Skip to main content
Echelon
Graph
Product
Enterprise
Compliance
Pulse
Exposures
AI Analyst
Compare
Docs
Login
Start Free
Pulse
›
Vendor Advisories
›
Microsoft Security Response Center (MSRC)
›
CVE-2026-48526
CVE-2026-48526
High
CVSS
7.4
PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed
Vendor
Microsoft Security Response Center (MSRC)
Published
July 27, 2026
Last Modified
—
🔗 CVE IDs covered (1)
CVE-2026-48526 →