CVE-2026-71886: Product identification pending
- Severity
- 8.2 (HIGH)
- Vendor
- BOUNCY CASTLE FOR JAVA
- Affected versions
- Before 1.86
- Fixed version
- 1.86
- Patch status
- Patched
- Published
- 2026-10-03T09:17:04.897
- Modified
- 2026-10-03T09:17:04.897
Why it matters
High-severity vulnerability requiring prioritized review.
Recommended admin actions
- Review and patch based on exposure, asset criticality, and business impact.
- Compare installed versions against the affected version range in the advisory.
Technical summary
In Bouncy Castle for Java before 1.86, the high-level OpenPGP certificate API accepted a third-party certification or trust delegation from any component key of the issuing certificate, without requiring that component to have been granted the authority to certify. OpenPGPCertificate.getCertificationBy() and getDelegationBy() resolve a third-party signature by matching its issuer key identifier against every key of the third-party certificate, then verify the issuing component's binding chain and the signature itself; nothing checked that the issuing component carried the RFC 9580 sec. 5.2.3.29 certification key flag (CERTIFY_OTHER) when the signature was created. A subkey bound only with SIGN_DATA – the online signing subkey of exactly the offline-primary arrangement those key flags exist to express – could therefore issue a positive User ID certification over an attacker-controlled identity, or a full-trust depth-one direct-key delegation of introducer trust, and the API returned it as a valid signature chain attributed to the third-party certificate. An application treating getCertificationBy(…).isValid() or getDelegationBy(…) as an identity or trusted-introducer decision would attribute the attacker's assertion to the offline primary key. The same held for a legacy RSA subkey bound only for encryption, whose algorithm is nonetheless able to sign. This does not forge the primary key's signature or recover any private key; it promotes an already-compromised restricted subkey to the primary key's identity-issuing authority, defeating the containment the key-flag separation provides. A third-party certification or delegation is now attributed to the issuing certificate only when the component key that made it is the primary key, or is a subkey holding CERTIFY_OTHER when the signature was created, so certification-capable subkeys continue to be accepted; primary keys are accepted whatever their key flags say, since a primary key is certification-capable by construction and certificates carrying no key flags subpacket at all are common. Third-party revocations are deliberately outside the rule, since declining to honour one would keep trust alive rather than withdraw it.
View the official NVD record for CVE-2026-71886
CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.
VULNERABILITY PULSE
| AFFECTED PRODUCT | ACTION | ||
|---|---|---|---|
| CVE-2026-105105 |
AIT-Core
Reporter: 309F9EA4-E3E9-4C6C-B79D-E8EB01244F2C
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2026-75937 |
IX Family
Reporter: E8A6BB0B-E373-42B1-A5DE-93E314325576
|
9.4
CRITICAL
|
VIEW RECORD |
| CVE-2026-105080 |
Product identification pending PATCH
Reporter: CVE
|
9.4
CRITICAL
|
VIEW RECORD |
| CVE-2026-104019 |
sagemaker-distribution
Reporter: FF89BA41-3AA1-4D27-914A-91399E9639E5
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-82042 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-95102 |
monta.app
Reporter: ICS-CERT
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-84411 |
RouterOS PATCH
Reporter: ICS-CERT
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-71885 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
9.2
CRITICAL
|
VIEW RECORD |
| CVE-2026-87115 |
VikAppointments Services Booking Calendar
Reporter: SECURITY
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-92084 |
Beaver Builder Page Builder – Drag and Drop Website Builder
Reporter: SECURITY
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-39718 |
Wallstreet
Reporter: AUDIT
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-92536 |
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
Reporter: SECURITY
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-97644 |
Groundhogg — CRM, Newsletters, and Marketing Automation
Reporter: SECURITY
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-88783 |
Kubio AI Page Builder PATCH
Reporter: CONTACT
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-18443 |
Smart Manager – WooCommerce Bulk Edit: Products, Orders, Users & More (Spreadsheet)
Reporter: SECURITY
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-105115 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-96451 |
Ultimate Member PATCH
Reporter: AUDIT
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-82039 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-97363 |
Product identification pending
Reporter: ICS-CERT
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-104433 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-71888 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-71889 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-71890 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-94591 |
Product identification pending
Reporter: ICS-CERT
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-94592 |
Product identification pending
Reporter: ICS-CERT
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-89236 |
SaveTo Wishlist Lite PATCH
Reporter: CONTACT
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-94593 |
Product identification pending
Reporter: ICS-CERT
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-104476 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-91078 |
TillKit PATCH
Reporter: CONTACT
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-71883 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-71886 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-71887 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-85515 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-103065 |
Kirki PATCH
Reporter: AUDIT
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-104988 |
Product identification pending
Reporter: SECALERT
|
8.1
HIGH
|
VIEW RECORD |
| CVE-2026-101923 |
