CWE-295: Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
670 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-30836 — Step CA: Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18)
- CVE-2024-5261 — TLS certificate are not properly verified when utilizing LibreOfficeKit
- CVE-2024-49369 — Icinga 2 has a TLS Certificate Validation Bypass for JSON-RPC and HTTP API Connections
- CVE-2025-55109 — BMC Control-M/Agent default SSL/TLS configuration authenticated bypass
- CVE-2024-52330 — ECOVACS lawnmowers and vacuums do not properly validate TLS certificates
- CVE-2024-52329 — ECOVACS HOME mobile app plugins do not properly validate TLS certificates
- CVE-2025-3463 — "This issue is limited to motherboards and does not affect laptops, desktop computers, or other endpoints." An insuffici
- CVE-2026-22696 — dcap-qvl has Missing Verification for QE Identity
- CVE-2025-61778 — Akka.Remote TLS did not properly implement certificate-based authentication
- CVE-2024-13990 — MicroWorld eScan AV Insecure Update Mechanism Allows Man-in-the-Middle Replacement of Updates
- CVE-2025-7395 — Domain Name Validation Bypass with Apple Native Certificate Validation
- CVE-2025-40801 — A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi
- CVE-2026-25160 — Alist has Insecure TLS Config
- CVE-2025-7390 — Bypass the client certificate trust check of an opc.https server while only secure communication is allowed
- CVE-2025-40800 — A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), NX V2
- CVE-2025-11043 — Improper Server Certificate Validation in Automation Studio
- CVE-2026-24933 — An improper certificate validation vulnerability was found in ADM while sending HTTPS requests to the server.
- CVE-2026-24932 — An improper certificate validation vulnerability was found in ADM while updating the DDNS settings.
- CVE-2026-30840 — Wallos: Server-Side Request Forgery (SSRF) in Notification Testers
- CVE-2025-66001 — NeuVector OpenID Connect is vulnerable to man-in-the-middle (MITM)
Recently published
- CVE-2026-79690 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-79736 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-79729 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-79732 — Dell Secure Connect Gateway (SCG) 5.0 Appliance, versions prior to 5.36.00.xx, contains an Improper Certificate Validati
- CVE-2026-78483 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-85102 — Improper Certificate Validation in Quantum Security Gateway
- CVE-2026-78489 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-78492 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-79637 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-79967 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-78491 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-80122 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-78494 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-87733 — An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Ds
- CVE-2026-87608 — Improper certificate validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging so
- CVE-2026-87551 — Improper certificate validation in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging soc
- CVE-2026-87571 — Improper certificate validation in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging s
- CVE-2026-84197 — In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from
- CVE-2026-78234 — Hawtio-operator: hawtio-operator: service-ca signing oracle allows arbitrary-cn certificate issuance to namespace edit users
- CVE-2026-79639 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains