Threat reportVulnerabilityTL-2026-1008

Multiple WolfSSL Critical Vulnerabilities: Certificate Bypass, RCE, and Post-Quantum Weakening

criticalACTIVE

Multiple WolfSSL Critical Vulnerabilities (TL-2026-1008), also tracked as WolfSSL Multiple Vulnerabilities June 2026, is a critical-severity software vulnerability scored CVSS 9.3, first published 2026-06-30. It has no confirmed attribution, affects WolfSSL wolfSSL (cryptographic library), references 8 CVEs (CVE-2026-11310, CVE-2026-11999, CVE-2026-6091), maps to 21 MITRE ATT&CK techniques (T1041, T1059, T1068), and is covered by 9 detection rules and 26 indicators of compromise.

CVSS
9.3/10Critical
CVEs
8Referenced vulnerabilities
Techniques
21MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
26Indicators of compromise

Key facts for TL-2026-1008

Threat ID
TL-2026-1008
Also known as
WolfSSL Multiple Vulnerabilities June 2026
Severity
CRITICAL
CVSS
9.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
consumer-devices, iot, automotive, health, industrial, telecoms, aerospace, government administration, finance
Target regions
North America, Europe, Asia-Pacific, Global
Detection rules
9
Indicators of compromise
26

Malware and tooling in Multiple WolfSSL Critical Vulnerabilities

Malware and tooling: CVE-2026-11310-CertificateBypass-Toolkit, CVE-2026-6679-Scanner, IoT-Botnet-WolfSSL-Variant, Cobalt Strike / Sliver / Brute Ratel, Metasploit-WolfSSL-RCE-Module, OpenSSL

How Multiple WolfSSL Critical Vulnerabilities works

WolfSSL cryptographic library versions before 5.9.1/5.9.2 contain eight critical vulnerabilities including X.509 certificate validation bypasses enabling MITM attacks, heap buffer overflows in DTLS 1.3 processing enabling remote code execution, stack buffer overflows in PKCS7 handling, and ECDSA signature verification weaknesses affecting post-quantum cryptography implementations. Affects billions of IoT devices, embedded systems, and servers relying on WolfSSL for TLS/DTLS operations.

WolfSSL announced eight critical vulnerabilities on June 25-30, 2026, affecting versions 5.9.1 and earlier. The vulnerability set spans four distinct attack categories:

1. X.509 Certificate Trust-Chain Bypass (CVE-2026-11310, CVE-2026-11999, CVE-2026-6091, CVE-2026-55960): Four separate bypasses in certificate validation logic, specifically in OpenSSL compatibility code (OPENSSL_EXTRA builds). These vulnerabilities allow attackers to present invalid certificate chains that never reach a trust anchor but are accepted as valid, enabling man-in-the-middle attacks. Affects applications using X509_verify_cert() API with caller-supplied untrusted intermediates, S/MIME/CMS validation, code/firmware signing verification, and JWT/JWS x5c validation.

2. DTLS 1.3 Heap Buffer Overflows (CVE-2026-6679, CVE-2026-5264): Two separate heap buffer overflow vulnerabilities in DTLS 1.3 ACK serialization and processing paths. The first (CVE-2026-6679) results from integer truncation in computing ACK record-number list length, causing undersized buffer allocation. The second (CVE-2026-5264) occurs during crafted DTLS ACK message processing. Both occur before peer authentication and enable remote code execution with no user interaction required.

3. PKCS7 Stack Buffer Overflow (CVE-2026-5295): Unbounded OID copying in wc_PKCS7_DecryptOri() function processing CMS EnvelopedData with OtherRecipientInfo recipients. OID values longer than the fixed 32-byte MAX_OID_SZ buffer trigger stack overflow, affecting PKCS7-enabled builds with registered ORI decrypt callbacks.

4. ECDSA Signature Verification Weakness (CVE-2026-5194): Missing hash/digest size and OID validation in ECDSA certificate signature verification when EdDSA or ML-DSA (Dilithium) post-quantum algorithms are also enabled. Allows acceptance of undersized digests unsuitable for key type, weakening authentication in post-quantum cryptography deployments. Affects asn.c and ecc.c code paths.