Photo Reviews for WooCommerce
Reporter: SECURITY
|
8.1
HIGH
|
VIEW RECORD |
| CVE-2026-94505 |
Nelio Content – Editorial Calendar & Social Media Auto-Posting
Reporter: SECURITY
|
8.1
HIGH
|
VIEW RECORD |
| CVE-2026-104873 |
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
|
7.6
HIGH
|
VIEW RECORD |
| CVE-2026-105119 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
7.6
HIGH
|
VIEW RECORD |
| CVE-2026-93428 |
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-101159 |
WP Ultimate Review PATCH
Reporter: CONTACT
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-101160 |
WP Ultimate Review PATCH
Reporter: CONTACT
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-101161 |
WP Ultimate Review PATCH
Reporter: CONTACT
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-103514 |
WP 2FA PATCH
Reporter: CONTACT
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-103913 |
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-97337 |
Simple Membership
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-75028 |
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-96267 |
WP Visitor Statistics (Real Time Traffic)
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-96270 |
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-92977 |
Real Cookie Banner: GDPR & ePrivacy Cookie Consent
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-101928 |
Magic Tooltips For Contact Form 7
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-87091 |
Welcart e-Commerce
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-93430 |
GD Rating System
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-96564 |
SEOPress – AI SEO Plugin & On-site SEO
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-96575 |
Transliterator – Multilingual and Multi-script Text Conversion
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-96650 |
Strong Testimonials
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-97341 |
Visitor Traffic Real Time Statistics
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-93889 |
Mail logging & Catcher
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-97660 |
WPC Product Options for WooCommerce
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-104991 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-82045 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-105050 |
Product identification pending PATCH
Reporter: CVE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-104478 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-71891 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-105113 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-103342 |
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) PATCH
Reporter: AUDIT
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-82043 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-93474 |
Product identification pending
Reporter: ICS-CERT
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-97212 |
Product identification pending
Reporter: ICS-CERT
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-105030 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-71892 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-105120 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-105121 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-103293 |
MPG PATCH
Reporter: CONTACT
|
6.8
MEDIUM
|
VIEW RECORD |
| CVE-2026-85568 |
Unlimited Elements for Elementor PATCH
Reporter: CONTACT
|
6.8
MEDIUM
|
VIEW RECORD |
| CVE-2026-88782 |
Kubio AI Page Builder PATCH
Reporter: CONTACT
|
6.8
MEDIUM
|
VIEW RECORD |
| CVE-2026-94238 |
Loco Translate PATCH
Reporter: CONTACT
|
6.8
MEDIUM
|
VIEW RECORD |
| CVE-2026-94239 |
Loco Translate PATCH
Reporter: CONTACT
|
6.8
MEDIUM
|
VIEW RECORD |
| CVE-2026-85015 |
Unlimited Elements for Elementor PATCH
Reporter: CONTACT
|
6.6
MEDIUM
|
VIEW RECORD |
| CVE-2026-103036 |
orpc PATCH
Reporter: SECURITY-ADVISORIES
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-103918 |
orpc PATCH
Reporter: SECURITY-ADVISORIES
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-82041 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-94539 |
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent
Reporter: SECURITY
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-95865 |
Beaver Builder Page Builder – Drag and Drop Website Builder
Reporter: SECURITY
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-100152 |
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)
Reporter: SECURITY
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-100157 |
WP Ultimate Review
Reporter: SECURITY
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-94378 |
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-92727 |
EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2025-12828 |
Ultra Addons Lite for Elementor
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-100148 |
Rich Showcase for Google Reviews
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-101162 |
WP Ultimate Review PATCH
Reporter: CONTACT
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-97344 |
Wp Social Login and Register Social Counter
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-15795 |
Responsive Starter Templates – Elementor Templates & Starter Sites
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-92767 |
Twenty20 Image Before-After
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-104871 |
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
|
6.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-82044 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-92923 |
Unlimited Elements for Elementor PATCH
Reporter: CONTACT
|
6.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-92243 |
Ivory Search – WordPress Search Plugin
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-92538 |
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-92551 |
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
About the Vulnerability Pulse CVE Feed
The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.
How to Use the CVE Advisory Tracker
Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.
What Is a CVE Advisory?
A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.
CVE Analysis & Writeups
For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.