# CVE-2026-16458

## Summary

- **CVE ID:** CVE-2026-16458
- **Severity:** MEDIUM
- **CVSS Score:** 5.9 (CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-208, CWE-327
- **Published:** Aug 13, 2026
- **Last Modified:** Aug 13, 2026

## Description

Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.

## Affected Products

- Oberon microsystems AG — ocrypto (3.0.0)

## References

- [CNA](https://www.oberon.ch/security-advisories/cve-2026-16458/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.07%
- **EPSS Percentile:** 0.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._