logo

wolfSSL Vulnerability Hits IoT, Routers and Military Systems, Update to 5.9.1 Now

ID: 8c950ade-59d6-5636-998f-b79554f42a5c

STIX ID: report--8c950ade-59d6-5636-998f-b79554f42a5c

Feed Name: HackRead

Threat Score
90/100

Date Published: 2026-04-14

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

A critical vulnerability (CVE-2026-5194) in the wolfSSL cryptographic library permits signature verification to accept improperly sized digests and missing OID checks, enabling forged certificates across algorithms like ECDSA, DSA, ML-DSA, Ed25519, and Ed448. The flaw affects many embedded and IoT devices (reported impact up to ~5 billion devices); wolfSSL released a patch in version 5.9.1 (8 Apr 2026), but unmaintained or unmanaged devices remain a significant supply-chain risk—organisations should apply firmware updates where available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.