# CWE-126: Buffer Over-read

> As of 2026-10-10, CWE-126 (Buffer Over-read) underlies 5 CVEs tracked by Threadlinqs, none of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 5 tracked threats.

**Last updated:** 2026-10-10

## What is CWE-126?

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

CWE-126 is a variant-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Memory-Unsafe; C; C++.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/126.html) (CWE-126 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Confidentiality** — Read Memory
- **Confidentiality** — Bypass Protection Mechanism. By reading out-of-bounds memory, an attacker might be able to get secret values, such as memory addresses, which can bypass protection mechanisms such as ASLR in order to improve the reliability and likelihood of exploiting a separate weakness to achieve code execution instead of just denial of service.
- **Availability, Integrity** — DoS: Crash, Exit, or Restart. An attacker might be able to cause a crash or other denial of service by causing the product to read a memory location that is not allowed (such as a segmentation fault), or to cause other conditions in which the read operation returns more data than is expected.

_Source: MITRE CWE, common consequences._

## How CWE-126 is exploited in the wild

Threadlinqs maps 5 CVEs to CWE-126, published between 2026-07-14 and 2026-08-11. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 5 medium. The highest EPSS score in the set is 0.6% (CVE-2026-50445), the modelled probability of exploitation in the next 30 days. 5 tracked threats reference CWE-126 directly or through a CVE it covers; the most recent is “Cisco Talos disclosure: Microsoft, Adobe, Apple, and Foxit vulnerabilities (CVE-2026-48388, CVE-2026-57256, CVE-2026-91799, CVE-2026-50475, CVE-2026-58613, CVE-2026-80093, CVE-2026-49177)” (2026-10-07). Affected products concentrate in Fortinet (2), Microsoft (2), Zoom Communications (1).

## Vulnerabilities (CVEs)

All 5 CVEs mapped to CWE-126, CISA KEV first, then by CVSS score.

- [CVE-2026-50445](https://intel.threadlinqs.com/cve/CVE-2026-50445) — CVSS 6.5 medium · EPSS 0.6% · published 2026-07-14
- [CVE-2026-53414](https://intel.threadlinqs.com/cve/CVE-2026-53414) — CVSS 6.5 medium · EPSS 0.3% · published 2026-08-11
- [CVE-2026-50475](https://intel.threadlinqs.com/cve/CVE-2026-50475) — CVSS 5.5 medium · EPSS 0.3% · published 2026-07-14
- [CVE-2025-43892](https://intel.threadlinqs.com/cve/CVE-2025-43892) — CVSS 4.1 medium · EPSS 0.3% · published 2026-07-14
- [CVE-2026-59840](https://intel.threadlinqs.com/cve/CVE-2026-59840) — CVSS 4.1 medium · EPSS 0.3% · published 2026-07-14

## Affected vendors

- [Fortinet](https://intel.threadlinqs.com/vendors/fortinet) — 2 CVEs
- [Microsoft](https://intel.threadlinqs.com/vendors/microsoft) — 2 CVEs
- [Zoom Communications](https://intel.threadlinqs.com/vendors/zoom-communications) — 1 CVE

## Threat activity

5 tracked threats cite CWE-126:

- [Cisco Talos disclosure: Microsoft, Adobe, Apple, and Foxit vulnerabilities (CVE-2026-48388, CVE-2026-57256, CVE-2026-91799, CVE-2026-50475, CVE-2026-58613, CVE-2026-80093, CVE-2026-49177)](https://intel.threadlinqs.com/threat/TL-2026-3011) — HIGH · 2026-10-07
- [Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)](https://intel.threadlinqs.com/threat/TL-2026-2486) — CRITICAL · 2026-09-13
- ["Zoomsday" Flaws (CVE-2026-53413, CVE-2026-53414, CVE-2026-53415) Let One Zoom Meeting Participant Attack Another](https://intel.threadlinqs.com/threat/TL-2026-2001) — CRITICAL · 2026-08-12
- [Windows RDP Memory-Disclosure Vulnerabilities (CVE-2026-50445, CVE-2026-57982, CVE-2026-55003, CVE-2026-50497, CVE-2026-57979) — July 2026 Patch Tuesday](https://intel.threadlinqs.com/threat/TL-2026-1370) — MEDIUM · 2026-07-15
- [NGINX Rift — CVE-2026-42945 Heap Buffer Overflow in ngx_http_rewrite_module (CVSS v4 9.2 Critical, 18-Year-Old Pre-Auth RCE, Public PoC)](https://intel.threadlinqs.com/threat/TL-2026-0517) — CRITICAL · 2026-05-14

## Detection methods (MITRE CWE)

- **Automated Static Analysis**: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)
- **Automated Dynamic Analysis**: Use tools that are integrated during compilation to insert runtime error-checking mechanisms related to memory safety errors, such as AddressSanitizer (ASan) for C/C++ [REF-1518].

_Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher._

## Related weaknesses

- [CWE-125 Out-of-bounds Read](https://intel.threadlinqs.com/cwe/CWE-125)
- [CWE-788](https://cwe.mitre.org/data/definitions/788.html)

Canonical: https://intel.threadlinqs.com/cwe/CWE-126
Source definition: https://cwe.mitre.org/data/definitions/126.html
Detection rules and IOCs for threats exploiting CWE-126 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
