A vulnerability marked as critical has been reported in Legion of the Bouncy Castle Bouncy Castle for Java and Bouncy Castle for Java LTS up to 1.84/2.73.11. This vulnerability affects unknown code. The manipulation leads to insufficient verification of data authenticity.
This vulnerability is uniquely identified as CVE-2026-12860. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.