{"schema_version":1,"title":"CoreWCF vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 11 vulnerabilities in CoreWCF: 0 in the last 7 days and 11 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-54784, was published on 8 July 2026.","url":"https://junglewise.ai/threats/technologies/corewcf","json_url":"https://junglewise.ai/threats/technologies/corewcf.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/corewcf","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":4,"all_time":11,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":11,"last_365_days":11},"latest":[{"cve":"CVE-2026-54784","cvss":7.4,"epss":0.0027,"slug":"cve-2026-54784-corewcf-cleartext-proof-key-exposure-in-spnego-negotiation","title":"CoreWCF cleartext proof key exposure in SPNEGO negotiation","severity":"high","exploited":false,"published_at":"2026-07-08T23:16:56.307+00:00","url":"https://junglewise.ai/threats/cve-2026-54784-corewcf-cleartext-proof-key-exposure-in-spnego-negotiation"},{"cve":"CVE-2026-54783","cvss":7.4,"epss":0.0019,"slug":"cve-2026-54783-corewcf-signature-verification-bypass-in-ws-security","title":"CoreWCF signature verification bypass in WS-Security","severity":"high","exploited":false,"published_at":"2026-07-08T23:16:56.173+00:00","url":"https://junglewise.ai/threats/cve-2026-54783-corewcf-signature-verification-bypass-in-ws-security"},{"cve":"CVE-2026-54782","cvss":10,"epss":0.0041,"slug":"cve-2026-54782-corewcf-authentication-bypass-in-saml-token-validation","title":"CoreWCF authentication bypass in SAML token validation","severity":"critical","exploited":false,"published_at":"2026-07-08T23:16:56.03+00:00","url":"https://junglewise.ai/threats/cve-2026-54782-corewcf-authentication-bypass-in-saml-token-validation"},{"cve":"CVE-2026-54781","cvss":7.4,"epss":0.0025,"slug":"cve-2026-54781-corewcf-improper-authentication-in-saml-samlsecuritytokenhandler","title":"CoreWCF improper authentication in SAML SamlSecurityTokenHandler","severity":"high","exploited":false,"published_at":"2026-07-08T23:16:55.89+00:00","url":"https://junglewise.ai/threats/cve-2026-54781-corewcf-improper-authentication-in-saml-samlsecuritytokenhandler"},{"cve":"CVE-2026-54780","cvss":3.7,"epss":0.0024,"slug":"cve-2026-54780-corewcf-algorithm-downgrade-in-ws-security-receive-pipeline","title":"CoreWCF algorithm downgrade in WS-Security receive pipeline","severity":"low","exploited":false,"published_at":"2026-07-08T23:16:55.757+00:00","url":"https://junglewise.ai/threats/cve-2026-54780-corewcf-algorithm-downgrade-in-ws-security-receive-pipeline"},{"cve":"CVE-2026-54779","cvss":5.9,"epss":0.0043,"slug":"cve-2026-54779-corewcf-saml-token-replay-protection-bypass-in","title":"CoreWCF SAML token replay protection bypass in DefaultTokenReplayCache","severity":"medium","exploited":false,"published_at":"2026-07-08T23:16:55.63+00:00","url":"https://junglewise.ai/threats/cve-2026-54779-corewcf-saml-token-replay-protection-bypass-in"},{"cve":"CVE-2026-54778","cvss":6.2,"epss":0.0013,"slug":"cve-2026-54778-corewcf-race-condition-in-unixdomainsocket-identity-resolution","title":"CoreWCF race condition in UnixDomainSocket identity resolution","severity":"medium","exploited":false,"published_at":"2026-07-08T23:16:55.493+00:00","url":"https://junglewise.ai/threats/cve-2026-54778-corewcf-race-condition-in-unixdomainsocket-identity-resolution"},{"cve":"CVE-2026-54775","cvss":6.5,"epss":0.006,"slug":"cve-2026-54775-corewcf-denial-of-service-via-kafka-tombstone-record","title":"CoreWCF denial of service via Kafka tombstone record","severity":"medium","exploited":false,"published_at":"2026-07-08T23:16:55.227+00:00","url":"https://junglewise.ai/threats/cve-2026-54775-corewcf-denial-of-service-via-kafka-tombstone-record"},{"cve":"CVE-2026-54774","cvss":7.4,"epss":0.002,"slug":"cve-2026-54774-corewcf-saml-signature-bypass-in-samlserializer","title":"CoreWCF SAML signature bypass in SamlSerializer","severity":"high","exploited":false,"published_at":"2026-07-08T23:16:55.09+00:00","url":"https://junglewise.ai/threats/cve-2026-54774-corewcf-saml-signature-bypass-in-samlserializer"},{"cve":"CVE-2026-54773","cvss":5.9,"epss":0.0037,"slug":"cve-2026-54773-corewcf-improper-signature-verification-in-ws-security","title":"CoreWCF improper signature verification in WS-Security","severity":"medium","exploited":false,"published_at":"2026-07-08T23:16:54.96+00:00","url":"https://junglewise.ai/threats/cve-2026-54773-corewcf-improper-signature-verification-in-ws-security"},{"cve":"CVE-2026-54777","cvss":6.5,"epss":0.0012,"slug":"cve-2026-54777-corewcf-netnamedpipe-race-condition-in-namedpipelistener","title":"CoreWCF NetNamedPipe race condition in