Forkast·
Bouncy Castle CVE-2026-71885 Harvested the Credential Binding That Authenticates Agent-to-Agent Channels
CVSS 9.2
vulnerability severity score
CVE-2026-71885: Identity Binding Failure in Bouncy Castle CVE-2026-71885, a critical vulnerability (CVSS 9.2) in Bouncy Castle for Java versions prior to 1.86, was disclosed on October 3, 2026. The flaw, categorized as CWE-295, involves…