Use of a broken or risky cryptographic algorithm in VeraCrypt - CVE-2026-53762
Published: July 24, 2026
VeraCrypt
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper cryptographic implementation in the wolfCrypt backend when deriving SHA-256 and SHA-512 volume header keys. A remote attacker can obtain an encrypted container, disk image, or volume header and perform offline password guessing to disclose sensitive information.
Only non-default builds made with the opt-in WOLFCRYPT=1 configuration are vulnerable. Official precompiled binaries and usual distribution packages are unaffected.