CVE-2026-71892: Product identification pending
- Severity
- 6.9 (MEDIUM)
- Vendor
- BOUNCY CASTLE FOR JAVA
- Affected versions
- Before 1.86
- Fixed version
- 1.86
- Patch status
- Patched
- Published
- 2026-10-03T09:17:05.913
- Modified
- 2026-10-03T09:17:05.913
Why it matters
Vulnerability requiring standard triage and vendor validation.
Recommended admin actions
- Review during normal vulnerability triage unless the affected system is internet-facing or business-critical.
- Compare installed versions against the affected version range in the advisory.
Technical summary
In Bouncy Castle for Java before 1.86, the opt-in key-size validation on CMS key-transport recipients, org.bouncycastle.cms.jcajce.JceKeyTransRecipient.setKeySizeValidation(true), never ran for a message using RFC 9709 content-encryption key derivation (id-alg-cek-hkdf-sha256). The branch that should have selected the actual content-encryption algorithm carried in the key derivation AlgorithmIdentifier's parameters compared the encrypted-key byte array against the id-alg-cek-hkdf-sha256 object identifier, a comparison between a byte array and an ASN1ObjectIdentifier that is false for every possible input, so the check fell through to a key-size lookup on the outer wrapper OID. That OID identifies a key-derivation construction rather than a cipher and has no registered key size, so the size comparison was skipped entirely. A key-transport EnvelopedData or AuthEnvelopedData whose transported, HKDF-derived content-encryption key did not match the key size of the advertised content-encryption algorithm was therefore accepted even with validation explicitly enabled, silently defeating the only mechanism the API offers for enforcing recovered key size. The recipient now dispatches on the content-encryption AlgorithmIdentifier's algorithm OID, so validation checks the recovered key against the inner content-encryption algorithm. Messages with a matching key size, non-HKDF messages, and recipients that do not enable validation are unaffected. This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
View the official NVD record for CVE-2026-71892
CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.
VULNERABILITY PULSE
| AFFECTED PRODUCT | ACTION | ||
|---|---|---|---|
| CVE-2026-105105 |
AIT-Core
Reporter: 309F9EA4-E3E9-4C6C-B79D-E8EB01244F2C
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2026-75937 |
IX Family
Reporter: E8A6BB0B-E373-42B1-A5DE-93E314325576
|
9.4
CRITICAL
|
VIEW RECORD |
| CVE-2026-105080 |
Product identification pending PATCH
Reporter: CVE
|
9.4
CRITICAL
|
VIEW RECORD |
| CVE-2026-104019 |
sagemaker-distribution
Reporter: FF89BA41-3AA1-4D27-914A-91399E9639E5
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-82042 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-95102 |
monta.app
Reporter: ICS-CERT
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-84411 |
RouterOS PATCH
Reporter: ICS-CERT
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-71885 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
9.2
CRITICAL
|
VIEW RECORD |
| CVE-2026-87115 |
VikAppointments Services Booking Calendar
Reporter: SECURITY
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-92084 |
Beaver Builder Page Builder – Drag and Drop Website Builder
Reporter: SECURITY
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-39718 |
Wallstreet
Reporter: AUDIT
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-92536 |
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
Reporter: SECURITY
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-97644 |
Groundhogg — CRM, Newsletters, and Marketing Automation
Reporter: SECURITY
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-88783 |
Kubio AI Page Builder PATCH
Reporter: CONTACT
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-18443 |
Smart Manager – WooCommerce Bulk Edit: Products, Orders, Users & More (Spreadsheet)
Reporter: SECURITY
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-105115 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-96451 |
Ultimate Member PATCH
Reporter: AUDIT
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-82039 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-97363 |
Product identification pending
Reporter: ICS-CERT
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-104433 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-71888 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-71889 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-71890 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-94591 |
Product identification pending
Reporter: ICS-CERT
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-94592 |
Product identification pending
Reporter: ICS-CERT
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-89236 |
SaveTo Wishlist Lite PATCH
Reporter: CONTACT
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-94593 |
Product identification pending
Reporter: ICS-CERT
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-104476 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-91078 |
TillKit PATCH
Reporter: CONTACT
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-71883 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-71886 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-71887 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-85515 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-103065 |
Kirki PATCH
Reporter: AUDIT
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-104988 |
Product identification pending
Reporter: SECALERT
|
8.1
HIGH
|
VIEW RECORD |
| CVE-2026-101923 |
Photo Reviews for WooCommerce
Reporter: SECURITY
|
8.1
HIGH
|
VIEW RECORD |
| CVE-2026-94505 |
Nelio Content – Editorial Calendar & Social Media Auto-Posting
Reporter: SECURITY
|
8.1
HIGH
|
VIEW RECORD |
| CVE-2026-104873 |
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
|
7.6
HIGH
|
VIEW RECORD |
| CVE-2026-105119 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
7.6
HIGH
|
VIEW RECORD |
| CVE-2026-93428 |
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-101159 |
WP Ultimate Review PATCH
Reporter: CONTACT
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-101160 |
WP Ultimate Review PATCH
Reporter: CONTACT
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-101161 |
WP Ultimate Review PATCH
Reporter: CONTACT
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-103514 |
WP 2FA PATCH
Reporter: CONTACT
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-103913 |
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-97337 |
Simple Membership
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-75028 |
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-96267 |
WP Visitor Statistics (Real Time Traffic)
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-96270 |
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-92977 |
Real Cookie Banner: GDPR & ePrivacy Cookie Consent
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-101928 |
Magic Tooltips For Contact Form 7
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-87091 |
Welcart e-Commerce
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-93430 |
GD Rating System
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-96564 |
SEOPress – AI SEO Plugin & On-site SEO
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-96575 |
Transliterator – Multilingual and Multi-script Text Conversion
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-96650 |
Strong Testimonials
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-97341 |
Visitor Traffic Real Time Statistics
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-93889 |
Mail logging & Catcher
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-97660 |
WPC Product Options for WooCommerce
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-104991 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-82045 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-105050 |
Product identification pending PATCH
Reporter: CVE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-104478 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-71891 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-105113 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-103342 |
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) PATCH
Reporter: AUDIT
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-82043 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-93474 |
Product identification pending
Reporter: ICS-CERT
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-97212 |
Product identification pending
Reporter: ICS-CERT
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-105030 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-71892 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-105120 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-105121 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-103293 |
MPG PATCH
Reporter: CONTACT
|
6.8
MEDIUM
|
VIEW RECORD |
| CVE-2026-85568 |
Unlimited Elements for Elementor PATCH
Reporter: CONTACT
|
6.8
MEDIUM
|
VIEW RECORD |
| CVE-2026-88782 |
Kubio AI Page Builder PATCH
Reporter: CONTACT
|
6.8
MEDIUM
|
VIEW RECORD |
| CVE-2026-94238 |
Loco Translate PATCH
Reporter: CONTACT
|
6.8
MEDIUM
|
VIEW RECORD |
| CVE-2026-94239 |
Loco Translate PATCH
Reporter: CONTACT
|
6.8
MEDIUM
|
VIEW RECORD |
| CVE-2026-85015 |
Unlimited Elements for Elementor PATCH
Reporter: CONTACT
|
6.6
MEDIUM
|
VIEW RECORD |
| CVE-2026-103036 |
orpc PATCH
Reporter: SECURITY-ADVISORIES
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-103918 |
orpc PATCH
Reporter: SECURITY-ADVISORIES
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-82041 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-94539 |
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent
Reporter: SECURITY
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-95865 |
Beaver Builder Page Builder – Drag and Drop Website Builder
Reporter: SECURITY
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-100152 |
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)
Reporter: SECURITY
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-100157 |
WP Ultimate Review
Reporter: SECURITY
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-94378 |
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-92727 |
EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2025-12828 |
Ultra Addons Lite for Elementor
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-100148 |
Rich Showcase for Google Reviews
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-101162 |
WP Ultimate Review PATCH
Reporter: CONTACT
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-97344 |
Wp Social Login and Register Social Counter
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-15795 |
Responsive Starter Templates – Elementor Templates & Starter Sites
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-92767 |
Twenty20 Image Before-After
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-104871 |
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
|
6.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-82044 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-92923 |
Unlimited Elements for Elementor PATCH
Reporter: CONTACT
|
6.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-92243 |
Ivory Search – WordPress Search Plugin
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-92538 |
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-92551 |
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
About the Vulnerability Pulse CVE Feed
The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.
How to Use the CVE Advisory Tracker
Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.
What Is a CVE Advisory?
A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.
CVE Analysis & Writeups
For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.