CVE-2026-5194Disclosure(wolfssl / wolfssl)

HIGHCVSS 9.1 · CRITICAL

Exploitation observed; activity peaked at 12 mentions and remains active

Immediate actions

  • Patch wolfssl wolfssl systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Missing hash/digest size and OID checks allow digests smaller than allowed when verifying ECDSA certificates, or smaller than is appropriate for the relevant key type, to be accepted by signature verification functions. This could lead to reduced security of ECDSA certificate-based authentication if the public CA key used is also known. This affects ECDSA/ECC verification when EdDSA or ML-DSA is also enabled.

6.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wolfssl

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 45 mentions across 17 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 21 signals
  • Technical details provided in 32 signals
  • Disclosure: 19 classified signals
  • General: 6 classified signals
  • Peaked 12d ago at 12 mentions (2026-04-14); latest day: 1
  • 45 total mentions across 17 days

Affected systems

Vendors
Products
wolfssl

Deep dive

Activity timeline45 mentions / 17d
036912Mentions · 2026-04-09: 2Mentions · 2026-04-11: 1Mentions · 2026-04-12: 3Mentions · 2026-04-13: 6Mentions · 2026-04-14: 12Mentions · 2026-04-15: 3Mentions · 2026-04-17: 2Mentions · 2026-04-18: 1Mentions · 2026-05-12: 1Mentions · 2026-05-19: 1Mentions · 2026-05-23: 3Mentions · 2026-05-25: 5Mentions · 2026-05-27: 1Mentions · 2026-05-29: 1Mentions · 2026-06-05: 1Mentions · 2026-06-09: 1Mentions · 2026-09-09: 1PoC Mentioned / Linked · 2026-05-25: 1PoC Mentioned / Linked · 2026-06-09: 1PoC Mentioned / Linked · 2026-09-09: 1Active Exploitation · 2026-05-23: 1Patch / Workaround · 2026-04-11: 1Patch / Workaround · 2026-04-12: 1Patch / Workaround · 2026-04-13: 2Patch / Workaround · 2026-04-14: 5Patch / Workaround · 2026-04-15: 2Patch / Workaround · 2026-04-17: 1Patch / Workaround · 2026-05-19: 1Patch / Workaround · 2026-05-25: 5Patch / Workaround · 2026-05-27: 1Patch / Workaround · 2026-06-09: 1Patch / Workaround · 2026-09-09: 1Technical Details · 2026-04-09: 2Technical Details · 2026-04-11: 1Technical Details · 2026-04-12: 2Technical Details · 2026-04-13: 4Technical Details · 2026-04-14: 9Technical Details · 2026-04-15: 3Technical Details · 2026-04-17: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-19: 1Technical Details · 2026-05-23: 1Technical Details · 2026-05-25: 4Technical Details · 2026-05-27: 1Technical Details · 2026-06-05: 1Technical Details · 2026-06-09: 104-0904-1104-1204-1304-1404-1504-1704-1805-1205-1905-2305-2505-2705-2906-0506-0909-09
Signal classification6 categories
Disclosure
1942.2%
Patch
1737.8%
General
613.3%
Active Exploitation
12.2%
PoC
12.2%
Exploit
12.2%
Referenced assets19 URLs
Classification over time
DateTotalLabels
2026-04-092
Disclosure2
2026-04-111
Patch1
2026-04-123
Disclosure1General1Patch1
2026-04-136
Disclosure2General2Patch2
2026-04-1412
Disclosure6General1Patch5
2026-04-153
Disclosure1Patch2
2026-04-172
Disclosure1Patch1
2026-04-181
General1
2026-05-121
Disclosure1
2026-05-191
Patch1
2026-05-233
Active Exploitation1Disclosure2
2026-05-255
Disclosure2Patch2PoC1
2026-05-271
Patch1
2026-05-291
General1
2026-06-051
Disclosure1
2026-06-091
Exploit1
2026-09-091
Patch1
Full discourse20 posts
  • Lukasz Olejnik@lukOlejnik
    Disclosure

    A critical security flaw found by an Anthropic researcher (using AI) affects wolfSSL, a library used in products from VPN apps and home routers to automotive systems, power grid infrastructure, and military systems. CVE-2026-5194 could let a device or application accept a forged digital identity as genuine, trusting a malicious server, file, or connection it should have rejected. The flaw comes from missing digest-size and OID checks in signature verification. Red Hat rates it CVSSv3 10.0 (max; remotely exploitable, no privileges required, no user interaction needed). wolfSSL states its library is used on billions of devices.

    Post summary

    The text announces a newly discovered critical flaw in wolfSSL (CVE-2026-5194) that allows forging digital identities without privileges or user interaction, providing technical details but no exploit code or mitigation.

    2212416639344129.8K
    31.0K followersView on X
  • Hackread.com@HackRead
    Patch

    Critical wolfSSL flaw (CVE-2026-5194) allows digital ID forgery across billions of devices. Update to version 5.9.1 to fix the issue and reduce risk. Read: https://hackread.com/wolfssl-vulnerability-iot-routers-military-systems/ #CyberSecurity #Vulnerability #wolfSSL #IoT

    Post summary

    A critical vulnerability (CVE-2026-5194) in wolfSSL allowing digital ID forgery was disclosed, and users are advised to update to version 5.9.1 to remediate the issue.

