OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-77696

LOW · CVSS 3.7 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability arises from the SM2 signature generation process, which employs non-constant-time arithmetic on secret values, creating a timing side-channel that can be exploited. An attacker measuring the time taken for signature generation could potentially deduce the secret nonce, leading to the recovery of the private key through advanced attacks. Organizations utilizing applications that perform SM2 signature generation should prioritize addressing this issue to mitigate the risk of key compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77696
Severity
LOW
CVSS
3.7
EPSS
0.24%

Original NVD Description

Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel. Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm.

Related CVEs

Other vulnerabilities affecting the same vendor(s)