Skip to content
ThreatCluster

Vulnerabilities in Arm Mbed Crypto and Mbed TLS Expose Private Keys

First seen 18 Feb 2026, 10:13 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

Two vulnerabilities have been identified in Arm Mbed Crypto and Mbed TLS that could allow local attackers to recover private keys through side-channel attacks. CVE-2019-18222, published on January 23, 2020, involves an issue with the ECDSA signature implementation, while CVE-2019-16910, published on September 26, 2019, relates to insufficient entropy in RNG when deterministic ECDSA is enabled.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 213d ago How this analysis works

Timeline

2019-09-26
CVE-2019-16910 published
2020-01-23
CVE-2019-18222 published
2026-02-18
Information published about both vulnerabilities

More articles in this cluster (3)

Following this threat?

Track CVE-2019-16910 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed