CVE-2026-21383
HIGHDescription
Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security.
Is your site exposed to CVE-2026-21383?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| qualcomm | fastconnect_6900_firmware |
| qualcomm | fastconnect_6900 |
| qualcomm | fastconnect_7800_firmware |
| qualcomm | fastconnect_7800 |
| qualcomm | lemans_au_lgit_firmware |
| qualcomm | lemans_au_lgit |
| qualcomm | lemansau_firmware |
| qualcomm | lemansau |
| qualcomm | pandeiro_firmware |
| qualcomm | pandeiro |
| qualcomm | qam8255p_firmware |
| qualcomm | qam8255p |
| qualcomm | qam8397p_firmware |
| qualcomm | qam8397p |
| qualcomm | qam8797p_firmware |
| qualcomm | qam8797p |
| qualcomm | qamsrv1h_firmware |
| qualcomm | qamsrv1h |
| qualcomm | qamsrv1m_firmware |
| qualcomm | qamsrv1m |
| qualcomm | qca6595au_firmware |
| qualcomm | qca6595au |
| qualcomm | qca6696_firmware |
| qualcomm | qca6696 |
| qualcomm | qca6698aq_firmware |
| qualcomm | qca6698aq |
| qualcomm | qca6797aq_firmware |
| qualcomm | qca6797aq |
| qualcomm | qca8695au_firmware |
| qualcomm | qca8695au |
| qualcomm | qdu1000_firmware |
| qualcomm | qdu1000 |
| qualcomm | qdu1110_firmware |
| qualcomm | qdu1110 |
| qualcomm | qdu1210_firmware |
| qualcomm | qdu1210 |
| qualcomm | qdx1010_firmware |
| qualcomm | qdx1010 |
| qualcomm | qdx1011_firmware |
| qualcomm | qdx1011 |
| qualcomm | qln1083bd_firmware |
| qualcomm | qln1083bd |
| qualcomm | qln1086bd_firmware |
| qualcomm | qln1086bd |
| qualcomm | qpa1083bd_firmware |
| qualcomm | qpa1083bd |
| qualcomm | qpa1086bd_firmware |
| qualcomm | qpa1086bd |
| qualcomm | qualcomm_dragonwing_x100_accelerator_card_firmware |
| qualcomm | qualcomm_dragonwing_x100_accelerator_card |
| qualcomm | qxm1093_firmware |
| qualcomm | qxm1093 |
| qualcomm | qxm1094_firmware |
| qualcomm | qxm1094 |
| qualcomm | qxm1095_firmware |
| qualcomm | qxm1095 |
| qualcomm | qxm1096_firmware |
| qualcomm | qxm1096 |
| qualcomm | sa7255p_firmware |
| qualcomm | sa7255p |
| qualcomm | sa7775p_firmware |
| qualcomm | sa7775p |
| qualcomm | sa8255p_firmware |
| qualcomm | sa8255p |
| qualcomm | sa8620p_firmware |
| qualcomm | sa8620p |
| qualcomm | sa8770p_firmware |
| qualcomm | sa8770p |
| qualcomm | sa9000p_firmware |
| qualcomm | sa9000p |
| qualcomm | sar1165p_firmware |
| qualcomm | sar1165p |
| qualcomm | sar2130p_firmware |
| qualcomm | sar2130p |
| qualcomm | snapdragon_ar1_gen_1_platform_firmware |
| qualcomm | snapdragon_ar1_gen_1_platform |
| qualcomm | snapdragon_ar1\+_gen_1_platform_firmware |
| qualcomm | snapdragon_ar1\+_gen_1_platform |
| qualcomm | srv1h_firmware |
| qualcomm | srv1h |
| qualcomm | srv1m_firmware |
| qualcomm | srv1m |
| qualcomm | sxr2230p_firmware |
| qualcomm | sxr2230p |
| qualcomm | sxr2250p_firmware |
| qualcomm | sxr2250p |
| qualcomm | wcd9380_firmware |
| qualcomm | wcd9380 |
| qualcomm | wcd9385_firmware |
| qualcomm | wcd9385 |
| qualcomm | wcn3950_firmware |
| qualcomm | wcn3950 |
| qualcomm | wcn7860_firmware |
| qualcomm | wcn7860 |
| qualcomm | wcn7861_firmware |
| qualcomm | wcn7861 |
| qualcomm | wsa8830_firmware |
| qualcomm | wsa8830 |
| qualcomm | wsa8832_firmware |
| qualcomm | wsa8832 |
| qualcomm | wsa8835_firmware |
| qualcomm | wsa8835 |
| qualcomm | xrv7209_firmware |
| qualcomm | xrv7209 |
| qualcomm | xrv9209_firmware |
| qualcomm | xrv9209 |
References
Frequently Asked Questions
What is CVE-2026-21383? +
How severe is CVE-2026-21383? +
What products are affected by CVE-2026-21383? +
How do I check if I'm vulnerable to CVE-2026-21383? +
Related Vulnerabilities
Due to Nonce reuse, attackers can perform reply attack or decrypt captured packets.
We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user …
Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended …
Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attackers to recover plaintext conversation state by …
Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DSA::sign caches the per-signature nonce …
hpke-js is a Hybrid Public Key Encryption (HPKE) module built on top of Web Cryptography API. Prior to version 1.7.5, …