TrustedFirmware Mbed TLS

2 known vulnerabilities in TrustedFirmware Mbed TLS, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-73064 CVSS 2.9 low In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes…
  • CVE-2026-25832 CVSS 3.7 low In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.