PT-2026-106751 · Microsoft+2 · Msquic+2

CVE-2026-105794

·

Published

2026-10-06

·

Updated

2026-10-06

CVSS v4.0

9.1

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MsQuic versions prior to 2.4.20 MsQuic versions prior to 2.5.11 MsQuic versions prior to 2.6.1
Description MsQuic clients using the OpenSSL or QuicTLS TLS backends fail to properly verify that a server certificate matches the intended target server hostname. This allows an on-path attacker to present a certificate that does not match the target hostname and spoof the server identity in a man-in-the-middle attack, where an attacker intercepts communication between two parties. The Schannel backend is not affected.
Recommendations Update to version 2.4.20. Update to version 2.5.11. Update to version 2.6.1.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105794
GHSA-W5F4-FX9M-M4Q7

Affected Products

Msquic
Openssl
Quictls