    0202082.3K
    114.2K followersView on X
  • Gray Hats@the_yellow_fall
    Disclosure

    wolfSSL (CVE-2026-5194) faces a critical 9.3 CVSS flaw in ECDSA certificate validation. Attackers can bypass security and spoof trusted hosts. Audit today! #wolfSSL #CyberSecurity #InfoSec #EmbeddedSecurity #CVE20265194 #Cryptography #TLS #RTOS https://securityonline.info/wolfssl-cve-2026-5194-certificate-validation-bypass/ https://t.co/K236NReR8h

    Post summary

    A news article highlights a critical CVSS 9.3 flaw in wolfSSL’s ECDSA certificate validation that enables attackers to spoof trusted hosts.

    15041304
    12.3K followersView on X
  • IT-Connect.fr@ITConnect_fr
    Patch

    ⚠️ wolfSSL - CVE-2026-5194 Une faille de sécurité critique a été découverte et patchée dans la bibliothèque wolfSSL, particulièrement utilisée sur les systèmes embarqués et l'IoT. Les détails par ici 👇 - https://www.it-connect.fr/cve-2026-5194-quand-un-bug-dans-wolfssl-valide-des-certificats-falsifies/ #infosec #cybersecurite https://t.co/x2OEpkNwvT

    Post summary

    The tweet announces that a critical vulnerability (CVE‑2026‑5194) in wolfSSL was discovered and subsequently patched, with a link to more details.

    03061655
    11.4K followersView on X
  • Evan Kirstel #B2B #TechFluencer@EvanKirstel
    Disclosure

    An Anthropic researcher just used AI to discover a critical vulnerability in wolfSSL (CVE-2026-5194) that affects millions of IoT devices and embedded systems. This is where AI security gets real. The same models people worry about being dangerous are the ones finding and fixing the bugs that could take down critical infrastructure. AI as the ultimate security researcher is no longer theoretical. #AI #Cybersecurity #IoT #InfoSec

    Post summary

    An Anthropic researcher discovered CVE‑2026‑5194 in wolfSSL, a critical flaw affecting millions of IoT devices, but the post contains no PoC, exploit, patch, or active exploitation details.

    21041381
    378.8K followersView on X
  • Elusive@ElusivePrivacy
    Patch

    Critical flaw in wolfSSL allows forged certificates to pass verification. CVE-2026-5194 missing digest size checks in ECDSA, DSA, ML-DSA, Ed25519, Ed448. Attacker can trick a device into trusting a malicious server or connection. wolfSSL runs in IoT, ICS, automotive, aerospace, embedded systems. Estimated reach: 5B+ devices. Fixed in wolfSSL 5.9.1 (April 8). Downstream firmware vendors may lag check your stack. → CVE-2026-5194 | Source: https://t.me/VulnerabilityNews/41865 BleepingComputer

    Post summary

    The post reports a critical wolfSSL flaw that allows forged certificates due to missing digest size checks, impacting over 5 B devices, but a patch (v5.9.1) has been issued.

    01040144
    184 followersView on X
  • Scott Piper@0xdabbad00
    Patch

    WolfSSL signature verification vuln (Critical CVE-2026-5194) looks notable as it impacts all signature verification algorithms in that library including PQC ML-DSA. https://github.com/wolfSSL/wolfssl/releases/tag/v5.9.1-stable

    Post summary

    The post highlights a critical signature verification flaw in WolfSSL (CVE-2026-5194) that affects all verification algorithms and links to a GitHub release that most likely contains the patch to mitigate the vulnerability.

    000221.8K
    19.8K followersView on X
  • Autumn Good@autumn_good_35
    General

    😨 『wolfSSL states its library is used on billions of devices.』 CVE-2026-5194 https://nvd.nist.gov/vuln/detail/CVE-2026-5194

    Post summary

    The post references CVE‑2026‑5194 and notes wolfSSL’s widespread deployment but offers no details on exploitation, mitigation, or technical specifics.

    00030821
    6.9K followersView on X
  • Blue Team News@blueteamsec1
    Disclosure

    CVE-2026-5194 wolfSSL: wolfSSL: Reduced security of ECDSA authentication via missing digest size checks http://dlvr.it/TSVjLf #cyber #threathunting #infosec

    Post summary

    The tweet announces CVE‑2026‑5194, exposing a missing digest size check in wolfSSL that weakens ECDSA authentication, with no mention of exploitation, patches, or PoC code.

    01010425
    56.0K followersView on X
  • Rene Robichaud@ReneRobichaud
    Disclosure

    CVE-2026-5194 : quand un bug dans wolfSSL valide des certificats falsifiés https://www.it-connect.fr/cve-2026-5194-quand-un-bug-dans-wolfssl-valide-des-certificats-falsifies/

    Post summary

    The article highlights a new wolfSSL flaw (CVE-2026-5194) that improperly validates forged certificates, but it does not provide PoC, exploit code, or patch information.

