CVE-2026-40947: Yubico LIBFIDO2

Low severity, CVSS 2.9. EPSS: 0.1% chance of exploitation in the next 30 days.

Yubico libfido2 before 1.17.0, python-fido2 before 2.2.0, and yubikey-manager before 5.9.1 have an unintended DLL search path.

Affected products

  • Yubico LIBFIDO2: before 1.17.0 (fixed in 1.17.0)
  • Yubico Python-FIDO2: before 2.2.0 (fixed in 2.2.0)
  • Yubico Yubikey-Manager: before 5.9.1 (fixed in 5.9.1)

Published 2026-04-16. Last modified 2026-06-17.