The vulnerability set reveals systemic issues in cryptographic validation logic, boundary checking, and integration with post-quantum algorithms. Most vulnerabilities require minimal network interaction and no user intervention, making them highly exploitable. Certificate validation bypasses directly enable MITM attacks at scale. RCE vectors via DTLS allow direct system compromise. Post-quantum weakness undermines forward-secrecy deployments.

WolfSSL is embedded in billions of IoT devices (smartwatches, fitness trackers, medical devices), automotive systems (V2X communication), industrial control systems, embedded Linux devices, firmware update mechanisms, and server applications requiring lightweight TLS. Attackers exploiting these vulnerabilities can intercept encrypted communications, forge authentication credentials, execute arbitrary code on target devices, and bypass post-quantum cryptographic protections—directly impacting availability, confidentiality, and integrity of critical infrastructure.

MITRE ATT&CK techniques used in TL-2026-1008

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059 Command and Scripting Interpreter; T1106 Native API

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071 Application Layer Protocol; T1573 Encrypted Channel

Initial Access

T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise

Impact

T1486 Data Encrypted for Impact; T1499 Endpoint Denial of Service; T1529 System Shutdown/Reboot; T1561 Disk Wipe

Discovery

T1518 Software Discovery

Credential Access

T1528 Steal Application Access Token; T1557 Adversary-in-the-Middle

Persistence

T1547 Boot or Logon Autostart Execution

defense-impairment

T1553 Subvert Trust Controls; T1600 Weaken Encryption; T1685 Disable or Modify Tools

Resource Development

T1583 Acquire Infrastructure; T1587 Develop Capabilities

Affected products and versions in Multiple WolfSSL Critical Vulnerabilities

  • WolfSSL — wolfSSL (cryptographic library)
    Vulnerable versions: 5.9.1 and earlier (CVE-2026-11310, CVE-2026-11999, CVE-2026-6091, CVE-2026-55960, CVE-2026-5295, CVE-2026-5194); 5.9.0 and earlier (CVE-2026-6679); All versions < 5.9.1 (CVE-2026-5264)
    Fixed in: 5.9.1 (fixes most CVEs); 5.9.2 (fixes all CVEs including CVE-2026-6679); 5.10.0+ (if released with additional fixes)
  • Apple — iOS, macOS, watchOS (embedded WolfSSL for certain security operations)
    Vulnerable versions: Dependent on WolfSSL version bundled in OS releases
  • Fitbit / Google — Fitbit smartwatch firmware
    Vulnerable versions: Firmware versions using WolfSSL < 5.9.1
  • Various — IoT devices (Amazon Alexa, Google Home, Samsung SmartThings, Philips Hue, TP-Link, D-Link)
    Vulnerable versions: Firmware versions using WolfSSL < 5.9.1
  • Nordic Semiconductor — nRF Connect SDK (embedded Bluetooth/Thread devices)
    Vulnerable versions: SDK versions bundling WolfSSL < 5.9.1
  • Wind River — VxWorks, Linux Kernel (wolfSSL optional TLS provider)
    Vulnerable versions: Builds with WolfSSL < 5.9.1

Remediation for Multiple WolfSSL Critical Vulnerabilities

Patches

  • WolfSSL 5.9.1: Fixes CVE-2026-11310, CVE-2026-11999, CVE-2026-6091, CVE-2026-55960, CVE-2026-5294, CVE-2026-5295, CVE-2026-5194
  • WolfSSL 5.9.2: Fixes CVE-2026-6679 (DTLS 1.3 ACK buffer overflow)
  • Vendor firmware updates: Device manufacturers must rebuild and release patched firmware for embedded systems

Immediate actions

  • Identify all instances of WolfSSL in use (embedded systems, firmware, containerized applications, IoT devices)
  • Disable DTLS 1.3 if not required (reduces RCE surface: CVE-2026-6679, CVE-2026-5264)
  • Disable OPENSSL_EXTRA build flag if native wolfSSL APIs are sufficient (eliminates X.509 bypass surface: CVE-2026-11310, CVE-2026-11999, CVE-2026-6091)
  • Disable PKCS7 support unless cryptographic message handling is critical (mitigates CVE-2026-5295)
  • If post-quantum algorithms (ML-DSA/Dilithium) are not deployed, disable EdDSA/ML-DSA (mitigates CVE-2026-5194)
  • Block untrusted network traffic to/from vulnerable wolfSSL applications at perimeter
  • Monitor TLS handshake failures and anomalies indicating exploitation attempts
  • Implement certificate pinning in client applications to prevent MITM acceptance

