Client Impersonation Vulnerability in Mbed TLS by ARM
CVE-2026-34873

9.1CRITICAL

Key Information:

Vendor

ARM

Status
Vendor
CVE Published:
1 April 2026

What is CVE-2026-34873?

A vulnerability in Mbed TLS affecting versions 3.5.0 to 4.0.0 allows an attacker to impersonate a client when resuming a TLS 1.3 session. This can lead to unauthorized access to sensitive information. Users are advised to update to the latest version of Mbed TLS to mitigate this risk. Detailed information can be found in the official security advisory.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.