CVE-2026-13608 is a high-severity (CVSS 3.1 base 7.4) authentication-bypass flaw in libcurl’s SASL negotiation for LDAP authentication. As with CVE-2026-19931 and CVE-2026-18924, this appears in Microsoft’s own security-update data because Windows bundles libcurl — the actually affected project is curl, not Microsoft-authored code.
What the vulnerability does
Per curl’s own advisory, a flaw in libcurl’s SASL handshake logic for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker positioned as a man-in-the-middle can inject a premature or shortcut response that bypasses full peer validation — effectively tricking the client into believing authentication succeeded when the cryptographic exchange was never actually completed.
The CVSS vector (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N) shows a network-reachable flaw with high attack complexity (an MITM position is required) needing no privileges or user interaction, with high confidentiality and integrity impact but no availability impact — consistent with an authentication bypass rather than a crash or resource-exhaustion bug.
What we don’t yet have
No public proof-of-concept or evidence of active exploitation is documented as of this writing, and CVE-2026-13608 is not listed in CISA’s KEV catalog. Confidence is medium — description and CVSS trace to NVD/curl’s advisory, but affected/fixed version ranges aren’t yet present in our ingested data.
Why this matters
The high attack complexity (a network position capable of intercepting and manipulating the connection) narrows real-world exploitability compared to a remote, unauthenticated bug, but any application using libcurl for LDAP authentication over an untrusted network path — corporate VPNs with compromised nodes, shared or hostile network segments — should still prioritize confirming their libcurl version once curl publishes the specific fixed release.
Frequently Asked Questions
What is CVE-2026-13608? A CVSS 7.4 high-severity vulnerability in libcurl allowing a man-in-the-middle attacker to bypass SASL/LDAP authentication via an incomplete handshake.
Is this a Microsoft vulnerability? No — it’s a libcurl (curl project) vulnerability that appears in Microsoft’s data because Windows bundles libcurl.
Is CVE-2026-13608 being actively exploited? Not as of this writing — it is not listed in CISA’s Known Exploited Vulnerabilities catalog.
Data sourced from the National Vulnerability Database (NVD) and curl’s own advisory (curl.se), aggregated September 2026. See more vulnerability intelligence.