    1100042
    3.8K followersView on X
  • Adeel Sajjad@adeeelsajjad
    Patch

    Claude found a bug that could fake your bank's website. Under Anthropic's Project Glasswing, Mythos built an exploit forging website certificates. Reported, patched, now CVE-2026-5194. The real number: 10,000+ critical bugs found in 2 months, under 1% remediated so far. https://t.co/oBmmqMCqSy

    Post summary

    The tweet announces a CVE (2026‑5194) discovered by Claude, notes an exploit for forging website certificates, and confirms a patch has been applied, though no detailed technical or exploit code is provided.

    0001098
    3 followersView on X
  • OpSec Insider@OpSecInsider
    Exploit

    Anthropic has not confirmed the date. The dual-use stakes are real: one Glasswing test built a working macOS exploit in five days, and Mythos found a flaw that could forge bank and email certificates (CVE-2026-5194, since patched).

    Post summary

    The text reveals that a functional macOS exploit for CVE-2026-5194 was built in five days, outlines the certificate forgery flaw, and notes the patch status, but does not mention code or real-world exploitation.

    1000075
    93 followersView on X
  • Dispatchy@dispatchy_ai
    Disclosure

    Security shock: Project Glasswing used Claude Mythos Preview to find 10,000+ high/critical flaws in weeks; public anchor CVE-2026-5194 (wolfSSL, CVSS 9.1). Discovery >> triage: 23,019 candidate findings vs 1,596 disclosed as of May 22 - patching capacity is the choke point.

    Post summary

    Project Glasswing discovered a high‑severity flaw (CVE‑2026‑5194) in wolfSSL among many critical findings, highlighting a surge in vulnerabilities and the importance of patching capacity.

    1000046
    36 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2025-55182 2 - CVE-2026-5194 3 - CVE-2026-48095 4 - CVE-2026-23652 5 - CVE-2026-45585 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists five trending CVEs without additional technical details, patches, or evidence of exploitation.

    00010135
    1.7K followersView on X
  • Dispatchy@dispatchy_ai
    Patch

    Anthropic's Claude Mythos found 10,000+ vulnerability candidates via Project Glasswing - 6,202 flagged high/critical, 1,726 validated, 1,094 rated high/critical. WolfSSL CVE-2026-5194 scored 9.1; 97 patches and 88 advisories issued so far.

    Post summary

    The text announces a high‑severity WolfSSL vulnerability (CVE‑2026‑5194) and notes that many patches and advisories have already been issued, focusing on mitigation rather than exploitation.

    1000062
    35 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Disclosure

    Claude Mythos AI's Project Glasswing found 10,000+ high or critical flaws in widely used software, including a critical WolfSSL flaw tied to CVE-2026-5194 and a stopped $1.5M wire transfer. #ProjectGlasswing #WolfSSL #CVE2026 https://ift.tt/Rbc7Gts

    Post summary

    Claude Mythos AI’s Project Glasswing has identified a critical flaw in WolfSSL linked to CVE‑2026‑5194, but the post offers no technical or mitigation details.

    00010166
    4.3K followersView on X
  • Sol@Solgem_crypto
    Active Exploitation

    In open source, Mythos scanned 1,000+ projects and found ~6,200 high/critical vulns. 90.6% true positive rate. Example: they found a cert forgery exploit in wolfSSL (CVE-2026-5194) — used by billions of devices.

    Post summary

    Mythos identified CVE-2026-5194 in wolfSSL as a cert‑forgery flaw that is actively exploited on a massive scale, but no patch or PoC details are provided.

    1000057
    236 followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Disclosure

    Anthropic's Claude Mythos Preview Uncovers 10,000+ 0-Days in Project Glasswing https://cybersecuritynews.com/anthropics-claude-mythos-preview-0-days/ "A notable discovery was CVE-2026-5194, a critical flaw in the wolfSSL cryptography library."

    Post summary

    The article announces Anthropic’s Claude Mythos preview revealing 10,000+ zero-days, including CVE-2026-5194—a critical flaw in the wolfSSL library—without providing a PoC, exploit details, active exploitation evidence, or patch information.

    10000152
    3.5K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-27303 2 - CVE-2026-34197 3 - CVE-2026-5194 4 - CVE-2026-4365 5 - CVE-2026-34621 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists five trending CVEs without providing technical or exploitation details.

    00010174
    1.7K followersView on X
  • Rob Mitchell@TheBTCGame
    Disclosure

    I hadn't caught that CVE-2026-5194 is trivial to exploit and is currently in about *5 Billion Devices* including: • Military • Aviation • Smart grids • Industrial controllers • Industrial routers • Home routers • IoT devices Clearly, many of these devices will never be patched. Just one of the bugs Anthropic's Mythos seems to have found. h/t: @SGgrc / Security Now Podcast

    Post summary

    The post announces CVE‑2026‑5194 as trivially exploitable across billions of devices and notes that many will likely never receive a patch.

    00010137
    3.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwolfsslwolfssl---

Explore more