
CVE-2026-5477 An integer overflow existed in the wolfCrypt CMAC implementation, that could be exploited to forge CMAC tags. The function wc_CmacUpdate used the guard `if (cmac->total… https://www.cve.org/CVERecord?id=CVE-2026-5477
Post summary
CVE-2026-5477 describes an integer overflow in wolfCrypt CMAC that permits forging of CMAC tags, with no evidence of active exploitation, PoC, or patch information.


