CRITICAL 10.0 Microsoft
CVE-2025-68121
Unexpected session resumption in crypto/tls
Microsoft Security Update 2026-Feb: Unexpected session resumption in crypto/tls
Affected Products
- azl3 golang 1.27.0-1 on Azure Linux 3.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-68121
- https://nvd.nist.gov/vuln/detail/CVE-2025-68121
This critical severity vulnerability with a CVSS score of 10.0 was published on 2026-02-10 via Microsoft. Affected: azl3 golang 1.27.0-1 on Azure Linux 3.0.
Risk Timeline
CVE Disclosed2026-02-10 · 234 days ago
Remediation Resources
Official Advisory
msrc.microsoft.com/update-guide/vulnerability/CVE-2025-68121NVD / MITRE
nvd.nist.gov/vuln/detail/CVE-2025-68121Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2026-27211 | Cloud Hypervisor: Host File Exfiltration via QCOW Backing File Abuse | CRITICAL | 10.0 |
| CVE-2024-56719 | net: stmmac: fix TSO DMA API usage causing oops | CRITICAL | 10.0 |
| CVE-2025-62168 PoC | Squid vulnerable to information disclosure via authentication credential leakage | CRITICAL | 10.0 |
| CVE-2025-69720 | The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based b | CRITICAL | 9.8 |
| CVE-2025-39743 | jfs: truncate good inode pages when hard link is 0 | CRITICAL | 9.8 |
| CVE-2025-57052 | cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_inde | CRITICAL | 9.8 |
vulnfeed aggregates 10770 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.