CVE-2026-0420
An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacke
CVSS
5.9
Medium
EPSS
0.1%
p3
KEV
—
Exploit Today
1
0-100
Published: Jun 9, 2026 · Last modified: Jul 23, 2026 · CWE-325
0.1%EPSS · 30 days0.1%
2026-08-042026-08-31
An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product's confidentiality. This vulnerability affects the listed NETGEAR models.
- kb.netgear.comhttps://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory
- www.netgear.comhttps://www.netgear.com/support/product/rax120v2/
- www.netgear.comhttps://www.netgear.com/support/product/rax35/
- www.netgear.comhttps://www.netgear.com/support/product/rax38/
- www.netgear.comhttps://www.netgear.com/support/product/rax40/
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-252506.0 MED0.5%
——0EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" associated with "Secure Boot disable."5dCVE-2026-76784—4.2%
——1Multiple
TP-Link Kasa smart home devices contain insufficient cryptographic protections
in the local device communication protocol. An adjacent network attacker may
intercept, replay or forge locally exchanged control messages, potentially
resulting in unauthorized device control.
Successful
exploitation could allow an attacker to manipulate the operational state of an
affected device, resulting in unauthorized state changes, disruption of normal
device functionality or a denial-of-service condition.5dCVE-2026-176669.1 CRI15.1%
——5Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to bypass discretionary access control via malicious network traffic. (Chromium security severity: High)30dCVE-2026-597766.8 MED3.9%
——1Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the vulnerability is exploited, information stored in the IC chip may be read or tampered with.43dCVE-2026-586386.0 MED14.2%
——4Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.42dCVE-2026-551447.1 HIG13.1%
——4Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.43d