NVD Vulnerability Detail
Search Exploit, PoC
CVE-2026-6860
Summary

A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard name, e.g. if the server is configured with a certificate accepting *.example.com, any XYZ.example.com where xyz is a valid name can be used.

Publication Date May 6, 2026, 7:16 p.m.
Registration Date May 7, 2026, 4:08 a.m.
Last Update May 7, 2026, 1:16 a.m.
Related information, measures and tools
Common Vulnerabilities List