Skip to content
VulniPulse
Highest advisory severityCritical 1 vendor · 1 advisory

CVE-2026-40965

CVE-2026-40965: 1 tracked advisory record across VMware. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

VMware

1 advisory
  • Advisory severityCritical10.0

    Critical [CVE-2026-40965] Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure.

    CVE-2026-40965Source published Source updated

    Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC (Elliptic Curve) private keys are inadvertently exposed through the public /token_keys endpoint. This endpoint is designed to provide public key material for JWT token verification but incorrectly exposes private key components for EC keys. The vulnerability affects deployments using EC keys for JWT token signing. The vulnerability does not affect RSA key configurations, only deployments using EC keys for JWT signing. Affected versions: - uaa_release: v76.12.0 through v78.12.0 (inclusive); fixed in v78.13.0 or later - CF Deployment: v30.0.0 through v56.0.0 (inclusive); fixed in v56.1.0 or later (bundles uaa_release v78.13.0)

    Related products — impact not confirmed
    No product details extracted. Check the source bulletin.
    Source-reported affected versions
    • 12.0
    Source-reported fixed versions
    • 13.0
    Mitigation guidance
    No mitigation guidance extracted; consult the source.

Android app · Google Play

Monitor future VMware CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery