THREAT OPS › Threat News › [NVD] CVE-2026-3416 (MEDIUM 5.9) — The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks sufficient entropy for security-sensitive operations, allowing a sophisticated attacker to predict future sec
[NVD] CVE-2026-3416 (MEDIUM 5.9) — The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks sufficient entropy for security-sensitive operations, allowing a sophisticated attacker to predict future sec
CVE-2026-3416 CVSS: 5.9 MEDIUM Published: 2026-09-03T13:05:37.847
The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks sufficient entropy for security-sensitive operations, allowing a sophisticated attacker to predict future secrets. This enables malicious actors to forge event pa
MITRE ATT&CK techniques
- Data ManipulationT1565
Indicators of compromise
- CVE-2026-3416cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-3416