LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-18754

Published
CVSS9.1
Severitycritical
WeaknessCWE-321
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-18754

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-18754.