VeraCrypt 1.26.29 has been released for Linux, FreeBSD, Windows, and macOS, introducing broad platform and packaging changes alongside security fixes. The update adds native DEB and RPM packages, support for the Argon2id key derivation function, XML and TLV keyfile formats, FUSE3 integration, and Linux ntfs3 support for NTFS volumes. It also improves performance through optimized KDF handling and faster quick-format operations, while Windows builds gain compatibility updates for Windows 11 25H2, EFI changes tied to Microsoft UEFI CA 2023, and new options including /protectScreen and /enableIME.
The release also fixes two vulnerabilities: CVE-2026-53762, affecting the published VeraCrypt C/C++ SDK when built with WOLFCRYPT=1, and CVE-2026-54073, a Windows-specific memory or temporary-file handling issue described as enabling local privilege escalation. Separately, the report highlights an unpatched BitLocker zero-day known as GreatXML, which can reportedly expose encrypted data by forcing BitLocker into Recovery mode after a Windows Defender Offline Scan.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
The report states that the VeraCrypt C/C++ SDK was published alongside the broader VeraCrypt 1.26.29 release information. No specific publication date is explicitly provided in the source content.
VeraCrypt 1.26.29 was released for Linux, FreeBSD, Windows, and macOS, adding features such as native DEB and RPM packaging, Argon2id support, XML and TLV keyfiles, FUSE3 integration, and Windows 11 25H2 compatibility. The release also fixed CVE-2026-53762 affecting builds compiled with WOLFCRYPT=1 and CVE-2026-54073, a Windows local privilege escalation issue involving insecure temporary file handling.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourceveracrypt.fr
Open sourcegithub.com
Open sourceopennet.me
Open sourceopennet.ru
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.