AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-18753

CRITICAL · CVSS 9.1 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-04

CyberRota Analysis

AI-Generated

The vulnerability involves an embedded, static RSA private key within the firmware of a product utilizing the Lighttpd web server for TLS termination. This exposure compromises the confidentiality and integrity of HTTPS communications, allowing attackers to decrypt traffic and potentially spoof the server. Organizations using affected products should prioritize remediation to protect against significant security risks.

CVE
CVE-2026-18753
Severity
CRITICAL
CVSS
9.1
EPSS
0.31%

Original NVD Description

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing.