Certificate Verification Flaw in MsQuic Implementation by Microsoft
CVE-2026-105794

9.1CRITICAL

Key Information:

Vendor

Microsoft

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-105794?

MsQuic, a cross-platform C implementation of the IETF QUIC protocol, faced a vulnerability pre-versions 2.4.20, 2.5.11, and 2.6.1. This issue arises when clients utilizing the OpenSSL or QuicTLS TLS backend fail to properly verify that the server certificate aligns with the intended target server hostname. An attacker positioned on the network could exploit this weakness by presenting a fraudulent certificate, enabling them to impersonate the server in a man-in-the-middle attack. The vulnerability does not affect the Schannel backend. Microsoft has addressed this issue in subsequent versions, ensuring enhanced security for MsQuic users.

Affected Version(s)

msquic < 2.4.20 < 2.4.20

msquic >= 2.5.0, < 2.5.11 < 2.5.0, 2.5.11

msquic >= 2.6.0, < 2.6.1 < 2.6.0, 2.6.1

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.