CVE-2026-12340 Out-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computation
Information published.
Categories: Microsoft
CVE-2026-10512 X25519 x86_64 assembly final reduction leaves non-canonical field element
Information published.
Categories: Microsoft
CVE-2026-10592 Wildcard DNS SAN bypasses CA name-constraint checks
Information published.
Categories: Microsoft
CVE-2026-6091 Partial-chain verification accepts untrusted intermediate as trust anchor
Information published.
Categories: Microsoft
CVE-2026-6325 Out-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms list
Information published.
Categories: Microsoft
CVE-2026-55958 Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessage
Information published.
Categories: Microsoft
CVE-2026-6731 X.509 name constraint bypass via Subject CN treated as a DNS name
Information published.
Categories: Microsoft
CVE-2026-7511 PKCS7_verify signer confusion allows forged signatures to be accepted
Information published.
Categories: Microsoft
CVE-2026-6330 ML-KEM ARM64 NEON ciphertext comparison only compares half of the input
Information published.
Categories: Microsoft
CVE-2026-6331 HMAC zero-length tag forgery in EVP_DigestVerifyFinal
Information published.
Categories: Microsoft
CVE-2026-6094 Heap buffer overread in wc_PKCS7_DecodeEnvelopedData parsing crafted PKCS7 EnvelopedData
Information published.
Categories: Microsoft
CVE-2026-6678 Integer underflow in wc_PKCS7_DecryptOri handling crafted Other Recipient Info
Information published.
Categories: Microsoft
CVE-2026-55961 wolfSSL_PKCS7_verify() reports success for degenerate (certs-only) PKCS#7 with no signer
Information published.
Categories: Microsoft
CVE-2026-6329 PKCS#12 MAC verification uses attacker-controlled comparison length
Information published.
Categories: Microsoft
CVE-2026-11999 X.509 trust-chain bypass via path-depth exhaustion in wolfSSL_X509_verify_cert()
Information published.
Categories: Microsoft
CVE-2026-55962 TLS 1.3 post-handshake authentication: server accepts Finished without client Certificate/CertificateVerify
Information published.
Categories: Microsoft
CVE-2026-55967 AES-GCM streaming APIs do not reject >64 GiB cumulative single messages, enabling counter wrap and keystream reuse
Information published.
Categories: Microsoft
CVE-2026-11703 Missing SNI/ALPN binding on stateful (session-ID) TLS session resumption
Information published.
Categories: Microsoft
CVE-2026-55964 Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA (temporary CA exemption)
Information published.
Categories: Microsoft
CVE-2026-55960 Un-negotiated Raw Public Key (RFC 7250) accepted in place of X.509, bypassing chain validation
Information published.
Categories: Microsoft


