Skip to content
CVE-2026-6678: Integer Underflow Vulnerability in PKCS#7 Decryption

CVE-2026-6678: Integer Underflow Vulnerability in PKCS#7 Decryption

First seen 26 Jun 2026, 11:07 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •June 27, 2026 at 10:46 UTC
  • •CVE-2026-6678 involves an integer underflow in PKCS#7 message decryption.
  • •Exploitation allows unauthorized access to sensitive data through crafted messages.
  • •No patches or public proof-of-concept are currently available.

CVE-2026-6678 is an integer underflow vulnerability in the wc_PKCS7_DecryptOri function, affecting systems that process PKCS#7 messages. An unauthenticated attacker can exploit this vulnerability by sending crafted messages with malformed Other Recipient Info, leading to potential disclosure of sensitive data. The vulnerability has a CVSS base score of 4.0, indicating a low to medium severity. Currently, there is no public proof-of-concept or evidence of active exploitation. Security teams are advised to monitor and validate PKCS#7 message structures and restrict network access to affected systems. As of now, no patch information is available. The vulnerability was published on June 25, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 96d ago How this analysis works

Timeline

2026-06-25
CVE-2026-6678 published
CVE-2026-6678 was officially published, detailing an integer underflow in wc_PKCS7_DecryptOri.
Feedly
2026-06-26
Security advisory issued
Security teams are urged to monitor PKCS#7 messages and restrict access to vulnerable systems.
cve.akaoma.com

More articles in this cluster (5)

Following this threat?

Track CVE-2026-6678 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed