CVE-2026-59112
Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability in Estonian Informat
CVSS
—
No CVSS
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 10, 2026 · Last modified: Aug 10, 2026 · CWE-347 · CWE-754
Not enough EPSS history yet.
Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability in Estonian Information System Authority (RIA) libdigidocpp, DigiDoc4, DigiDoc on Android, and DigiDoc on iOS. This issue affects libdigidocpp: from 4.1.0 before 4.2.1; DigiDoc4: from 4.7.0 before 4.8.2; DigiDoc on Android: from 2.7.0 before 2.7.2; DigiDoc on iOS: from 2.8.0 before 2.8.1.
- github.comhttps://github.com/open-eid/libdigidocpp/pull/690
- www.id.eehttps://www.id.ee/en/article/ria-soovitab-kasutajatel-uuendada-id-tarkvara-eng/
- www.ria.eehttps://www.ria.ee/blogi/digidoc-rakendustes-esinenud-turvanorkus-mis-juhtus-ja-kuidas-see-parandati
- github.comhttps://github.com/open-eid/libdigidocpp/pull/690
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-10754——
———Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls.7hCVE-2026-167426.7 MED—
———systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user9hCVE-2026-58262—2.0%
——1Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, header signature verification counts the unused padding bits of the PubKeysBitmap toward the two-thirds validator quorum. These padding bits do not correspond to any validator and are ignored by the actual BLS aggregate-signature check, so a malicious or compromised block producer can set them to reach the required quorum while gathering fewer genuine validator signatures than the protocol demands. As a result, nodes that import or intercept the header accept it as correctly signed without a real two-thirds quorum, weakening consensus safety and undermining finality. This issue is fixed in version 1.7.20.3dCVE-2025-714135.3 MED9.8%
——3Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers cause repeated resets which may result in increased workload and reduced situational awareness. This type of attack can be carried out remotely over radio frequency.3hCVE-2025-714127.1 HIG8.2%
——2Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion, and improper response actions by flight crews, traffic controllers, and ground operations. This type of attack can be carried out remotely over radio frequency.3hCVE-2026-629187.5 HIG21.5%
——6Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.3d