Threat reportVulnerabilityTL-2026-1151

wolfSSL Improper Input Validation and Integer Underflow Vulnerabilities (CVE-2026-28739, CVE-2026-25106, CVE-2026-33091)

ACTIVE

wolfSSL Improper Input Validation and Integer Underflow (TL-2026-1151), also tracked as TALOS-2026-2408, is a unknown-severity software vulnerability, first published 2026-07-09. It has no confirmed attribution, affects wolfSSL Inc. wolfSSL embedded TLS/SSL and cryptography library, references 3 CVEs (CVE-2026-28739, CVE-2026-25106, CVE-2026-33091), maps to 16 MITRE ATT&CK techniques (T1036, T1040, T1068), and is covered by 9 detection rules and 15 indicators of compromise.

Severity
UNKNOWNAssessed severity
CVEs
3Referenced vulnerabilities
Techniques
16MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
15Indicators of compromise

Key facts for TL-2026-1151

Threat ID
TL-2026-1151
Also known as
TALOS-2026-2408, TALOS-2026-2409, TALOS-2026-2410
Severity
UNKNOWN
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, manufacturing, critical-infrastructure, health, automotive, telecoms
Target regions
Global
Detection rules
9
Indicators of compromise
15

Malware and tooling in wolfSSL Improper Input Validation and Integer Underflow

Malware and tooling: wolfSSL embedded TLS/SSL library

How wolfSSL Improper Input Validation and Integer Underflow works

Cisco Talos (researcher Ankur Tyagi) disclosed three vendor-patched vulnerabilities in the wolfSSL embedded TLS/SSL library: two improper-input-validation flaws (CVE-2026-28739 / TALOS-2026-2409, CVE-2026-25106 / TALOS-2026-2410) and one integer-underflow flaw (CVE-2026-33091 / TALOS-2026-2408). All three were fixed by the vendor prior to public disclosure on 2026-07-01/02 and rolled up in a Talos blog post on 2026-07-09.

wolfSSL is a small-footprint, portable TLS/SSL and cryptography library used across embedded systems, IoT devices, industrial and automotive controllers, medical devices, and cloud services where a lightweight secure-transport stack is required. Cisco Talos's third-party vulnerability disclosure program, through researcher Ankur Tyagi, identified and privately reported three distinct defects in the library to the vendor. Two of the three (TALOS-2026-2409 / CVE-2026-28739 and TALOS-2026-2410 / CVE-2026-25106) are classified by Talos as improper input validation issues; the source article groups both under this shared classification without further public breakdown of the specific parsing paths affected. The third (TALOS-2026-2408 / CVE-2026-33091) is classified as an integer underflow issue, a defect class in which an arithmetic subtraction on an attacker-influenced length or index value wraps below zero, typically producing an unexpectedly large unsigned value that is then used in a subsequent memory-copy or bounds calculation -- a pattern that commonly leads to heap corruption, out-of-bounds read/write, denial of service, or in the worst case remote code execution, depending on how the resulting value is consumed downstream. wolfSSL has released patches addressing all three defects; the Talos source article does not publish the affected version range, a CVSS score/vector, or any evidence of in-the-wild exploitation, so those fields are recorded as UNKNOWN/null per source-grounding requirements rather than estimated. Independent research confirms wolfSSL shipped v5.9.1 on 2026-04-08 and v5.9.2 on 2026-06-23, consistent with the Talos disclosure timeline (private vendor notification 2026-04-29, patch released 2026-06-23, public advisory 2026-07-01/02), indicating v5.9.2 is the remediated release line. Given the vulnerability classes involved -- input validation defects in a TLS library are frequently rooted in certificate/handshake parsing, and integer underflow defects in crypto/ASN.1 libraries are a recurring heap-corruption root cause (per CWE-191 advisory guidance) -- the practical risk profile for unpatched deployments is assessed as HIGH, spanning potential denial of service, memory corruption, and (for the input-validation class) possible security-control bypass in certificate/data validation logic, pending any vendor clarification of exact impact.

