CVE-2026-6860Disclosure(eclipse / vert.x)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard name, e.g. if the server is configured with a certificate accepting *.example.com, any XYZ.example.com where xyz is a valid name can be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770CWE-295

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vert.x

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-05-06); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
vert.x

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-06: 3Mentions · 2026-05-09: 1Technical Details · 2026-05-06: 3Technical Details · 2026-05-09: 105-0605-09
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-063
Disclosure2General1
2026-05-091
Disclosure1
Full discourse4 posts
  • DailyCVE@dailycve
    Disclosure

    🟠 Eclipse Vertx, Denial of Service (DoS) via Unbounded SNI Cache Growth, #CVE-2026-6860 (Medium) https://dailycve.com/eclipse-vertx-denial-of-service-dos-via-unbounded-sni-cache-growth-cve-2026-6860-medium/

    Post summary

    The post announces a new DoS vulnerability in Eclipse Vertx with technical details but provides no PoC, exploit, or patch information.

    0000029
    198 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-6860 A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard name, e.g. if the server is conf… https://www.cve.org/CVERecord?id=CVE-2026-6860 ----- Traducción: CVE-2026-6860 Un … http://infoflow.cloud`

    Post summary

    CVE-2026-6860 discloses that a TLS client can send an SNI with a server name that matches a wildcard, potentially bypassing hostname validation during the handshake.

    0000040
    75 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-6860 A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard name, e.g. if the server is conf… https://www.cve.org/CVERecord?id=CVE-2026-6860

    Post summary

    The text provides a brief technical description of a TLS handshake issue involving server name extensions and wildcard acceptance, but offers no evidence of exploitation, PoC, patch, or false‑positive claim.

    00000186
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6860 TLS Server Name Extension Spoofing via Wildcard Certificate Matching https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6860

    Post summary

    The text announces CVE-2026-6860, identifying it as a TLS Server Name Extension spoofing vulnerability that exploits wildcard certificate matching; there is no mention of exploitation, patch, or PoC.

    0000060
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appeclipsevert.x---

Explore more