LOW

CVE-2026-28387

CVSS v3

8.1

LOW

EPSS Score

0.0%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Microsoft Security Update (CVE-2026-28387)

Technical details

CVSS v3 Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U
Published
5/7/2026
MSRC Title
Potential Use-after-free in DANE Client Code

Frequently asked questions

What is CVE-2026-28387?

Microsoft Security Update (CVE-2026-28387)

Is CVE-2026-28387 actively exploited?

Active exploitation of CVE-2026-28387 has not been confirmed. The EPSS score is 0.0%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-28387?

CVE-2026-28387 has a CVSS v3 base score of 8.1 (LOW severity), with vector string CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U.

Is CVE-2026-28387 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.