CVE-2026-73064EPSS p0.9%

CVE-2026-73064CVE-2026-73064

Description

In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes into the start of the TLS stream. This only affects TLS 1.3 servers.

Scoring

CVSS 2.9 ()
VectorCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS0.10% probability of exploitation · percentile 0.9% · 2026-10-01T12:00:22Z
Last modified2026-09-24
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.