CVE-2026-1858 – wget2 Improper Certificate Validation

CVE ID :CVE-2026-1858

Published : April 29, 2026, 9:16 p.m. | 1 hour, 1 minute ago

Description :wget2 accepts a server certificate with incorrect Key Usage (KU) or Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication.

Severity: 4.8 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more…