NamedPipeListener","severity":"medium","exploited":false,"published_at":"2026-07-08T22:17:15.24+00:00","url":"https://junglewise.ai/threats/cve-2026-54777-corewcf-netnamedpipe-race-condition-in-namedpipelistener"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":1,"exploited":0,"vulnerabilities":11},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"CoreWCF","slug":"corewcf","vendor":{"name":"CoreWCF","slug":"corewcf","url":"https://junglewise.ai/threats/vendors/corewcf"},"aliases":[],"category":"library","homepage":"https://github.com/CoreWCF/CoreWCF","repo_url":"https://github.com/CoreWCF/CoreWCF","description":"CoreWCF is a port of Windows Communication Foundation (WCF) to .NET Core, providing a framework for building service-oriented applications.","url":"https://junglewise.ai/threats/technologies/corewcf"},"most_severe":[{"cve":"CVE-2026-54782","cvss":10,"epss":0.0041,"slug":"cve-2026-54782-corewcf-authentication-bypass-in-saml-token-validation","title":"CoreWCF authentication bypass in SAML token validation","severity":"critical","exploited":false,"published_at":"2026-07-08T23:16:56.03+00:00","url":"https://junglewise.ai/threats/cve-2026-54782-corewcf-authentication-bypass-in-saml-token-validation"},{"cve":"CVE-2026-54784","cvss":7.4,"epss":0.0027,"slug":"cve-2026-54784-corewcf-cleartext-proof-key-exposure-in-spnego-negotiation","title":"CoreWCF cleartext proof key exposure in SPNEGO negotiation","severity":"high","exploited":false,"published_at":"2026-07-08T23:16:56.307+00:00","url":"https://junglewise.ai/threats/cve-2026-54784-corewcf-cleartext-proof-key-exposure-in-spnego-negotiation"},{"cve":"CVE-2026-54781","cvss":7.4,"epss":0.0025,"slug":"cve-2026-54781-corewcf-improper-authentication-in-saml-samlsecuritytokenhandler","title":"CoreWCF improper authentication in SAML SamlSecurityTokenHandler","severity":"high","exploited":false,"published_at":"2026-07-08T23:16:55.89+00:00","url":"https://junglewise.ai/threats/cve-2026-54781-corewcf-improper-authentication-in-saml-samlsecuritytokenhandler"},{"cve":"CVE-2026-54774","cvss":7.4,"epss":0.002,"slug":"cve-2026-54774-corewcf-saml-signature-bypass-in-samlserializer","title":"CoreWCF SAML signature bypass in SamlSerializer","severity":"high","exploited":false,"published_at":"2026-07-08T23:16:55.09+00:00","url":"https://junglewise.ai/threats/cve-2026-54774-corewcf-saml-signature-bypass-in-samlserializer"},{"cve":"CVE-2026-54783","cvss":7.4,"epss":0.0019,"slug":"cve-2026-54783-corewcf-signature-verification-bypass-in-ws-security","title":"CoreWCF signature verification bypass in WS-Security","severity":"high","exploited":false,"published_at":"2026-07-08T23:16:56.173+00:00","url":"https://junglewise.ai/threats/cve-2026-54783-corewcf-signature-verification-bypass-in-ws-security"},{"cve":"CVE-2026-54775","cvss":6.5,"epss":0.006,"slug":"cve-2026-54775-corewcf-denial-of-service-via-kafka-tombstone-record","title":"CoreWCF denial of service via Kafka tombstone record","severity":"medium","exploited":false,"published_at":"2026-07-08T23:16:55.227+00:00","url":"https://junglewise.ai/threats/cve-2026-54775-corewcf-denial-of-service-via-kafka-tombstone-record"},{"cve":"CVE-2026-54777","cvss":6.5,"epss":0.0012,"slug":"cve-2026-54777-corewcf-netnamedpipe-race-condition-in-namedpipelistener","title":"CoreWCF NetNamedPipe race condition in NamedPipeListener","severity":"medium","exploited":false,"published_at":"2026-07-08T22:17:15.24+00:00","url":"https://junglewise.ai/threats/cve-2026-54777-corewcf-netnamedpipe-race-condition-in-namedpipelistener"},{"cve":"CVE-2026-54778","cvss":6.2,"epss":0.0013,"slug":"cve-2026-54778-corewcf-race-condition-in-unixdomainsocket-identity-resolution","title":"CoreWCF race condition in UnixDomainSocket identity resolution","severity":"medium","exploited":false,"published_at":"2026-07-08T23:16:55.493+00:00","url":"https://junglewise.ai/threats/cve-2026-54778-corewcf-race-condition-in-unixdomainsocket-identity-resolution"},{"cve":"CVE-2026-54779","cvss":5.9,"epss":0.0043,"slug":"cve-2026-54779-corewcf-saml-token-replay-protection-bypass-in","title":"CoreWCF SAML token replay protection bypass in DefaultTokenReplayCache","severity":"medium","exploited":false,"published_at":"2026-07-08T23:16:55.63+00:00","url":"https://junglewise.ai/threats/cve-2026-54779-corewcf-saml-token-replay-protection-bypass-in"},{"cve":"CVE-2026-54773","cvss":5.9,"epss":0.0037,"slug":"cve-2026-54773-corewcf-improper-signature-verification-in-ws-security","title":"CoreWCF improper signature verification in WS-Security","severity":"medium","exploited":false,"published_at":"2026-07-08T23:16:54.96+00:00","url":"https://junglewise.ai/threats/cve-2026-54773-corewcf-improper-signature-verification-in-ws-security"}],"generated_at":"2026-09-26T18:07:00.158435+00:00"}