Workarounds

  • If upgrade is not immediately feasible: Disable OPENSSL_EXTRA at compile time (eliminates 4 X.509 bypasses)
  • Disable DTLS 1.3 if TLS 1.3 is sufficient (eliminates 2 RCE vulnerabilities)
  • Restrict network access to wolfSSL services via firewall rules (allow TLS only from known peers)
  • Implement application-layer certificate validation separate from library validation as defense-in-depth
  • Use external TLS termination proxy (e.g., nginx, HAProxy) in front of vulnerable applications to validate certificates

Longer-term hardening

  • Upgrade all WolfSSL instances to version 5.9.1 (certificate/PKCS7/ECDSA) or 5.9.2 (DTLS RCE) or later
  • For firmware-embedded instances, contact device manufacturers for security updates
  • Conduct cryptographic audit of all TLS/DTLS endpoints after patching
  • Deploy behavioral EDR on all systems running vulnerable wolfSSL to detect exploitation (memory corruption, unexpected code execution)
  • Implement mutual TLS with certificate validation at both endpoints to detect MITM
  • Establish automated inventory of WolfSSL versions across infrastructure (both user-facing and internal services)

CVEs associated with Multiple WolfSSL Critical Vulnerabilities

CVE-2026-11310, CVE-2026-11999, CVE-2026-6091, CVE-2026-55960, CVE-2026-6679, CVE-2026-5264, CVE-2026-5295, CVE-2026-5194

Weaknesses (CWE) in Multiple WolfSSL Critical Vulnerabilities

CWE-295, CWE-190, CWE-197, CWE-787, CWE-122, CWE-121

Timeline of Multiple WolfSSL Critical Vulnerabilities

  • CVE-2026-5194 (ECDSA signature verification weakness with undersized digests) published, impacts post-quantum ML-DSA deployments
  • CVE-2026-5295 (PKCS7 stack buffer overflow in OtherRecipientInfo) published to NVD, affecting builds with --enable-pkcs7
  • CVE-2026-5264 (DTLS 1.3 heap buffer overflow in ACK processing) published to NVD by WolfSSL
  • CISA evaluates CVE-2026-5194 for known exploitation; marks as HIGH priority with CVSS 9.1 (CRITICAL)
  • Earlier CVEs (CVE-2026-5264, CVE-2026-5295, CVE-2026-5194) re-assessed and updated in NVD with refined descriptions and metrics
  • WolfSSL releases version 5.9.1 fixing CVE-2026-11310, CVE-2026-11999, CVE-2026-6091, CVE-2026-55960, CVE-2026-5295, CVE-2026-5194; does NOT fix CVE-2026-6679
  • CVE-2026-6679 (DTLS 1.3 ACK serialization integer truncation) disclosed with CVSS 7.5; second RCE vector via buffer overflow
  • CVE-2026-55960 (Raw Public Key un-negotiated acceptance) published; RFC 7250/8446 compliance violation when RPK builds are enabled
  • CVE-2026-6091 (partial-chain certificate verification bypass) disclosed; allows untrusted intermediate to serve as trust anchor when X509_V_FLAG_PARTIAL_CHAIN is enabled
  • CVE-2026-11999 (X.509 path-depth exhaustion bypass) published by WolfSSL; affects certificate validation in OpenSSL compatibility layer
  • WolfSSL publicly discloses CVE-2026-11310 (X.509 trust-chain bypass due to untrusted intermediate anchoring) via NVD
  • WolfSSL releases version 5.9.2 fixing all eight vulnerabilities including CVE-2026-6679 (DTLS 1.3 ACK overflow)
  • Security researchers identify CVE-2026-6679 affecting 5.9.0 and prior; requires WolfSSL 5.9.2 for complete fix
  • Security community begins cascading analysis of impact: IoT device supply-chain implications identified
  • TL-Intel-Harness threat assessment: WolfSSL vulnerabilities classified as CRITICAL with ACTIVE exploitability status; no public PoC identified but technical feasibility is HIGH
  • Cybersecurity News publishes comprehensive article detailing exposure to billions of IoT and server devices; highlights lack of firmware update mechanisms in some embedded deployments

Sources cited for Multiple WolfSSL Critical Vulnerabilities

Detection coverage for TL-2026-1008

As of 2026-06-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1008 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
26 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats