[vulnfeed] 4 critical CVEs — 2026-08-03 04:00 UTC
vulnfeed
Critical alert — 2026-08-03 04:04 UTC
4 new critical CVEs
in the last 5 hours — 4 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-59638CRITICAL
In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documente
In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Ca
CVSS 9.3
CVE-2026-59650CRITICAL
In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue al
In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
CVSS 9.3
CVE-2026-8763CRITICAL
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This is
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIP
CVSS 9.3
CVE-2026-58062CRITICAL
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certifica
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle f
CVSS 9.3
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: