LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-2673

openssl · openssl

Published
CVSS6.5
Severitymedium
WeaknessCWE-757
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Description

Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword. Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server. If an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to interpolate the built-in default group list into its ow

References

← Back to the CVE Tracker

Our coverage of CVE-2026-2673

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-2673.