CVE-2026-59642
In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
- Affected products
- Bouncy Castle For Java, Bcpkix Fips
- Fix
- Available
- CVSS 4.0
- 8.7 HIGH
- EPSS
- 0.2% (5th percentile)
- Weakness
- CWE-354
- NVD status
- Undergoing Analysis
- Published
- 2026-08-03
CVE-2026-59642 at NVD
No indexed exploits for CVE-2026-59642 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-59642 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.