Skip to content
Threat Feed

Tag

Certificate-Management

4 briefs RSS
medium advisory

Detection of Unauthorized Root or CA Certificate Installation

Adversaries can install malicious root or CA certificates into the Windows registry to facilitate traffic interception, bypass security controls, and establish persistence.

windows registry certificate-management
1r 1t
high advisory

Authorization Bypass in Lemur Leading to Unauthorized Certificate Revocation

An authorization bypass vulnerability in Lemur allows authenticated users to revoke arbitrary certificates by creating duplicate certificate records and bypassing ownership and endpoint-attached safeguards.

lemur +2 certificate-management authorization-bypass cve-2026-71417 cloud ssrf vulnerability cve-2026-70666
1r 5t 1c
critical advisory

CVE-2022-2068 c_rehash Command Injection Vulnerability

CVE-2022-2068 is a command injection vulnerability in the c_rehash script, requiring immediate attention to prevent potential arbitrary code execution.

cve-2022-2068 command-injection c_rehash certificate-management
2r 1t 1c
high advisory

Lego ACME Client Arbitrary File Write via Path Traversal

The lego ACME client is vulnerable to arbitrary file write and deletion via path traversal, where a malicious ACME server can supply a crafted challenge token containing `../` sequences, causing lego to write attacker-influenced content to any path writable by the lego process, potentially leading to remote code execution, data destruction, or privilege escalation.

lego path-traversal acme certificate-management cve-2026-40611
2r 1t