AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-21383

HIGH · CVSS 7.1 EPSS 0.07%

Source: NVD + CISA KEV + EPSS · Published 2026-07-06 · Last synced 2026-08-05

CyberRota Analysis

AI-Generated

A vulnerability exists in the implementation of AES-GCM key wrapping due to the use of a static initialization vector, compromising the cryptographic strength required for secure operations. This flaw can lead to potential data exposure or unauthorized access, making it critical for organizations utilizing affected cryptographic systems to prioritize remediation efforts. Security teams should assess their use of AES-GCM and implement unique initialization vectors to mitigate this risk.

CVE
CVE-2026-21383
Severity
HIGH
CVSS
7.1
EPSS
0.07%

Original NVD Description

Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security.

Related CVEs

Other vulnerabilities affecting the same vendor(s)