
OCaml patches Marshal deserialization buffer over-read enabling RCE
CVE-2026-28364 was published for OCaml Marshal deserialization, where missing bounds validation can enable a multi-phase attack chain leading to remote code execution.
VulnerabilitiesLanguagesSecure Coding
1 min27 Feb 2026
