CVE-2026-9058Disclosure

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

For untrusted certificates that contain the "Authority Information Access - caIssuers URI" extension, Szafir SDK will automatically download the parent CA certificate from the specified URL and will import it to its trust store as a "nonqualified" certificate. In such a case, Szafir SDK returns a success status code of 0 ("Positively verified") upon successful cryptographic verification and a certificate status of "nonqualified". For other types of untrusted certificates, Szafir SDK returns a success status code of 0 ("Positively verified") upon successful cryptographic verification and a certificate status of "nondetermined". This may lead integrating applications to incorrectly treat the digital signature as valid despite an untrusted certificate chain. This flaw enables authentication bypass and user impersonation: (1) in use-cases other than qualified certificate authentication, or (2) if the qualified certificate authentication use-case is not correctly implemented by the integrating application. This issue was fixed in version 1.8.463.2.

1.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295CWE-393CWE-637

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 11 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Technical details provided in 9 signals
  • Disclosure: 8 classified signals
  • General: 1 classified signal
  • Peaked 7d ago at 3 mentions (2026-05-25); latest day: 1
  • 11 total mentions across 9 days

Deep dive

Activity timeline11 mentions / 9d
01223Mentions · 2026-05-22: 1Mentions · 2026-05-25: 3Mentions · 2026-05-26: 1Mentions · 2026-05-28: 1Mentions · 2026-06-06: 1Mentions · 2026-06-10: 1Mentions · 2026-06-14: 1Mentions · 2026-06-16: 1Mentions · 2026-06-22: 1PoC Mentioned / Linked · 2026-06-10: 1PoC Mentioned / Linked · 2026-06-14: 1Technical Details · 2026-05-22: 1Technical Details · 2026-05-25: 2Technical Details · 2026-05-26: 1Technical Details · 2026-05-28: 1Technical Details · 2026-06-06: 1Technical Details · 2026-06-10: 1Technical Details · 2026-06-16: 1Technical Details · 2026-06-22: 105-2205-2505-2605-2806-0606-1006-1406-1606-22
Signal classification3 categories
Disclosure
872.7%
PoC
218.2%
General
19.1%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-05-221
Disclosure1
2026-05-253
Disclosure3
2026-05-261
Disclosure1
2026-05-281
Disclosure1
2026-06-061
Disclosure1
2026-06-101
PoC1
2026-06-141
PoC1
2026-06-161
Disclosure1
2026-06-221
General1
Full discourse11 posts
  • ZaufanaTrzeciaStrona @zaufanatrzeciastrona@infosec@Zaufana3Strona
    Disclosure

    Michał odkrył sposób na logowanie jako dowolny użytkownik do eZUS-u, E-Sądu, eZdrowia i innych rządowych systemów. Poczytajcie, bo to najgrubsze odkrycie tego roku w PL 1. https://zaufanatrzeciastrona.pl/post/zdalne-wykonanie-kodu-w-szafirhost-cve-2026-26928-badanie-e-podpisow-cz-1/ 2. https://zaufanatrzeciastrona.pl/post/hakowanie-e-sadu-yubikeyem-badanie-e-podpisow-cz-2/ 3. https://zaufanatrzeciastrona.pl/post/ominiecie-uwierzytelniania-w-zus-ie-i-systemach-e-zdrowia-czyli-o-krok-od-cyberchaosu-cve-2026-9058-badanie-e-podpisow-cz-3/ 4. https://zaufanatrzeciastrona.pl/post/podsumowanie-krytyczna-podatnosc-umozliwiajaca-calkowite-ominiecie-logowania-w-zus-ie-e-sadzie-i-systemach-e-zdrowia/ https://t.co/alwhxevIvH

    Post summary

    Michał revealed a method to authenticate as any user on several Polish government platforms, citing CVE‑2026‑26928 and CVE‑2026‑9058, but does not provide proof of active exploitation or a PoC.

    211111859039254.3K
    46.0K followersView on X
  • Michał Leszczyński@icedevml
    Disclosure

    Nagranie z mojej prezentacji na tegorocznym @CONFidenceConf "[PL] [CVE-2026-9058] Pełne ominięcie uwierzytelniania w ZUS, e-Sądzie, Usługach Elektronicznych Ochrony Zdrowia i kilku innych systemach administracji publicznej" https://youtu.be/pMdnS8I18Ts #Cybersecurity

    Post summary

    CVE-2026-9058 is disclosed as a complete authentication bypass affecting ZUS, e‑Sąd, e‑Health and other public administration systems; a YouTube presentation is referenced for details.

    062262210.0K
    433 followersView on X
  • confidenceconf@CONFidenceConf
    Disclosure

    To jest jedna z tych prezentacji, przy których trudno napisać spokojny opis. [CVE-2026-9058] Pełne ominięcie uwierzytelniania w ZUS, e-Sądzie, Usługach Elektronicznych Ochrony Zdrowia i kilku innych systemach administracji publicznej Brzmi poważnie? Bo jest poważnie. Do zo! https://t.co/GUR16IX88A

    Post summary

    The tweet announces CVE-2026-9058, describing a full authentication bypass across several public administration systems, without providing PoC, exploit, or mitigation details.

