Microsoft Security Response Center guidance
Release Notes
Vulnerability intelligence
CVE-2026-102633 and is rated Medium severity with a CVSS score of 5.9. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Release Notes
libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service.