Bouncy Castle CVE-2026-71885 Harvested the Credential Binding That Authenticates Agent-to-Agent Channels
CVE-2026-71885: Identity Binding Failure in Bouncy Castle CVE-2026-71885, a critical vulnerability (CVSS 9.2) in Bouncy Castle for Java versions prior to 1.86, was disclosed on October 3, 2026. The flaw, categorized as CWE-295, involves improper certificate validation within the Messaging Layer Security (MLS) protocol implementation. Bouncy Castle is the default cryptographic library for many Android…