CVE-2026-7511: PKCS7_verify signer confusion allows forged signatures to be accepted
Published Jun 25, 2026
·Updated
PKCS7verify signer confusion allows forged signatures, where the signer associated with a signature is not correctly bound, permitting a forged signature to be accepted.
Affected Software
1 affected component
wolfSSL wolfssl>=3.15.5<5.9.2
Remediation
Patch Available
Event History
Jun 25, 2026
CVE Published
via MITRE·09:32 PM
Data Sourced
via MITRE·09:32 PM
DescriptionWeakness
Data Sourced
via NVD·10:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-7511?
The severity of CVE-2026-7511 is rated as medium with a score of 5.9.
2
What does CVE-2026-7511 vulnerability involve?
CVE-2026-7511 involves PKCS7_verify signer confusion which allows forged signatures to be accepted.
3
How do I fix CVE-2026-7511?
To fix CVE-2026-7511, you should apply the available patch from wolfSSL.
4
Which software is affected by CVE-2026-7511?
The software affected by CVE-2026-7511 is wolfSSL.
5
When was CVE-2026-7511 published?
CVE-2026-7511 was published on June 25, 2026.