
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-54435 is a reserved CVE identifier associated with a vulnerability in mbedTLS, a widely used open-source cryptographic library. As of the time of this report, full vulnerability details have not been publicly published by the assigning CNA, though Feedly AI has detected discussions and scanner detections referencing this CVE. It has been estimated as HIGH severity by Feedly AI, and has been detected by Nessus (plugin 327897) and Qualys (detection 289088) (Feedly, Tenable Nessus). The CVE was first indexed by Feedly on July 11, 2026, with updates through August 6, 2026.
Full technical details for CVE-2026-54435 have not yet been publicly disclosed, as the CVE remains in a reserved state. Based on available signals, the vulnerability affects mbedTLS and has prompted security updates for Fedora and Debian distributions (Linux Compatible, Vulners/Debian). The specific CWE classification, attack vector, and exploitation mechanics have not been confirmed in any public advisory at this time.
The precise impact of CVE-2026-54435 is not yet publicly documented. Given that mbedTLS is a cryptographic library used in embedded systems, IoT devices, and network applications, vulnerabilities in this library can potentially affect confidentiality (e.g., cryptographic key exposure), integrity (e.g., bypassing authentication or signature verification), or availability (e.g., denial of service). The breadth of mbedTLS deployments means the affected asset scope could be significant across multiple platforms and distributions.
No public proof-of-concept exploit code or confirmed in-the-wild exploitation has been reported for CVE-2026-54435 at this time. The CVE is currently in a reserved state with no official advisory published. Detection plugins have been released by Tenable (Nessus plugin 327897, 329449, 329659) and Qualys (289088), suggesting vendors are tracking the issue proactively (Tenable Nessus, Tenable Container). No EPSS score or CISA KEV catalog listing has been identified for this CVE.
Users of mbedTLS on Fedora and Debian-based systems should apply the security updates issued by their respective distributions, as both have released patches referencing this CVE (Linux Compatible, Linux Security). Monitor the official mbedTLS GitHub repository and ARM/Mbed security advisories for a full disclosure and patched version numbers. Organizations using mbedTLS in embedded or IoT products should check with their vendors for firmware updates.
Coverage of CVE-2026-54435 has been limited to distribution-level security update announcements and scanner plugin releases, with no notable researcher commentary or social media discussion identified. German Linux security outlet Pro-Linux.de published brief notices about multiple mbedTLS issues including this CVE (Pro-Linux). No vendor official statements or significant community debate have been observed at this time.
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
mbedtls
devel
mbedtls
focal (esm-apps)
mbedtls
jammy
mbedtls
jammy (esm-apps)
mbedtls
noble
mbedtls
noble (esm-apps)
mbedtls
resolute
mbedtls
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."