CVE-2026-8932Patch(haxx / curl)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch haxx curl systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.

2.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-305

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • curl

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 12 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 3 signals
  • Disclosure: 5 classified signals
  • Peaked 5d ago at 5 mentions (2026-06-25); latest day: 1
  • 12 total mentions across 6 days

Affected systems

Vendors
Products
curl

Deep dive

Activity timeline12 mentions / 6d
01345Mentions · 2026-06-25: 5Mentions · 2026-06-26: 3Mentions · 2026-06-29: 1Mentions · 2026-07-02: 1Mentions · 2026-07-14: 1Mentions · 2026-08-01: 1PoC Mentioned / Linked · 2026-06-26: 1Patch / Workaround · 2026-06-25: 5Patch / Workaround · 2026-06-26: 1Patch / Workaround · 2026-06-29: 1Patch / Workaround · 2026-07-14: 1Technical Details · 2026-06-26: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-14: 106-2506-2606-2907-0207-1408-01
Signal classification2 categories
Patch
758.3%
Disclosure
541.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-06-255
Patch5
2026-06-263
Disclosure2Patch1
2026-06-291
Patch1
2026-07-021
Disclosure1
2026-07-141
Disclosure1
2026-08-011
Disclosure1
Full discourse12 posts
  • elhacker.NET@elhackernet
    Patch

    Vulnerabilidad de 25 años en cURL finalmente parcheada Se ha solucionado una falla de seguridad crítica en curl que había permanecido oculta durante más de 25 años CVE-2026-8932 https://blog.elhacker.net/2026/06/vulnerabilidad-de-25-anos-en-curl.html

    Post summary

    The post announces that the long‑hidden vulnerability CVE‑2026‑8932 in cURL has been finally patched, directing readers to a blog for more information.

    111046115.9K
    141.3K followersView on X
  • Md Ismail Šojal 🕷️@0x0SojalSec
    Patch

    Anthropic’s Mythos Discovered 25-year-old hidden vulnerability running on 30+ billion devices. cURL’s oldest vulnerability (CVE-2026-8932) has finally been patched alongside 17 others in a record release. Powering everything from OSes to cars to CI/CD pipelines. https://t.co/XVgFbSTXRq

    Post summary

    The tweet announces that CVE-2026-8932, a long‑standing cURL vulnerability, has been patched in a major release, without indicating active exploitation or a PoC.

    1301463.1K
    51.9K followersView on X
  • PatchHawk@patchhawk_
    Disclosure

    The 25-year one (CVE-2026-8932): For a quarter century, libcurl's connection-reuse check left out 5 client-cert settings - private key, key password, key type, cert type, key blob. Two transfers differing only there could share a connection - and an identity. https://t.co/Acujarl1GD

    Post summary

    A 25‑year‑old libcurl flaw (CVE‑2026‑8932) is disclosed: missing checks on five client‑certificate parameters allow connection reuse that can share identity between otherwise distinct transfers.

    12020121
    51 followersView on X
  • Nullvy | CyberNews@NullvyNews
    Patch

    أصدر مشروع cURL تحديثاً أمنياً استثنائياً عالج 18 ثغرة دفعة واحدة، بينها ثغرة CVE-2026-8932 التي ظلت مخفية لأكثر من 25 عاماً. 📌 للتفاصيل الكاملة: 🔗 https://www.instagram.com/p/DaBNGV5Ig2n/?igsh=N2pjZnVqcDQ0MGRm #cURL #Vulnerabilities https://t.co/mthFhrkMO0

    Post summary

    cURL issued a security update that patched 18 vulnerabilities, including the long‑hidden CVE‑2026‑8932, with a brief announcement and a link for full details.

    0002077
    25 followersView on X
  • Faithful_Crusader_of_Spirit_and_Sacrifice🌌🔮✝️@HonorGryph
    Disclosure

    CVE-2026-8932 は何者か ・CVE-2026-8932 は、「libcurlの接続再利用において、mTLS(クライアント証明書付きTLS)設定の差分をきちんと見ていなかった」系のバグと報じられている。x+3

    Post summary

    This snippet reports CVE-2026-8932 as a libcurl vulnerability where connection reuse does not correctly handle differences in mTLS configuration settings.

    1000076
    71 followersView on X
  • Cybronites Club@ClubCybronites
    Patch

    🚨 A 25-year-old flaw in libcurl (CVE-2026-8932) is finally patched. Even trusted open-source software can hide critical bugs for decades. Update your dependencies. 🔐 #CyberSecurity #CVE #libcurl #DevSecOps https://t.co/f8iUjSF7MZ

    Post summary

    The tweet announces that CVE-2026-8932, a longstanding flaw in libcurl, has been patched and advises users to update dependencies.

