CVE-2026-40947: Yubico LIBFIDO2
Low severity, CVSS 2.9. EPSS: 0.1% chance of exploitation in the next 30 days.
Yubico libfido2 before 1.17.0, python-fido2 before 2.2.0, and yubikey-manager before 5.9.1 have an unintended DLL search path.
Affected products
- Yubico LIBFIDO2: before 1.17.0 (fixed in 1.17.0)
- Yubico Python-FIDO2: before 2.2.0 (fixed in 2.2.0)
- Yubico Yubikey-Manager: before 5.9.1 (fixed in 5.9.1)
Published 2026-04-16. Last modified 2026-06-17.