Skip to main content
Echelon
Graph
Product
Directory
Enterprise
Compliance
Pulse
Exposures
AI Analyst
Compare
Docs
Login
Start Free
Pulse
›
Vendor Advisories
›
Microsoft Security Response Center (MSRC)
›
CVE-2025-27810
CVE-2025-27810
Medium
CVSS
5.4
Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.
Vendor
Microsoft Security Response Center (MSRC)
Published
July 11, 2026
Last Modified
—
🔗 CVE IDs covered (1)
CVE-2025-27810 →