CVE-2026-88647

Critical severity, CVSS 9.1. EPSS: 0.2% chance of exploitation in the next 30 days.

A hostname verification bypass in GnuTLS v3.8.13 allows attackers to circumvent the Common Name fallback mechanism and eavesdrop on communications via a crafted certificate.

Published 2026-10-08. Last modified 2026-10-10.