CVE-2026-6860
A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a
A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard name, e.g. if the server is configured with a certificate accepting *.example.com, any XYZ.example.com where xyz is a valid name can be used.
MEDIUM · CVSS 5.3
EPSS 0.00012
Schedule remediation
- Public exploit or PoC is available
- SSVC automatable: yes - attacks can be scripted at scale
Sigma rules0
YARA rules0