Wolfssl · Wolfssl · CVE-2026-6092
**Name of the Vulnerable Software and Affected Versions**
The product name cannot be determined (affected versions not specified)
**Description**
When `HAVE ENCRYPT THEN MAC` is configured, the implementation may incorrectly fall back to MAC-then-Encrypt instead of enforcing the Encrypt-then-MAC sequence. Encrypt-then-MAC is a cryptographic construction where data is first encrypted and then a Message Authentication Code (MAC) is applied to the ciphertext to ensure integrity and authenticity.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.