CVE-2026-102759: Medium severity Microsoft NetX Secure TLS vulnerability
NetX Secure TLS accepts an empty application-data record without verifying its message authentication code. In nxsecureverifymac, a decrypted application record whose length equals the negotiated MAC size is treated as valid and returns success after advancing the receive sequence number. The received MAC is never generated or compared.
Empty TLS application-data records are legal, and are commonly emitted by TLS 1.0 implementations as a BEAST mitigation.
Affected Software
Event History
Frequently Asked Questions
What traffic is affected by this flaw?
The issue affects decrypted TLS application-data records whose length equals the negotiated MAC size. These records are treated as valid without generating or comparing the received MAC.
Does an attacker need to send malformed TLS data?
No. Empty TLS application-data records are legal TLS records. The description notes that TLS 1.0 implementations commonly emit them as a BEAST mitigation.
What happens when a vulnerable record is accepted?
The MAC verification routine returns success and advances the receive sequence number even though the received MAC was not verified.