CVE-2026-56406 libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse. Information published. EPSS 0.00 CVE-2026-56406 libexpat US Microsoft Security · 27. 6. 10:05