CVE-2026-67404

LOWCVSS 9.2 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, When no CA bundle is available, ssl_options/1 falls back to [{verify, verify_none}] with no warning. An attacker in a man-in-the-middle position can forge the JWKS response, which leads the broker to accept arbitrary JWTs. Preconditions include The OAuth2 plugin must be in use with no cacertfile configured and the OS CA bundle empty or unreadable (for example, in a minimal container), and the attacker must hold a network man-in-the-middle position.. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-24: 209-24
Referenced assets1 URL
By indicator
Full discourse2 posts
  • CCB Alert@CCBalert

    Warning: Critical improper certificate validation flaws in #RabbitMQ. CVE-2026-67404 CVSS: 9.2, CVE-2026-67231 CVSS: 9.1. These vulnerabilities allow unauthenticated TLS bypass and token forgery #AuthBypass! Ref: https://github.com/rabbitmq/rabbitmq-server/security/advisories #Patch #Patch #Patch

    01020272
    7.3K followersView on X
  • AlexAImaginator@TraffAlex

    🔒 CYBERSECURITY, PRIVACY & OPEN SOURCE ROUNDUP — September 24, 2026 1️⃣ CHECK POINT GATEWAY VPN FLAW UNDER ACTIVE EXPLOITATION Check Point has confirmed that two flaws in its Security Gateway and Management web services — CVE-2026-85102 and CVE-2026-93616 — are being actively exploited. Attackers are routing their traffic through VPNs and proxies to hide their origin, and both CISA and the UK's NCSC have flagged the activity. If you run an internet-facing gateway, this is a patch-now situation rather than an end-of-quarter one. 🔹 @TweetThreatNews 2️⃣ US WATER SYSTEM PLCs REMOTELY ACCESSED BY ATTACKERS Investigators say attackers gained remote access to the programmable logic controllers that run parts of US water systems, while federal agencies probe possible Iran-backed links. Honeywell notes that many critical sites still lack full visibility into the building automation and IoT devices behind their walls. The practical takeaway: if you cannot see your OT devices, you cannot defend them. 🔹 @TweetThreatNews 3️⃣ RABBITMQ CERTIFICATE VALIDATION FLAWS NEED PATCHING Two critical improper certificate validation flaws have landed in RabbitMQ: CVE-2026-67404 (CVSS 9.2) and CVE-2026-67231 (CVSS 9.1). Together they allow an unauthenticated TLS bypass and token forgery, which effectively turns certificate checks into a formality. The project has published security advisories, and any broker sitting in front of your messaging infrastructure should be upgraded before an attacker finds it. 🔹 @CCBalert 4️⃣ CANADIAN TECH INDUSTRY PUSHES BACK AGAINST BILL C-22 Tailscale, NordVPN, Windscribe, and 20 other organizations published an open letter, covered by the Globe and Mail, arguing that Bill C-22 would force companies to weaken encryption, retain sensitive user metadata, and comply with secret government orders — creating honeypots of Canadian user data ripe for hackers. The industry's position: unless the bill is amended, Canada risks both its privacy standards and the competitiveness of its tech sector. 🔹 @c_spelliscy 5️⃣ RYUK OPERATOR SENTENCED TO TWO YEARS Karen Vardanyan, identified as the operator behind the Ryuk ransomware operation, was sentenced to two years in US federal prison and ordered to pay $1.2M in restitution. The operation she ran extracted $15M in extortion payments from hospitals and municipalities. It is a rare full-circle outcome: the person behind the keyboard is now behind a different one. 🔹 @TweetThreatNews 6️⃣ QUALCOMM BRINGS LINUX TO SNAPDRAGON X2 LAPTOPS Qualcomm talked up Linux on the Snapdragon X2, and a developer preview for the new platform is already out in the world. HP and ASUS are reportedly expected to ship X2 laptops with Linux support in the first half of 2027. If that timeline holds, the era of Linux on ARM being a tinkerer's niche is officially ending. 🔹 @phoronix 7️⃣ INTEL BUILDS A CUSTOM DXVK EXTENSION FOR ARC Intel has started developing DXVK-IGDEXT, its own extension of the DXVK translation layer aimed at improving the experience of running Windows games on Linux with Arc graphics. Instead of waiting for upstream Vulkan drivers to catch up, Intel is patching the translation layer itself — a pragmatic move for a GPU that is still trying to win over the gamer crowd. 🔹 @phoronix 8️⃣ NHTSA OPENS PROBE INTO COMMA AI AFTER FATAL CRASHES The NHTSA has opened an investigation into Comma AI following fatal crashes involving its open-source driver assistance stack. Even from within the community the consensus is nuanced: the technology is loved and the people behind it are respected, but open-source driver assistance needs extra caution — especially for the Rivian owners who run it. 🔹 @RivianTrackr 💭 The same 48 hours brought an actively exploited VPN flaw, confirmed intrusions into water-system PLCs, and a ransomware operator behind bars — while the open-source side quietly moved the goalposts: Linux is about to ship preinstalled on Snapdragon X2 laptops, Intel is writing its own Vulkan translation patches for Arc, and regulators are now looking at the open-source driving stacks in our cars. Security in 2026 is not something you install, it is a cadence: patch, verify, and keep reading the advisories. Which of these hits closest to home for you — patching an exposed gateway, hardening a messaging broker, or finally mapping your OT network? 👇 #CyberSecurity #OpenSource #Privacy

    10010201
    2.7K followersView on X

Explore more