Threat reportVulnerabilityTL-2026-1151
wolfSSL Improper Input Validation and Integer Underflow Vulnerabilities (CVE-2026-28739, CVE-2026-25106, CVE-2026-33091)
wolfSSL Improper Input Validation and Integer Underflow (TL-2026-1151), also tracked as TALOS-2026-2408, is a unknown-severity software vulnerability, first published 2026-07-09. It has no confirmed attribution, affects wolfSSL Inc. wolfSSL embedded TLS/SSL and cryptography library, references 3 CVEs (CVE-2026-28739, CVE-2026-25106, CVE-2026-33091), maps to 16 MITRE ATT&CK techniques (T1036, T1040, T1068), and is covered by 9 detection rules and 15 indicators of compromise.
- Severity
- UNKNOWNAssessed severity
- CVEs
- 3Referenced vulnerabilities
- Techniques
- 16MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-1151
- Threat ID
- TL-2026-1151
- Also known as
- TALOS-2026-2408, TALOS-2026-2409, TALOS-2026-2410
- Severity
- UNKNOWN
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, manufacturing, critical-infrastructure, health, automotive, telecoms
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in wolfSSL Improper Input Validation and Integer Underflow
Malware and tooling: wolfSSL embedded TLS/SSL library
How wolfSSL Improper Input Validation and Integer Underflow works
Cisco Talos (researcher Ankur Tyagi) disclosed three vendor-patched vulnerabilities in the wolfSSL embedded TLS/SSL library: two improper-input-validation flaws (CVE-2026-28739 / TALOS-2026-2409, CVE-2026-25106 / TALOS-2026-2410) and one integer-underflow flaw (CVE-2026-33091 / TALOS-2026-2408). All three were fixed by the vendor prior to public disclosure on 2026-07-01/02 and rolled up in a Talos blog post on 2026-07-09.
wolfSSL is a small-footprint, portable TLS/SSL and cryptography library used across embedded systems, IoT devices, industrial and automotive controllers, medical devices, and cloud services where a lightweight secure-transport stack is required. Cisco Talos's third-party vulnerability disclosure program, through researcher Ankur Tyagi, identified and privately reported three distinct defects in the library to the vendor. Two of the three (TALOS-2026-2409 / CVE-2026-28739 and TALOS-2026-2410 / CVE-2026-25106) are classified by Talos as improper input validation issues; the source article groups both under this shared classification without further public breakdown of the specific parsing paths affected. The third (TALOS-2026-2408 / CVE-2026-33091) is classified as an integer underflow issue, a defect class in which an arithmetic subtraction on an attacker-influenced length or index value wraps below zero, typically producing an unexpectedly large unsigned value that is then used in a subsequent memory-copy or bounds calculation -- a pattern that commonly leads to heap corruption, out-of-bounds read/write, denial of service, or in the worst case remote code execution, depending on how the resulting value is consumed downstream. wolfSSL has released patches addressing all three defects; the Talos source article does not publish the affected version range, a CVSS score/vector, or any evidence of in-the-wild exploitation, so those fields are recorded as UNKNOWN/null per source-grounding requirements rather than estimated. Independent research confirms wolfSSL shipped v5.9.1 on 2026-04-08 and v5.9.2 on 2026-06-23, consistent with the Talos disclosure timeline (private vendor notification 2026-04-29, patch released 2026-06-23, public advisory 2026-07-01/02), indicating v5.9.2 is the remediated release line. Given the vulnerability classes involved -- input validation defects in a TLS library are frequently rooted in certificate/handshake parsing, and integer underflow defects in crypto/ASN.1 libraries are a recurring heap-corruption root cause (per CWE-191 advisory guidance) -- the practical risk profile for unpatched deployments is assessed as HIGH, spanning potential denial of service, memory corruption, and (for the input-validation class) possible security-control bypass in certificate/data validation logic, pending any vendor clarification of exact impact.
