THE Erlang/OTP team has addressed five security vulnerabilities within the runtime and its TLS stack. The most critical issue, CVE-2026-55953, allows network attackers to bypass server certificate checks, risking man-in-the-middle attacks. The vulnerabilities also include denial-of-service issues that can crash the BEAM VM and affect various applications. The affected versions range from OTP 17 onward, with recommended immediate updates to patched builds.
National cybersecurity agencies are advising administrators to promptly apply these updates due to the significance of Erlang/OTP in numerous critical infrastructures.