CVE-2026-89102 is an improper certificate validation vulnerability in wolfSSL 5.7.2 through 5.9.2. In clients using RFC 6961 multiple OCSP-response stapling, wolfSSL can treat any certificate supplied in a peer's certificate chain as a certificate authority without verifying that it is authorized to issue certificates. The flaw occurs when the client is built with HAVE_CERTIFICATE_STATUS_REQUEST_V2 and uses wolfSSL_UseOCSPStaplingV2 with WOLFSSL_CSR2_OCSP_MULTI. A peer certificate can also be retained in the persistent trust store, extending the effect to later connections that reuse the affected wolfSSL context.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
High-severity wolfSSL certificate-forgery issue affecting clients using RFC 6961 multiple OCSP response stapling; an unauthorized chain certificate may be accepted as a CA.
High-severity certificate-forgery vulnerability in wolfSSL clients using RFC 6961 multiple OCSP stapling, caused by failure to verify CA authorization for a chain certificate.
A client-side certificate-validation flaw in wolfSSL 5.7.2 through 5.9.2 when RFC 6961 multiple OCSP stapling is enabled via HAVE_CERTIFICATE_STATUS_REQUEST_V2 and WOLFSSL_CSR2_OCSP_MULTI. The client can incorrectly trust any peer-chain certificate as a CA without verifying CA authorization, enabling an attacker with a certificate chaining to a trusted CA and its private key to forge certificates for arbitrary identities. The server end-entity certificate can also persist in the trust store and affect subsequent connections that reuse the context.
A high-severity improper certificate-validation flaw in wolfSSL's RFC 6961 OCSP stapling v2 multi-response implementation. A client using HAVE_CERTIFICATE_STATUS_REQUEST_V2 and WOLFSSL_CSR2_OCSP_MULTI can treat a non-CA certificate in a peer chain as a CA. An attacker possessing a certificate and private key chaining to a client-trusted CA may forge arbitrary certificates accepted by the client. The server end-entity certificate can also persist in the trust store, affecting later connections that reuse the context.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.