WOLFSSL released version 5.9.4 on 25 September 2026, fixing 10 vulnerabilities: three High, four Medium and three Low severity issues. No exploitation in the wild or confirmed public proof-of-concept has been reported. The flaws affect the TLS library used in embedded systems, IoT devices and software such as nginx, HAProxy, stunnel and OpenVPN compatibility builds, although exposure depends on the version and build configuration.
The most serious issues are CVE-2026-93302, CVE-2026-89102 and CVE-2026-89136, each rated 8.3 under CVSSv4. CVE-2026-93302 could allow a forged clone of a trusted certificate authority to pass verification because `MatchTrustedPeer` did not compare public keys; it affects versions 5.3.0 through 5.9.2 in builds using specified trusted-peer and CA-loading options.
CVE-2026-89102 affects versions 5.7.2 through 5.9.2 when multiple OCSP stapling is enabled, treating any certificate in a peer chain as a certificate authority. CVE-2026-89136 affects versions 5.6.0 through 5.9.2 when Raw Public Key support is enabled, allowing a client to accept an unsolicited server key; that feature is disabled by default.
Users should upgrade to wolfSSL 5.9.4. Where immediate upgrading is not possible, the project recommends reviewing build flags, including disabling OpenSSL-compatible defaults and avoiding trusted-peer APIs for CA loading in relation to CVE-2026-93302. Device manufacturers should incorporate the fixes into firmware updates.