A vulnerability was found in wolfSSL up to 5.9.0. It has been declared as critical. Affected by this vulnerability is the function wc_CmacUpdate of the component Message Handler. The manipulation results in integer overflow.

This vulnerability is identified as CVE-2026-5477. The attack can be executed remotely. There is not any exploit available.