THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-63073 (CRITICAL 9.8) — Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client that enforces an expected sender or uses a p

[NVD] CVE-2026-63073 (CRITICAL 9.8) — Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client that enforces an expected sender or uses a p

mednvdPublished 2026-08-25

CVE-2026-63073 CVSS: 9.8 CRITICAL Published: 2026-08-25T13:19:26.147

Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`.

Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client that enforces an expected sender or uses a pinned server certificate whose subject becomes the

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-63073