CVE-2026-8149Disclosure

LOWCVSS 5.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on X86_64, AVX, AVX-512f, Linux, Legion of the Bouncy Castle Inc. BC-FJA bc-fips on Linux, X86_64, AVX, AVX-512f. This vulnerability is associated with program files gcm128w, gcm512w, gcm128w.C, gcm512w.C. This issue affects BC-LTS: from 2.73.0 before 2.73.11; BC-FJA: from 2.1.0 before 2.1.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1068

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-08); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-08: 2Mentions · 2026-05-09: 1Technical Details · 2026-05-08: 2Technical Details · 2026-05-09: 105-0805-09
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-082
Disclosure2
2026-05-091
General1
Full discourse3 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    🔥 Two fresh bugs to watch: CVE-2026-8149 affects BC-FJA BC-FIPS on Linux x86_64/AVX/AVX-512f in gcm128w and gcm512w (2.1.0 through 2.1.2), while CVE-2026-8148 lets a local attacker escalate to SYSTEM in NAVER MYBOX Explorer for Windows before 3.0.11.160 via registry manipulation. https://nvd.nist.gov/vuln/detail/CVE-2026-8149 https://nvd.nist.gov/vuln/detail/CVE-2026-8148 #CVE #CyberSecurity #Infosec #Vulnerability #Linux #Windows #PrivilegeEscalation

    Post summary

    The post announces two new CVEs—CVE‑2026‑8149 affecting BC‑FJA BC‑FIPS on Linux and CVE‑2026‑8148 enabling local privilege escalation in NAVER MYBOX Explorer—detailing affected components, versions, and vulnerability nature.

    0001076
    1.3K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-8149 A vulnerability in Legion of the Bouncy Castle Inc. BC-FJA BC-FIPS on Linux, X86_64, AVX, AVX-512f. This vulnerability is associated with program files gcm128w, gcm51… https://www.cve.org/CVERecord?id=CVE-2026-8149

    Post summary

    The text references CVE-2026-8149, noting affected Bouncy Castle components and platform details, but provides no PoC, exploitation evidence, patch information, or false‑positive claim.

    00000156
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8149 Cryptographic Vulnerability in Bouncy Castle BC-FJA 2.1.0 Through 2.1.2 L... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8149 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The post announces CVE-2026-8149, a cryptographic flaw affecting Bouncy Castle BC-FJA versions 2.1.0 to 2.1.2, and provides links to detailed vulnerability information and a notification.

    0000040
    4.0K followersView on X

Explore more