CWE-296: Improper Following of a Certificate's Chain of Trust
The product does not follow, or incorrectly follows, the chain of trust for a certificate back to a trusted root certificate.
17 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-48057 — Icinga 2 certificate renewal might incorrectly renew an invalid certificate
- CVE-2025-1146 — CrowdStrike Falcon Sensor for Linux TLS Issue
- CVE-2026-24066 — Slate Digital Connect macOS XPC certificate validation privilege escalation
- CVE-2026-33779 — Junos OS: SRX Series: Insufficient certificate verification for device to SD cloud communication
- CVE-2026-27134 — Strimzi: All CAs from a custom CA chain consisting of multiple CAs are trusted for mTLS user autentication
- CVE-2026-27133 — Strimzi All CAs from CA chain will be trusted in Kafka Connect and Kafka MirrorMaker 2 target clusters
- CVE-2026-42789 — Non-CA certificate accepted as intermediate issuer in public_key path validation
- CVE-2026-73542 — Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an at
- CVE-2025-22459 — Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a r
- CVE-2024-43196 — IBM OpenPages data manipulation
- CVE-2025-10539 — Improper TLS Certificate Validation RCE via Malicious Update in DeskTime Time Tracking App
Recently published
- CVE-2026-73542 — Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an at
- CVE-2026-24066 — Slate Digital Connect macOS XPC certificate validation privilege escalation
- CVE-2026-42789 — Non-CA certificate accepted as intermediate issuer in public_key path validation
- CVE-2025-10539 — Improper TLS Certificate Validation RCE via Malicious Update in DeskTime Time Tracking App
- CVE-2026-33779 — Junos OS: SRX Series: Insufficient certificate verification for device to SD cloud communication
- CVE-2026-27134 — Strimzi: All CAs from a custom CA chain consisting of multiple CAs are trusted for mTLS user autentication
- CVE-2026-27133 — Strimzi All CAs from CA chain will be trusted in Kafka Connect and Kafka MirrorMaker 2 target clusters
- CVE-2025-48057 — Icinga 2 certificate renewal might incorrectly renew an invalid certificate
- CVE-2025-22459 — Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a r
- CVE-2024-43196 — IBM OpenPages data manipulation
- CVE-2025-1146 — CrowdStrike Falcon Sensor for Linux TLS Issue