CVE-2026-56405 libexpat before 2.8.2 has an integer overflow in getAttributeId. Information published. EPSS 0.00 CVE-2026-56405 libexpat US Microsoft Security · 27. 6. 10:04