CVE-2026-59639
In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
- Affected products
- Bouncy Castle For Java, Bcpkix Fips
- Fix
- Available
- CVSS 4.0
- 8.7 HIGH
- EPSS
- 0.2% (7th percentile)
- Weakness
- CWE-347
- NVD status
- Undergoing Analysis
- Published
- 2026-08-03
CVE-2026-59639 at NVD
No indexed exploits for CVE-2026-59639 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-59639 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.