Loading
An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the serialized structures to induce memory corruption, leading to arbitrary code execution. This is caused by Incorrect Use of Privileged APIs.
Use CWE-250, Arm vendor hub and Mbed Tls product page to widen CVE-2026-34877 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-34875, CVE-2026-34873 and CVE-2026-34872 for nearby disclosures in the same product family.