The Encryption Library in 5 Billion Devices Just Broke: CVE-2026-5194 and the wolfSSL Certificate Forgery Flaw
Secure IoT House
April 23, 2026
CVE-2026-5194 is a critical CVSS 9.3–10.0 flaw in wolfSSL that allows forged certificate attacks on 5 billion IoT, router, and embedded devices. Patched in version 5.9.1, but most devices won't get the update.
Discussion in the ATmosphere