External risk intelligence

MsQuic Certificate Validation Bypass Allows Man-in-the-Middle Attacks

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-105794

MsQuic is a library commonly used to implement network protocols, specifically QUIC, which is designed for internet-facing communication. Because it is a core networking component integrated into applications that frequently act as clients or servers over the public internet, it is highly probable that deployments involving this library are exposed to internet-based traffic.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in MsQuic, a cross-platform implementation of the QUIC protocol. When using specific TLS backends, MsQuic clients may fail to verify server certificates correctly, potentially allowing attackers to impersonate servers and intercept communications. While the Schannel backend is not affected, this issue impacts client implementations relying on OpenSSL or QuicTLS.

  • Attackers can spoof servers due to unverified certificates.
  • Impacts services using MsQuic with specific TLS backends.
  • Confirm if MsQuic is used and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker on the same network can impersonate a legitimate server by presenting a fake security certificate. This allows them to intercept and potentially modify traffic between a victim and the intended server, leading to a man-in-the-middle attack. The vulnerability exists in the client's certificate validation process when using specific TLS backends.

  • Attacker must be on the same network.
  • Attacker presents a mismatched server certificate.
  • Risk of man-in-the-middle attacks.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, MsQuic clients that use the OpenSSL or QuicTLS TLS backend could be vulnerable to man-in-the-middle attacks. An attacker could present a forged server certificate, impersonating the intended server and potentially intercepting or altering communications. This could affect the integrity and confidentiality of data transmitted.

  • Server impersonation.
  • Attacker presents a fake certificate.
  • Communication could be intercepted.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given that MsQuic is a cross-platform QUIC implementation, ownership likely falls to application owners, platform teams, or infrastructure teams managing services that use this library. The immediate practical step is to determine which applications and services utilize MsQuic with the OpenSSL or QuicTLS backends, assess their exposure (especially internet-facing ones), and identify the accountable system owners before planning any remediation.

  • Confirm impacted systems and owner.
  • Verify backend TLS implementation.
  • Plan remediation based on exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is MsQuic and why is it used?

MsQuic is a C-based library that provides the IETF QUIC protocol for various programming languages, including C++, C#, and Rust. Developers use it to build high-performance network applications that need reliable and secure data transmission over the internet, serving as a foundational piece of technology for cross-platform communication.

What does CWE-295 mean for CVE-2026-105794?

The vulnerability is classified as CWE-295, which refers to improper certificate validation. In the context of CVE-2026-105794, this means affected MsQuic clients fail to verify that a server's digital certificate matches the actual domain name being accessed. Because the client does not perform this essential identity check, it cannot confirm it is talking to the real server, opening the door for impersonation.

How can an attacker trigger this vulnerability?

An attacker must be positioned on the network path between the client and the intended server to conduct a man-in-the-middle attack. By presenting a mismatched or fraudulent certificate, they can trick the vulnerable client into trusting them. Notably, this flaw only impacts clients configured with OpenSSL or QuicTLS backends; implementations using the Schannel backend are not affected.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal indicates that because MsQuic is a library designed for internet-facing communication, there is a high probability that applications using it are exposed to public network traffic. If your software uses MsQuic as a client with OpenSSL or QuicTLS, the risk of interception during network operations is elevated, making identification of these components a priority.

How should I respond to this vulnerability?

First, identify all internal applications or services that rely on the MsQuic library. Check your software configuration to see if they utilize the OpenSSL or QuicTLS backends. If you identify vulnerable instances, prioritize updating the MsQuic library to version 2.4.20, 2.5.11, or 2.6.1, depending on your current branch, to ensure proper server certificate verification is restored.

References