MITRE ATT&CK techniques used in TL-2026-1151

Defense Evasion

T1036 Masquerading; T1211 Exploitation for Stealth

Credential Access

T1040 Network Sniffing; T1557 Adversary-in-the-Middle

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Initial Access

T1190 Exploit Public-Facing Application

Execution

T1203 Exploitation for Client Execution

Lateral Movement

T1210 Exploitation of Remote Services

Impact

T1499 Endpoint Denial of Service

Discovery

T1518 Software Discovery

Command and Control

T1573 Encrypted Channel

Resource Development

T1587.004 Exploits; T1588.005 Exploits; T1588.006 Vulnerabilities

Reconnaissance

T1592.002 Software; T1595.002 Vulnerability Scanning

Affected products and versions in wolfSSL Improper Input Validation and Integer Underflow

  • wolfSSL Inc. — wolfSSL embedded TLS/SSL and cryptography library
    Vulnerable versions: Not published by source; wolfSSL v5.9.1 (2026-04-08) and earlier releases are consistent with the pre-patch disclosure timeline
    Fixed in: wolfSSL v5.9.2 (released 2026-06-23), per the vendor patch date confirmed in the Talos disclosure timeline

Remediation for wolfSSL Improper Input Validation and Integer Underflow

Patches

  • Upgrade to wolfSSL v5.9.2 (released 2026-06-23) or later, which the disclosure timeline indicates contains the fixes for all three reported issues

Immediate actions

  • Inventory all products and firmware images embedding wolfSSL and identify the linked library version
  • Prioritize internet-facing and certificate-validating deployments (VPN endpoints, IoT device provisioning, TLS-terminating gateways) for patch review
  • Where patching is not immediately possible, restrict exposure of services that parse untrusted TLS handshakes, X.509 certificates, or PKCS#7/CMS structures through wolfSSL

Workarounds

  • No vendor-published workaround is documented in the source article; version upgrade is the only confirmed remediation

Longer-term hardening

  • Adopt a component/SBOM tracking process for embedded cryptographic libraries to shorten future patch-identification time
  • Enable fuzzing/static-analysis coverage of ASN.1, certificate, and length-arithmetic parsing paths in any custom code layered on wolfSSL
  • Subscribe to Cisco Talos and wolfSSL vendor security advisories for early warning of future disclosures

CVEs associated with wolfSSL Improper Input Validation and Integer Underflow

CVE-2026-28739, CVE-2026-25106, CVE-2026-33091

Weaknesses (CWE) in wolfSSL Improper Input Validation and Integer Underflow

CWE-20, CWE-191

Timeline of wolfSSL Improper Input Validation and Integer Underflow

  • wolfSSL v5.9.1 released; per the confirmed disclosure timeline this and earlier releases predate the fix for the three reported issues.
  • Cisco Talos (researcher Ankur Tyagi) privately disclosed the three wolfSSL vulnerabilities (TALOS-2026-2408/2409/2410) to the wolfSSL vendor under Cisco's third-party disclosure policy.
  • wolfSSL released version 5.9.2, the release consistent with the vendor-patch date recorded in the Talos disclosure timeline for these issues.
  • Cisco Talos publicly disclosed TALOS-2026-2408 (CVE-2026-33091, integer underflow) and TALOS-2026-2409 (CVE-2026-28739, improper input validation).
  • Cisco Talos publicly disclosed TALOS-2026-2410 (CVE-2026-25106, improper input validation).
  • The same Cisco Talos roundup post that disclosed the three wolfSSL CVEs also published 14 GeoVision advisories covering 37 CVEs (researcher Philippe Laulheret) and one VTK-DICOM heap-based buffer overflow, CVE-2026-22879 / TALOS-2026-2366 (researcher Emmanuel Tacheau) -- unrelated products bundled in the same disclosure cycle, authored by Kri Dontje.
  • NVD API query for CVE-2026-28739, CVE-2026-25106, and CVE-2026-33091 returned zero published records (totalResults: 0) at RESEARCH time, confirming no independent CVSS/CWE scoring is yet available and grounding the source's UNKNOWN severity and null CVSS fields.
  • TL-Intel-Harness HUNT phase ingested the Talos blog post via the Cisco Talos Intelligence Blog RSS feed and created threat skeleton TL-2026-1151.
  • Cisco Talos Intelligence Blog published a consolidated vulnerability-disclosure roundup covering the three wolfSSL CVEs alongside separate GeoVision and VTK-DICOM advisories, noting Snort coverage is available via Snort.org rule sets.

Sources cited for wolfSSL Improper Input Validation and Integer Underflow

Detection coverage for TL-2026-1151

As of 2026-07-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1151 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
15 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats