CVE-2026-10097 ML-KEM-1024 x64 AVX2 incomplete cipher text comparison enables IND-CCA2 break and static private-key recovery
Information published.
Categories: Microsoft
CVE-2026-10098 OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status
Information published.
Categories: Microsoft
CVE-2026-8720 HMAC-BLAKE2 final discards message when key length exceeds block size
Information published.
Categories: Microsoft
CVE-2026-12340 Out-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computation
Information published.
Categories: Microsoft
CVE-2026-10512 X25519 x86_64 assembly final reduction leaves non-canonical field element
Information published.
Categories: Microsoft
CVE-2026-10592 Wildcard DNS SAN bypasses CA name-constraint checks
Information published.
Categories: Microsoft
CVE-2026-6091 Partial-chain verification accepts untrusted intermediate as trust anchor
Information published.
Categories: Microsoft
CVE-2026-6325 Out-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms list
Information published.
Categories: Microsoft
CVE-2026-55958 Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessage
Information published.
Categories: Microsoft
CVE-2026-6731 X.509 name constraint bypass via Subject CN treated as a DNS name
Information published.
Categories: Microsoft
CVE-2026-7511 PKCS7_verify signer confusion allows forged signatures to be accepted
Information published.
Categories: Microsoft
CVE-2026-6330 ML-KEM ARM64 NEON ciphertext comparison only compares half of the input
Information published.
Categories: Microsoft
CVE-2026-6331 HMAC zero-length tag forgery in EVP_DigestVerifyFinal
Information published.
Categories: Microsoft
CVE-2026-6094 Heap buffer overread in wc_PKCS7_DecodeEnvelopedData parsing crafted PKCS7 EnvelopedData
Information published.
Categories: Microsoft
CVE-2026-6678 Integer underflow in wc_PKCS7_DecryptOri handling crafted Other Recipient Info
Information published.
Categories: Microsoft
CVE-2026-55961 wolfSSL_PKCS7_verify() reports success for degenerate (certs-only) PKCS#7 with no signer
Information published.
Categories: Microsoft
CVE-2026-6329 PKCS#12 MAC verification uses attacker-controlled comparison length
Information published.
Categories: Microsoft
CVE-2026-11999 X.509 trust-chain bypass via path-depth exhaustion in wolfSSL_X509_verify_cert()
Information published.
Categories: Microsoft
CVE-2026-55962 TLS 1.3 post-handshake authentication: server accepts Finished without client Certificate/CertificateVerify
Information published.
Categories: Microsoft
CVE-2026-55967 AES-GCM streaming APIs do not reject >64 GiB cumulative single messages, enabling counter wrap and keystream reuse
Information published.
Categories: Microsoft


