The product does not validate, or incorrectly validates, a certificate.
1,395 vulnerabilities with CWE-295
CVE-2026-9259
MEDIUM
Canon Inc. Eos Network Setting Tool For Windows - Improper Certificate Validation
CVSS 6.5
CVE-2026-9258
MEDIUM
Canon Inc. Eos Network Setting Tool For Windows - Improper Certificate Validation
CVSS 6.5
CVE-2026-45170
HIGH
Idira Privilege Cloud Connector: Potential Security Bypass due to Incomplete TLS Certificate Validation
CVE-2026-45175
HIGH
Idira Endpoint Privilege Manager Agent: Security Control and Cryptographic Validation Bypass in Internal Agent Validation Processes
CVE-2026-40992
MEDIUM
Mail Auto-Configuration Does Not Enable SSL Hostname Verification
CVSS 5.0
CVE-2026-53475
CRITICAL
Assisted-migration-agent: tls verification disabled on all vcenter connections
CVSS 9.3
CVE-2026-9758
HIGH
Improper Certificate Validation in S2OPC
CVSS 7.3
CVE-2026-41714
MEDIUM
In Spring AMQP the RabbitConnectionFactoryBean.setUri("amqps://...") bypasses secure SSL setup, uses TrustEverythingTrustManager
CVSS 4.0
CVE-2026-42769
MEDIUM
Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate
CVSS 5.3
CVE-2026-50752
HIGH
Certificate Validation Bypass in VPN Site-to-Site Connections Using IKEv1
CVSS 7.4
CVE-2026-45745
HIGH
Termix has improper certificate validation in Electron desktop client that enables MITM credential/token theft
CVSS 8.0
CVE-2026-41859
HIGH
Cloud Foundry Foundation Bosh < 282.1.9 - Improper Certificate Validation
CVSS 7.8
CVE-2026-49267
MEDIUM
Apache Airflow: No certificate validation on SMTP STARTTLS connections
CVSS 5.9
CVE-2026-47074
HIGH
ex_aws_sns SigningCertURL not validated in verify_message/1
CVE-2026-42790
HIGH
nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification
CVSS 8.1
CVE-2026-42791
LOW
OCSP responder certificate validity period not checked in public_key
CVSS 3.7
CVE-2026-42789
MEDIUM
Non-CA certificate accepted as intermediate issuer in public_key path validation
CVSS 4.8
CVE-2026-45574
HIGH
epa4all-client: TLS Certificate Validation Disabled in Production
CVSS 8.1
CVE-2026-44900
HIGH
epa4all-client: VAU Signature bypass
CVSS 8.1
CVE-2026-44213
MEDIUM
OpenTelemetry.Exporter.Instana bypasses TLS certificate validation when a proxy is configured
CVSS 6.5
CVE-2026-42012
HIGH
Gnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sans
CVSS 7.1
CVE-2026-48697
HIGH
FastNetMon Community Edition <= 1.2.9 - Missing TLS Certificate Validation in execute_web_request_secure
CVSS 7.4
CVE-2026-32253
CRITICAL
Sunshine: Authentication bypass via improper client certificate validation
CVSS 9.8
CVE-2026-8992
HIGH
Ivanti Secure Access Client - Improper Certificate Validation
CVSS 8.8
CVE-2026-42508
CRITICAL
Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts
CVSS 9.1
Details
Vulnerabilities
1,395