Wolfssl Wolfssl — CVE-2026-6094 (Critical)
Critical vendor advisory
CVE-2026-6094
Summary
Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supplied data delivered via S/MIME or CMS.
Why it matters
This CVE carries a CRITICAL severity rating (CVSS 9.1) in Wolfssl Wolfssl. Patch or mitigate promptly. EPSS percentile: 18%.
Operator check
Review CVE-2026-6094 in your asset inventory. Apply patches per vendor guidance and verify Wolfssl is not exposed. CVSS score: 9.1. EPSS probability: 0.3%; percentile: 18%.
Sources
PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.