
Multiple wolfSSL vulnerabilities expose billions of servers and IoT devices to cyberattacks 🔹 Flaws in wolfSSL's certificate verifier (CVE-2026-11310, CVE-2026-11999) allow attacker-controlled certificates to be wrongly trusted 🔹 Crafted DTLS 1.3 ACK messages can trigger heap buffer overflows, risking remote crashes or code execution (CVE-2026-6679, CVE-2026-5264) 🔹 Admins urged to upgrade to wolfSSL 5.9.1 or 5.9.2 and disable unneeded features like OpenSSL compatibility and PKCS7 support
Post summary
Multiple wolfSSL vulnerabilities exposing billions of devices to certificate misuse and heap overflows have been disclosed; administrators should upgrade to 5.9.1/5.9.2 and disable unnecessary features to mitigate risk.

