Microsoft Security Response Center guidance
Release Notes
Vulnerability intelligence
CVE-2026-89136 and is rated High severity with a CVSS score of 8.3. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Release Notes
When using RPK (Raw Public Key), the client side of a TLS 1.2, 1.3 and DTLS 1.2 connection could accept an unsolicited server_cert_type=RawPublicKey which allowed a malicious or misbehaving server to bypass authentication. RPK is off by default and only enabled in --enable-rpk OR --enable-all OR --enable-distro AKA HAVE_RPK builds.