# Multiple WolfSSL Critical Vulnerabilities: Certificate Bypass, RCE, and Post-Quantum Weakening

> WolfSSL cryptographic library versions before 5.9.1/5.9.2 contain eight critical vulnerabilities including X.509 certificate validation bypasses enabling MITM attacks, heap buffer overflows in DTLS 1.3 processing enabling remote code execution, stack buffer overflows in PKCS7 handling, and ECDSA signature verification weaknesses affecting post-quantum cryptography implementations. Affects billions of IoT devices, embedded systems, and servers relying on WolfSSL for TLS/DTLS operations.

- **Published:** 2026-06-30T00:00:00Z
- **Last reviewed:** 2026-06-30T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1008
- **ID:** TL-2026-1008
- **Severity:** CRITICAL (CVSS 9.3)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 26 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-11310, CVE-2026-11999, CVE-2026-6091, CVE-2026-55960, CVE-2026-6679, CVE-2026-5264, CVE-2026-5295, CVE-2026-5194

## Description

WolfSSL announced eight critical vulnerabilities on June 25-30, 2026, affecting versions 5.9.1 and earlier. The vulnerability set spans four distinct attack categories:

1. X.509 Certificate Trust-Chain Bypass (CVE-2026-11310, CVE-2026-11999, CVE-2026-6091, CVE-2026-55960): Four separate bypasses in certificate validation logic, specifically in OpenSSL compatibility code (OPENSSL_EXTRA builds). These vulnerabilities allow attackers to present invalid certificate chains that never reach a trust anchor but are accepted as valid, enabling man-in-the-middle attacks. Affects applications using X509_verify_cert() API with caller-supplied untrusted intermediates, S/MIME/CMS validation, code/firmware signing verification, and JWT/JWS x5c validation.

2. DTLS 1.3 Heap Buffer Overflows (CVE-2026-6679, CVE-2026-5264): Two separate heap buffer overflow vulnerabilities in DTLS 1.3 ACK serialization and processing paths. The first (CVE-2026-6679) results from integer truncation in computing ACK record-number list length, causing undersized buffer allocation. The second (CVE-2026-5264) occurs during crafted DTLS ACK message processing. Both occur before peer authentication and enable remote code execution with no user interaction required.

3. PKCS7 Stack Buffer Overflow (CVE-2026-5295): Unbounded OID copying in wc_PKCS7_DecryptOri() function processing CMS EnvelopedData with OtherRecipientInfo recipients. OID values longer than the fixed 32-byte MAX_OID_SZ buffer trigger stack overflow, affecting PKCS7-enabled builds with registered ORI decrypt callbacks.

4. ECDSA Signature Verification Weakness (CVE-2026-5194): Missing hash/digest size and OID validation in ECDSA certificate signature verification when EdDSA or ML-DSA (Dilithium) post-quantum algorithms are also enabled. Allows acceptance of undersized digests unsuitable for key type, weakening authentication in post-quantum cryptography deployments. Affects asn.c and ecc.c code paths.

The vulnerability set reveals systemic issues in cryptographic validation logic, boundary checking, and integration with post-quantum algorithms. Most vulnerabilities require minimal network interaction and no user intervention, making them highly exploitable. Certificate validation bypasses directly enable MITM attacks at scale. RCE vectors via DTLS allow direct system compromise. Post-quantum weakness undermines forward-secrecy deployments.

WolfSSL is embedded in billions of IoT devices (smartwatches, fitness trackers, medical devices), automotive systems (V2X communication), industrial control systems, embedded Linux devices, firmware update mechanisms, and server applications requiring lightweight TLS. Attackers exploiting these vulnerabilities can intercept encrypted communications, forge authentication credentials, execute arbitrary code on target devices, and bypass post-quantum cryptographic protections—directly impacting availability, confidentiality, and integrity of critical infrastructure.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1195 Supply Chain Compromise
- T1059 Command and Scripting Interpreter
- T1106 Native API
- T1547 Boot or Logon Autostart Execution
- T1068 Exploitation for Privilege Escalation
- T1600 Weaken Encryption
- T1553 Subvert Trust Controls
- T1685 Disable or Modify Tools
- T1528 Steal Application Access Token
- T1557 Adversary-in-the-Middle
- T1518 Software Discovery
- T1071 Application Layer Protocol
- T1573 Encrypted Channel
- T1041 Exfiltration Over C2 Channel
- T1486 Data Encrypted for Impact
- T1499 Endpoint Denial of Service
- T1529 System Shutdown/Reboot
- T1561 Disk Wipe
- T1583 Acquire Infrastructure
- T1587 Develop Capabilities

## Sources

- [Multiple WolfSSL Vulnerabilities Expose Billions of Servers and IoT Devices](https://cybersecuritynews.com/multiple-wolfssl-vulnerabilities/)
- [NVD: CVE-2026-11310 - WolfSSL X.509 Trust-Chain Bypass](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-11310)
- [NVD: CVE-2026-11999 - WolfSSL Path-Depth Exhaustion](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-11999)
- [NVD: CVE-2026-6091 - WolfSSL Partial-Chain Bypass](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-6091)
- [NVD: CVE-2026-55960 - WolfSSL Raw Public Key Bypass](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-55960)
- [NVD: CVE-2026-6679 - WolfSSL DTLS 1.3 Heap Buffer Overflow (ACK Serialization)](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-6679)
- [NVD: CVE-2026-5264 - WolfSSL DTLS 1.3 ACK Message Heap Buffer Overflow](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-5264)
- [NVD: CVE-2026-5295 - WolfSSL PKCS7 Stack Buffer Overflow (ORI)](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-5295)
- [NVD: CVE-2026-5194 - WolfSSL ECDSA Signature Verification Weakness](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-5194)
- [WolfSSL Official Security Update Announcement](https://www.wolfssl.com/)
- [WolfSSL GitHub Repository - Security Fixes](https://github.com/wolfSSL/wolfssl/releases)
- [RFC 7250 - Using Raw Public Keys in Transport Layer Security (TLS)](https://tools.ietf.org/html/rfc7250)
- [RFC 8446 - The Transport Layer Security (TLS) 1.3 Protocol](https://tools.ietf.org/html/rfc8446)
- [DTLS 1.3 RFC 9147 - The Datagram Transport Layer Security (DTLS) Protocol Version 1.3](https://tools.ietf.org/html/rfc9147)
- [FIPS 186-5: Digital Signature Standard (DSS)](https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1008
