CVE-2026-53499
Last modified
CVE-2026-53499 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. FORT Validator is a Resource Public Key Infrastructure (RPKI) relying-party validator that produces validated route-origin data. FORT Validator versions through 1.6.7 contain an origin-validation error in their RRDP processing: a delegated CA under the same Trust Anchor Locator (TAL) can reference a victim CA’s public RRDP notification and snapshot URLs, causing FORT’s URL-based download cache to report success after deleting the victim’s local snapshot. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
FORT Validator is a Resource Public Key Infrastructure (RPKI) relying-party validator that produces validated route-origin data. FORT Validator versions through 1.6.7 contain an origin-validation error in their RRDP processing: a delegated CA under the same Trust Anchor Locator (TAL) can reference a victim CA’s public RRDP notification and snapshot URLs, causing FORT’s URL-based download cache to report success after deleting the victim’s local snapshot. Following a routine victim publication, this can silently remove the victim’s VRPs and other signed objects from FORT’s output, potentially enabling route hijacking or loss of reachability. Version 1.6.8 contains a patch that rejects cross-origin RRDP snapshot and delta URLs; as a workaround, administrators can disable HTTP/RRDP with --http.enabled=false while keeping rsync enabled, although this can leave data unavailable or stale where rsync is not supported.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| NICMx | FORT-validator | < 1.6.8 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-53499?
How severe is CVE-2026-53499?
How do I fix CVE-2026-53499?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5349A vulnerability was identified in Trendnet TEW-657BRM 1.00.1…8.8
- CVE-2026-53492containerd is an open-source container runtime. In Versions …9.6
- CVE-2026-53493containerd is an open-source container runtime. Prior to ver…6.9
- CVE-2026-53495containerd is an open-source container runtime. Prior to 1.7…6.8
- CVE-2026-53496ExifReader is a JavaScript Exif information parser. Prior to…5.3
- CVE-2026-53497CrossWatch (CW) is a synchronization engine. Prior to versio…5.3
- CVE-2026-5350A security flaw has been discovered in Trendnet TEW-657BRM 1…8.8
- CVE-2026-53500Thumbor is an open-source photo thumbnail service by globo.c…8.2
- CVE-2026-53501Thumbor is an open-source photo thumbnail service by globo.c…8.2
- CVE-2026-53502Thumbor is an open-source photo thumbnail service by globo.c…8.7
- CVE-2026-53503Thumbor is an open-source photo thumbnail service by globo.c…7.5
- CVE-2026-53504Thumbor is an open-source photo thumbnail service by globo.c…7.5
Are you affected by CVE-2026-53499?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
