CVE-2026-6094 is a heap buffer overread vulnerability found in the wc_PKCS7_DecodeEnvelopedData function, which processes crafted PKCS7 EnvelopedData structures. This vulnerability can be exploited by unauthenticated…
4 articles · Updated June 26, 2026
Recent Intelligence Reports
CVE-2026-6094 CVE Vulnerability Disclosures / 16h Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supplied data delivered via S/MIME or CMS.— cve.report · June 26, 2026
CVE-2026-6094 AKAOMA CVE VULNERABILITIES / 15h Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supplied data delivered via S/MIME or CMS.— cve.akaoma.com · June 26, 2026