CVE-2026-18753: The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to b
The
product firmware contains an embedded, static RSA private key utilized by the
Lighttpd web server for TLS termination. Exposure of this private key allows
malicious actors to breach the confidentiality and integrity of HTTPS
communications, enabling traffic decryption and server spoofing.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-18753
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-18753 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for product firmware contains
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
More from NVD Recent CVEs
- highCVE-2026-67243: freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerab…2026-08-04
- unknownCVE-2026-18759: The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based i…2026-08-04
- highCVE-2026-18755: A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write acc…2026-08-04
- criticalCVE-2026-18754: The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web…2026-08-04
- unknownCVE-2026-64565: In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix heap-…2026-08-04