Two high-severity vulnerabilities were disclosed in Mbed TLS, including a buffer overflow in FFDH public key export tracked as CVE-2026-34875 and a memory-corruption issue tied to serialized SSL context or session structures tracked as CVE-2026-34877. The first flaw affects Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0, while the second impacts Mbed TLS 2.19.0 through 3.6.5 as well as 4.0.0. Both issues were assigned a CVSS v3.1 score vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating remotely exploitable conditions with low attack complexity and high impact on confidentiality, integrity, and availability.
CVE-2026-34875 is classified under CWE-120 and occurs during export of FFDH public keys, creating a buffer overflow condition. CVE-2026-34877 is associated with CWE-502 and CWE-250 and can lead to arbitrary code execution if an attacker can alter serialized SSL context or session data before it is processed. Mbed TLS security advisories were published for both flaws, putting organizations that embed the library in network-facing products, cryptographic services, or TLS-enabled applications on notice to review affected versions and vendor guidance immediately.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A second Mbed TLS vulnerability, CVE-2026-34877, was disclosed affecting versions 2.19.0 through 3.6.5 and 4.0.0. The issue involves unsafe handling of serialized SSL context or session structures that can enable arbitrary code execution, with references to Mbed TLS security advisories.
A new vulnerability, CVE-2026-34875, was published affecting Mbed TLS through version 3.6.5 and TF-PSA-Crypto 1.0.0. The flaw is a buffer overflow during FFDH public key export and was documented with high-impact CVSS scoring and Mbed TLS advisory references.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.