logo

Let’s Encrypt Halts Certificate Issuance After Cross-Signed Root Certificate Incident

ID: 37cf440c-4f3b-545b-b7bd-848b0d0de9ef

STIX ID: report--37cf440c-4f3b-545b-b7bd-848b0d0de9ef

Feed Name: cybersecurityNews.com

Threat Score
45/100

Date Published: 2026-05-09

Date Updated: 2026-05-11

Author: Guru Baran

...
...

Let’s Encrypt temporarily halted certificate issuance on May 8, 2026 after detecting a critical cross-signed certificate linking its Generation X root to an upcoming Generation Y root; issuance across production and staging was stopped as a precaution, resumed after ~2.5 hours, and all new certificates were rolled back to the Generation X root, affecting the tlsserver and shortlived ACME profiles—administrators are advised to verify renewal chains for certificates issued around this window.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.