CVE-2026-8286

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.

Scoring

Severity
HIGH
CVSS base score
8.1
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS probability
0.31%
CWE
CWE-295
Published
2026-07-03
Last modified
2026-09-15

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs