THREAT OPS › Threat News › [NVD] CVE-2026-63076 (HIGH 7.5) — Issue summary: OpenSSL CMP password based protection verification only
checks whether the protectionAlg parameter was not NULL and not its
ASN.1 type, before treating it as a PBMParameter. A crafted message can
contain a parameter of a different type, which is then dereferenced a
[NVD] CVE-2026-63076 (HIGH 7.5) — Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced a
CVE-2026-63076 CVSS: 7.5 HIGH Published: 2026-08-25T13:19:26.543
Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced as an invalid pointer.
Impact summary: A remote, unaut
Indicators of compromise
- CVE-2026-63076cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-63076