Threats·Cloud & SaaSBreaking389 Directory Server STARTTLS Buffer Injection Flaw Enables On-Path Authentication Bypass (CVE-2026-86345)A flaw in 389 Directory Server fails to discard buffered plaintext bytes during StartTLS negotiation, enabling on-path attackers to forge successful LDAP authentications.Aisha Noor2 Oct 20268 min read