    020601.6K
    3.7K followersView on X
  • confidenceconf@CONFidenceConf
    General

    The results are in! 🎉 Based on attendee feedback, here are the highest-rated sessions from CONFidence 2026: 🏆 Michał Leszczyński - [CVE-2026-9058] Pełne ominięcie uwierzytelniania w ZUS, e-Sądzie, Usługach Elektronicznych Ochrony Zdrowia i kilku innych systemach administracji publicznej 🏆 Adam Haertle - Pozwy, wezwania i sprostowania - jak pisać o bezpieczeństwie i nie ustępować 🏆 Piotr Zarzycki - Wciąż jestem dietetykiem: fake reviewsy, fake eksperci i prawdziwy internet 🏆 Julia Zduńczyk - Za Zamkniętymi Drzwiami - czyli jak obejść fizyczną kontrolę dostępu i czytniki RFID 🏆 Mateusz Nalewajski & Karol Celiński - SDRy na poważnie, czyli jak złapać drona? 🏆 Mateusz Chrobok - Iluzja, której właśnie zapłaciliście rocznie miliony 🏆 Radosław Kumorek - AMSI vs. Obfuscacja: Gra w Kotka i Myszkę 🏆 Stanisław Kozioł - MCP Gateway - Security Enabler dla serwerów MCP 🏆 Sławomir Kiraga & Alex Wloch - Unmasking Impersonations: Exposing Global Fraud Networks 🏆 Agata Ślusarek & Adam Lange - Cyberzłoczyńcy bez maj .... cenzury ;) Kolejna część sagi przestępczości niezorganizowanej Congratulations to all speakers! 👏 We're thrilled to see such a diverse set of topics resonate with the CONFidence community - from vulnerability research and threat intelligence to physical security, AI, fraud investigations, and cybercrime. Thank you to every speaker who shared their expertise, stories, and hard-earned lessons with our attendees. And thank you to everyone who completed the post-event survey and helped us identify the sessions that made the biggest impact. See you at the next CONFidence! 🚀 Or at Oh My Hack :)

    Post summary

    An announcement of a conference session that references CVE-2026-9058, describing a full authentication bypass, but offering no further technical details, PoC, exploit, patch, or evidence of active exploitation.

    002303.9K
    3.7K followersView on X
  • Dariusz Gardyński@andig1989
    Disclosure

    1.1.6 Michał Leszczyński - [PL] [CVE-2026-9058] Pełne ominięcie uwierzytelniania w ZUS, e-Sądzie... https://youtu.be/pMdnS8I18Ts

    Post summary

    The YouTube video announces CVE‑2026‑9058, describing a full authentication bypass in Polish government services, but it provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000045
    15 followersView on X
  • RetroNukleon@RetroNukleon
    PoC

    Michał Leszczyński pokazał, jak pełne ominięcie uwierzytelnienia w kluczowych systemach rządowych (http://m.in. ZUS i e-Sąd). Zaczyna się niewinnie od starej biblioteki z 2007 roku w updaterze… a kończy logowaniem się do ZUS-u jako dowolna osoba. CVE-2026-9058 to prawdziwy poziom masterclass w security researchu. Warto obejrzeć. https://www.youtube.com/watch?v=pMdnS8I18Ts #Cybersecurity #Hacking #CONFidence2026 #ZUS #InfoSec

    Post summary

    A Polish security researcher demonstrated a complete authentication bypass in key government systems, including ZUS, by exploiting an old library from 2007, with a YouTube video detailing the exploit.

    0000057
    146 followersView on X
  • ⚛ ⚛ ⚛ Monika@artur_dybala
    PoC

    1.1.6 Michał Leszczyński - [PL] [CVE-2026-9058] Pełne ominięcie uwierzyt... https://youtu.be/pMdnS8I18Ts?si=zFhThtG28A5hF7mi przez @YouTube - Kartonowe Państwo

    Post summary

    A YouTube video is linked that demonstrates a complete authentication bypass for CVE‑2026‑9058, confirming a proof‑of‑concept exists, but no exploit code, active exploitation, or patch information is provided.

    0000041
    78 followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Disclosure

    CVE-2026-9058 (Szafir SDK) is a critical certificate-trust validation flaw where signer certificate trust cannot be established, enabling authentication bypass etc See full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-05-25/TIER_2_CVE-2026-9058.md#CyberSecurity #DigitalIdentity #DPI #ElectronicSignature #TrustServices

    Post summary

    The post announces CVE-2026-9058, a critical certificate‑trust validation flaw in the Szafir SDK that allows authentication bypass, and directs readers to a GitHub analysis for more details.

    0000052
    46 followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Disclosure

    CVE-2026-9058 (Szafir SDK) is a critical electronic-signature verification flaw undermining document authenticity and identity assurance. See full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-05-25/TIER_2_CVE-2026-9058.md#CyberSecurity #DigitalIdentity #DPI #ElectronicSignature #TrustServices #VulnerabilityManagement

    Post summary

    The post announces CVE‑2026‑9058 as a critical flaw in electronic signature verification, linking to a detailed analysis but providing no PoC, exploit, patch, or active‑exploitation evidence.

    0000072
    46 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-9058 Szafir SDK returns a success status code from the cryptographic digital signature verification process (i.e. /VerifyingTaskItem/Signature/VerificationResult/Result/@cod… https://www.cve.org/CVERecord?id=CVE-2026-9058

    Post summary

    The text discloses a flaw in the Szafir SDK’s digital signature verification where a success status is incorrectly returned, potentially allowing bypass of authentication.

    00000221
    57.5K followersView on X
  • Israel@f1tym1
    Disclosure

    Vulnerability in Szafir SDK software https://ift.tt/vweMOCf Improper Certificate Verification vulnerability (CVE-2026-9058) has been found in Szafir SDK software. Introduction to Malware Binary Triage (IMBT) Course Looking to level up your skills? Get 10% off using coupon c…

    Post summary

    A new CVE-2026-9058 related to improper certificate verification was discovered in Szafir SDK, but no further exploitation or mitigation details are provided.

    0000059
    980 followersView on X

Explore more