CVE-2026-40012
MEDIUMCVSS 5.3/10EPSS 0.30%
Last modified
CVE-2026-40012 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have ECS enabled;. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have ECS enabled;
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-40012?
ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have ECS enabled;
How severe is CVE-2026-40012?
CVE-2026-40012 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 0.30% probability of exploitation in the next 30 days.
How do I fix CVE-2026-40012?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-40007Uncontrolled Recursion, Uncontrolled Resource Consumption vu…7.5
- CVE-2026-40008Use of Externally-Controlled Input to Select Classes or Code…9.8
- CVE-2026-40009Improper Privilege Management, Improper Access Control vulne…6.5
- CVE-2026-4001The Woocommerce Custom Product Addons Pro plugin for WordPre…9.8
- CVE-2026-40010Missing invocation of Servlet http web request method change…9.1
- CVE-2026-40011An attacker sending a large number of crafted DNS queries mi…3.7
- CVE-2026-40016Attacker can upload a malicious Sieve script over ManageSiev…6.5
- CVE-2026-4002The Petje.af plugin for WordPress is vulnerable to Cross-Sit…4.3
- CVE-2026-40020Attacker can use the IMAP SETACL command to inject the anyon…4.3
- CVE-2026-40021Apache Log4net's XmlLayout https://logging.apache.org/log4n…5.3
- CVE-2026-40022When authentication is enabled on the Apache Camel embedded …8.2
- CVE-2026-40023Apache Log4cxx's XMLLayout https://logging.apache.org/log4c…5.3
Are you affected by CVE-2026-40012?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
