USN-8769-1: phpseclib vulnerability
It was discovered that phpseclib did not perform padding validation in constant time when using AES in CBC mode. A remote attacker could possibly use this issue to conduct a padding oracle timing attack and obtain sensitive information.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8769-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-329350.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2024-273550.57% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2024-273540.60% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2023-528920.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Exploitation likely imminentCVE-2023-48795EPSS puts this in the most-targeted tier (93.3% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 99.8% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-32935 | coverage & exploitation status | NVD · CVE.org |
| CVE-2024-27355 | coverage & exploitation status | NVD · CVE.org |
| CVE-2024-27354 | coverage & exploitation status | NVD · CVE.org |
| CVE-2023-52892 | coverage & exploitation status | NVD · CVE.org |
| CVE-2023-48795 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [high] Cacti: Multiple Vulnerabilitiescert-bund
- highexploited[UPDATE] [high] Oracle Communications: Multiple vulnerabilitiescert-bund
- unknownJenkins Security Advisory 2024-04-17jenkins
- unknownJenkins Security Advisory 2024-03-06jenkins
More from Ubuntu Security Notices
- unknownUSN-8770-1: SimpleSAMLphp vulnerabilities2026-09-15
- unknownUSN-8768-1: Shibboleth vulnerability2026-09-15
- unknownUSN-8767-1: Snapcast vulnerability2026-09-15
- unknownUSN-8766-1: Suricata-Update vulnerability2026-09-15
- unknownUSN-8765-1: python-sql vulnerability2026-09-15