    0001049
    9 followersView on X
  • LinuxSecurity@lnxsec
    Patch

    @The_Cyber_News It’s remarkable that CVE-2026-8932 remained unnoticed since curl 7.7. With so many dependencies across systems, do you anticipate any major impact as this patch gets rolled out worldwide?

    Post summary

    The tweet highlights a newly discovered CVE that has eluded detection and discusses the rollout of a patch, without providing exploit details or evidence of active exploitation.

    00001104
    4.4K followersView on X
  • guriguri@guriguri_dW
    Disclosure

    #IBMAIX ■ Security Bulletin: Multiple vulnerabilities impact AIX due to CURL libcurl (CVE-2026-10536, CVE-2026-11856, CVE-2026-8286, CVE-2026-8458, CVE-2026-8924, CVE-2026-8927, CVE-2026-8932, CVE-2026-9547). https://www.ibm.com/support/pages/node/7281743 沢山あります! 😱

    Post summary

    IBM has released a security bulletin addressing eight AIX vulnerabilities related to libcurl; the tweet cites the CVE list and links to the IBM page but includes no technical exploitation or patch details.

    0000051
    123 followersView on X
  • BT Haberler@BTHaberler
    Disclosure

    curl'de 2001'den kalma açık yapay zeka ile ortaya çıkarıldı: mTLS bağlantıları yanlış istemciyle yeniden kullanılabiliyordu! Aisle şirketi, yapay zeka destekli analizle libcurl'de 25 yılı aşkın süredir var olan bir açık keşfetti. CVE-2026-8932, curl 7.7'den (Mart 2001) 8.20.0'a kadar tüm sürümleri etkiliyor. • libcurl, bağlantı havuzundaki mTLS bağlantılarını yeniden kullanırken istemci sertifikası ve özel anahtar parametrelerini tam kontrol etmiyordu. • Uygulama sertifikayı değiştirse bile eski kimlik bilgileriyle açılan bağlantı riskli şekilde yeniden kullanılabiliyordu. • curl 8.21.0 sürümüyle bu dahil toplam 18 açık kapatıldı; komut satırı aracı değil, libcurl kullanan uygulamalar etkileniyor. Squidbleed'den sonra bir 25 yıllık açık daha yapay zeka ile bulundu — eski kod tabanları artık daha derin taranıyor! #SiberGüvenlik #curl #GüvenlikAçığı

    Post summary

    AI‑driven analysis exposed the long‑standing CVE‑2026‑8932 in libcurl, highlighting mTLS reuse flaws, and notes that version 8.21.0 patches the issue.

    0000043
    36 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    curlが18件の 脆弱性を一度に修正し単一リリースの過去最多、25年前のバグも含む-CVE-2026-8932 https://rocket-boys.co.jp/security-measures-lab/curl-record-vulnerability-fix-25year-old-bug/ #セキュリティ対策Lab #security #securitynews

    Post summary

    The tweet announces that curl will release a fix for 18 vulnerabilities in a single update, including the 25-year-old CVE‑2026‑8932, and provides a link for more details.

    00000106
    449 followersView on X
  • Ashraf Zaryouh@0xBlackash
    Disclosure

    ⚠️ CVE-2026-8932 - The Oldest libcurl Security Bug The oldest security vulnerability ever fixed in libcurl—remaining unnoticed for over 25 years. https://github.com/0xBlackash/CVE-2026-8932/ #Curl https://t.co/g2Keh2xXix

    Post summary

    The tweet announces CVE-2026-8932, the oldest libcurl vulnerability, linking to a GitHub repository that likely hosts a PoC, without indicating active exploitation, patch status, or detailed technical data.

    0000041
    32 followersView on X
  • TECHEPAGES@techepages
    Patch

    🚨 A 25-year-old curl vulnerability (CVE-2026-8932, dating back to 2001) has finally been patched, part of curl 8.21.0, which fixes a record-breaking 18 CVEs in one release. curl powers 30 billion+ devices, mostly via the embedded libcurl library. The wave started when Anthropic's Mythos AI model flagged one bug, triggering a flood of reports. AISLE alone claimed 6 of the 18 CVEs. An upgrade is strongly advised, especially for auth, proxy, or HTTP/2/3-heavy environments.

    Post summary

    Curl version 8.21.0 patches CVE-2026-8932 along with 17 other CVEs, and an upgrade is strongly recommended.

    0000050
    19 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphaxxcurl---

Explore more