MITRE ATT&CK techniques used in TL-2026-1151
Defense Evasion
T1036 Masquerading; T1211 Exploitation for Stealth
Credential Access
T1040 Network Sniffing; T1557 Adversary-in-the-Middle
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Initial Access
T1190 Exploit Public-Facing Application
Execution
T1203 Exploitation for Client Execution
Lateral Movement
T1210 Exploitation of Remote Services
Impact
T1499 Endpoint Denial of Service
Discovery
Command and Control
Resource Development
T1587.004 Exploits; T1588.005 Exploits; T1588.006 Vulnerabilities
Reconnaissance
Affected products and versions in wolfSSL Improper Input Validation and Integer Underflow
- wolfSSL Inc. — wolfSSL embedded TLS/SSL and cryptography library
Vulnerable versions: Not published by source; wolfSSL v5.9.1 (2026-04-08) and earlier releases are consistent with the pre-patch disclosure timeline
Fixed in: wolfSSL v5.9.2 (released 2026-06-23), per the vendor patch date confirmed in the Talos disclosure timeline
Remediation for wolfSSL Improper Input Validation and Integer Underflow
Patches
- Upgrade to wolfSSL v5.9.2 (released 2026-06-23) or later, which the disclosure timeline indicates contains the fixes for all three reported issues
Immediate actions
- Inventory all products and firmware images embedding wolfSSL and identify the linked library version
- Prioritize internet-facing and certificate-validating deployments (VPN endpoints, IoT device provisioning, TLS-terminating gateways) for patch review
- Where patching is not immediately possible, restrict exposure of services that parse untrusted TLS handshakes, X.509 certificates, or PKCS#7/CMS structures through wolfSSL
Workarounds
- No vendor-published workaround is documented in the source article; version upgrade is the only confirmed remediation
Longer-term hardening
- Adopt a component/SBOM tracking process for embedded cryptographic libraries to shorten future patch-identification time
- Enable fuzzing/static-analysis coverage of ASN.1, certificate, and length-arithmetic parsing paths in any custom code layered on wolfSSL
- Subscribe to Cisco Talos and wolfSSL vendor security advisories for early warning of future disclosures
CVEs associated with wolfSSL Improper Input Validation and Integer Underflow
CVE-2026-28739, CVE-2026-25106, CVE-2026-33091
Weaknesses (CWE) in wolfSSL Improper Input Validation and Integer Underflow
Timeline of wolfSSL Improper Input Validation and Integer Underflow
- wolfSSL v5.9.1 released; per the confirmed disclosure timeline this and earlier releases predate the fix for the three reported issues.
- Cisco Talos (researcher Ankur Tyagi) privately disclosed the three wolfSSL vulnerabilities (TALOS-2026-2408/2409/2410) to the wolfSSL vendor under Cisco's third-party disclosure policy.
- wolfSSL released version 5.9.2, the release consistent with the vendor-patch date recorded in the Talos disclosure timeline for these issues.
- Cisco Talos publicly disclosed TALOS-2026-2408 (CVE-2026-33091, integer underflow) and TALOS-2026-2409 (CVE-2026-28739, improper input validation).
- Cisco Talos publicly disclosed TALOS-2026-2410 (CVE-2026-25106, improper input validation).
- The same Cisco Talos roundup post that disclosed the three wolfSSL CVEs also published 14 GeoVision advisories covering 37 CVEs (researcher Philippe Laulheret) and one VTK-DICOM heap-based buffer overflow, CVE-2026-22879 / TALOS-2026-2366 (researcher Emmanuel Tacheau) -- unrelated products bundled in the same disclosure cycle, authored by Kri Dontje.
- NVD API query for CVE-2026-28739, CVE-2026-25106, and CVE-2026-33091 returned zero published records (totalResults: 0) at RESEARCH time, confirming no independent CVSS/CWE scoring is yet available and grounding the source's UNKNOWN severity and null CVSS fields.
- TL-Intel-Harness HUNT phase ingested the Talos blog post via the Cisco Talos Intelligence Blog RSS feed and created threat skeleton TL-2026-1151.
- Cisco Talos Intelligence Blog published a consolidated vulnerability-disclosure roundup covering the three wolfSSL CVEs alongside separate GeoVision and VTK-DICOM advisories, noting Snort coverage is available via Snort.org rule sets.
Sources cited for wolfSSL Improper Input Validation and Integer Underflow
- Vulnerability Spotlight: wolfSSL vulnerabilities disclosed
- Cisco Talos Vulnerability Reports index
- Cisco Talos Zero-Day and Disclosed Vulnerability Reports
- wolfSSL Security Vulnerabilities documentation
- wolfSSL Release 5.9.2 (June 23, 2026)
- wolfSSL Release 5.9.1 (April 8, 2026)
- Critical wolfSSL Security Vulnerabilities Expose IoT Systems
Detection coverage for TL-2026-1151
As of 2026-07-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1151 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.