{
  "title": "CVE of the day — CVE-2026-58162 (CVSS 10.0, critical)",
  "title_variants": [
    {
      "id": "v0",
      "title": "CVE of the day — CVE-2026-58162 (CVSS 10.0, critical)"
    },
    {
      "id": "v1",
      "title": "CVE-2026-58162: critical vulnerability, CVSS 10,0/10, type validation of the"
    }
  ],
  "description": "CVE-2026-58162: critical vulnerability, CVSS 10,0/10, type validation of the improper certificate, exploitable remotely, without privileges, without user interaction. The Apache Traffic Server certifier plugin generates certifieds based on attacker-controlled client SNI. This issue affects Apache..",
  "keywords": [
    "c",
    "cve-2026-58162",
    "vulnerability",
    "critical vulnerability",
    "cwe-295",
    "cvs",
    "cybersecurity",
    "cybersecurity",
    "♪",
    "security update"
  ],
  "scenes": [
    {
      "title": "CVE-2026- 58162",
      "subtitle": "CVSS 10.0",
      "text": "CVE-2026-58162: Critical gravity, CVSS score 10,0 out of 10 according to the National Vulnerability Database."
    },
    {
      "title": "Validation of improper certificate",
      "subtitle": "validation of the improper certificate · CVSS v3.1",
      "text": "The Apache Traffic Server certifier plugin generates certifieds based on attacker-controlled client SNI. This affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0.."
    },
    {
      "title": "EXPOSURE AND MITIGATION",
      "subtitle": "remotely exploitable, without privileges, without user interaction",
      "text": "Remotely exploitable Vulnerability, without privileges, without user interaction. Apply the update of the supplier promptly and consult the official notice on NVD."
    }
  ],
  "publication_date": "2026-07-31T00:26:26.061Z",
  "duration": 20,
  "topic": "cve",
  "lang": "en",
  "translation_group": "cve-2026-07-31",
  "poster": "cve-2026-07-31-en.jpg",
  "preview": "cve-2026-07-31-en.gif",
  "og_card": "cve-2026-07-31-en.og.jpg",
  "audiogram": "cve-2026-07-31-en.audiogram.mp4",
  "captions": "cve-2026-07-31-en.vtt",
  "generation": {
    "procedural": true,
    "ai_generated": [
      "background",
      "voice"
    ],
    "real_data_source": "official public API",
    "filmed_real_event": false,
    "disclosure": "Procedurally generated from real public-source data; abstract AI-generated backgrounds; synthetic (TTS) voice. No real event is filmed or altered."
  },
  "transcript_text": "CVE-2026-58162: Critical gravity, CVSS score 10,0 out of 10 according to the National Vulnerability Database. The Apache Traffic Server certifier plugin generates certifieds based on attacker-controlled client SNI. This affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0.. Remotely exploitable Vulnerability, without privileges, without user interaction. Apply the update of the supplier promptly and consult the official notice on NVD.",
  "transcript": [
    {
      "start": 0,
      "end": 6.667,
      "text": "CVE-2026-58162: Critical gravity, CVSS score 10,0 out of 10 according to the National Vulnerability Database."
    },
    {
      "start": 6.667,
      "end": 13.333,
      "text": "The Apache Traffic Server certifier plugin generates certifieds based on attacker-controlled client SNI. This affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0.."
    },
    {
      "start": 13.333,
      "end": 20,
      "text": "Remotely exploitable Vulnerability, without privileges, without user interaction. Apply the update of the supplier promptly and consult the official notice on NVD."
    }
  ]
}