SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-18257

MEDIUM · CVSS 5.6 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The CycloneCrypto cryptographic wrapper in S2OPC has a vulnerability that improperly validates the validity period of root issuer certificates, potentially allowing untrusted certificates to be accepted as valid. This flaw could lead to unauthorized access or man-in-the-middle attacks, impacting the security of systems relying on this cryptographic implementation. Organizations using S2OPC should prioritize addressing this vulnerability to ensure the integrity of their cryptographic operations.

CVE
CVE-2026-18257
Severity
MEDIUM
CVSS
5.6
EPSS
0.10%

Original NVD Description

Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of S2OPC allows a certificate issued by this root issuer to be considered trusted