CVE-2026-34873: Trustedfirmware Mbed TLS
Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.
An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.
Affected products
- Trustedfirmware Mbed TLS: from 3.5.0, before 3.6.6 (fixed in 3.6.6); from 4.0.0, before 4.1.0 (fixed in 4.1.0)
Published 2026-04-01. Last modified 2026-06-17.