THREAT OPS › Threat News › [NVD] CVE-2026-63073 (CRITICAL 9.8) — Issue summary: OpenSSL CMP response validation passed an unexpected response
sender distinguished name directly as the format string to `ERR_raise_data()`.
Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client
that enforces an expected sender or uses a p
[NVD] CVE-2026-63073 (CRITICAL 9.8) — Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client that enforces an expected sender or uses a p
CVE-2026-63073 CVSS: 9.8 CRITICAL Published: 2026-08-25T13:19:26.147
Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`.
Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client that enforces an expected sender or uses a pinned server certificate whose subject becomes the
Indicators of compromise
- CVE-2026-63073cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-63073