CVE-2026-42766 Possible NULL Dereference in Password-Based CMS Decryption Information published. EPSS 0.01 CVE-2026-42766 US Microsoft Security · 13. 6. 10:05