CVE-2026-16462In PROCON-WEB SCADA the endpoint 'GetGridData' is not proper…9.8
- CVE-2026-16463A maliciously crafted DXF file, when parsed through Autodesk…7.8
- CVE-2026-16465A maliciously crafted DWG or DXF file, when parsed through A…7.1
- CVE-2026-16466IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage co…8.8
Are you affected by CVE-2026-16459?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
