Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.3 CVE-2026-55958

Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessage_CVE-2026-55958

Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer. In tsip_StoreMessage() the capacity check guarding the fixed message bag (MSGBAG...

wolfSSL wolfSSL 5.4.0 CVE
MEDIUM 4.2 CVE-2026-2299

Improper Access Control in Mattermost Google Drive Plugin File Creation Endpoint_CVE-2026-2299

The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated ...

Mattermost Mattermost Google Drive Plugin CVE
MEDIUM 6.3 CVE-2026-12340

Out-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computation_CVE-2026-12340

Out-of-bounds heap read during SM2/SM3 certificate signature verification. When parsing a certificate with an SM3wSM2 signature, the Subject Key Id...

wolfSSL wolfSSL 5.6.4 CVE
HIGH 8.7 CVE-2026-11310

X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoring_CVE-2026-11310

X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with --enable-ope...

wolfSSL wolfSSL 5.8.4 CVE
MEDIUM 6.3 CVE-2026-10592

Wildcard DNS SAN bypasses CA name-constraint checks_CVE-2026-10592

Certificates with wildcard DNS SANs (e.g. *.example.com) bypassed CA name-constraint checks. A certificate with a wildcard DNS SAN that should be r...

wolfSSL wolfSSL 3.9.10 CVE
LOW 2.3 CVE-2026-7531

Use-after-free in PQC hybrid key-share handling_CVE-2026-7531

Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1): a malicious TLS 1.3 serv...

wolfSSL wolfSSL 5.8.0 CVE
LOW 2.3 CVE-2026-10512

X25519 x86_64 assembly final reduction leaves non-canonical field element_CVE-2026-10512

The X25519 x86_64 assembly implementation fails to clear the most significant bit during the final modular reduction, so the computed result may no...

wolfSSL wolfSSL 5.6.4 CVE
MEDIUM 6.3 CVE-2026-10097

ML-KEM-1024 x64 AVX2 implicit rejection failure breaks IND-CCA2 security_CVE-2026-10097

ML-KEM-1024 x64 AVX2 implicit rejection failure in the Fujisaki-Okamoto transform breaks IND-CCA2 security, allowing decapsulation to deviate from ...

wolfSSL wolfSSL 5.7.0 CVE
MEDIUM 6.3 1455C226-77CD-

Exploit for Improper Authentication in Google Android_1455C226-77CD-5803-A0CE-7D7BC815D6F6

BlueDucky Ver 2.1 Android 🦆 Thanks to all the people at HackNexus. Make sure you come join us on VC ! https://discord.gg/HackNexus NOTES: I will n...

N/A N/A GITHUBEXPLOIT
CRITICAL 10 PACKETSTORM:224334

📄 Dalfox Found-Action Deserialization Remote Code Execution_PACKETSTORM:224334

When dalfox versions less than or equal to 2.12.0 is started in REST API server mode dalfox server, the server binds to 0.0.0.0:6664 by default and...

N/A N/A PACKETSTORM