Overview
What is CVE-2026-25835?
Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG).
Vulnerability intelligence
CVE-2026-25835 and is rated High severity with a CVSS score of 7.7. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG).