LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-74900

jahlives · openssl encrypt

Published
CVSS9.8
Severitycritical
WeaknessCWE-391
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silently fall back to simulation mode, generating a deterministic shared secret from only 16 bytes of the private key and publicly available encapsulated key data. Attackers who obtain 16 bytes of the private key can compute the shared secret and decrypt all ciphertext, as the fallback triggers on any KEM failure without raising an error.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-74900

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-74900.