SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-74901

CRITICAL · CVSS 9.8 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

OpenSSL versions prior to 1.4.0 are vulnerable to an authentication bypass due to a flaw in the pqc.py module, allowing AES-GCM decryption failures to revert to an unauthenticated AES-CTR mode. This vulnerability enables attackers to modify ciphertext during transmission, facilitating undetected bit-flipping attacks that compromise data integrity. Organizations using affected OpenSSL versions should prioritize immediate updates to mitigate this critical risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-74901
Severity
CRITICAL
CVSS
9.8
EPSS
0.23%
OpenSSL

Original NVD Description

openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ciphertext in transit to bypass integrity verification and perform bit-flipping attacks without detection.

Related CVEs

Other vulnerabilities affecting the same vendor(s)