CVE-2026-105794

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

MsQuic is a cross-platform C implementation of the IETF QUIC protocol exposed to C, C++, C#, and Rust. Prior to 2.4.20, 2.5.11, and 2.6.1, MsQuic clients using the OpenSSL or QuicTLS TLS backend do not properly verify that a server certificate matches the intended target server hostname. An on-path attacker can therefore present a certificate that does not match the intended target hostname and spoof the server in a man-in-the-middle attack. The Schannel backend is not affected. This issue is fixed in versions 2.4.20, 2.5.11, and 2.6.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-10-06: 210-06
Referenced assets2 URLs
Full discourse2 posts
  • VulnTracker@vuln_tracker

    Two Microsoft flaws, two broken checks. CVE-2026-105794 (MsQuic): spoofed servers pass TLS hostname checks. CVE-2026-105793 (UFO): a valid API key runs Android shell commands. VulnTracker recommends updating MsQuic to 2.6.1 and UFO to 3.0.9. #Microsoft #MsQuic https://t.co/3uAMxzLSvd

    20042167
    803 followersView on X
  • VulnTracker@vuln_tracker

    Details: https://vulntracker.io/cves/CVE-2026-105794 https://vulntracker.io/cves/CVE-2026-105793

    0000049
    803 followersView on X

Explore more