Certificate Transparency Logs Fail to Block Rogue CA Man-in-the-Middle Attacks
Certificate Transparency was designed to detect certificates issued without the domain owner’s knowledge, yet recent testing shows it provides little practical defense against man-in-the-middle attacks performed with rogue certificates from compromised or cooperative certificate authorities.
Limitations of Public CT Log Aggregators
Existing web aggregators such as crt.sh are frequently recommended for checking logged certificates, but they suffer from reliability problems including repeated 502 errors. More importantly, an attacker who can influence a certificate authority can also influence an aggregator, rendering third-party sites untrustworthy for high-stakes verification. Even when data is available, the pre-certificate stored in the log can be made nearly identical to a malicious certificate, making manual detection of mismatches extremely difficult.
Direct Cryptographic Verification Attempts
Direct queries to CT logs using the documented /ct/v1/get-proof-by-hash endpoint were performed on multiple real-world certificates extracted from browser sessions. Every request returned 404 Not Found. The built-in Windows utility certutil -dump similarly reported “Not found” for every SCT entry examined, including valid-looking timestamps and ECDSA signatures.
Proof-of-Concept Man-in-the-Middle Attack
To demonstrate the weakness, a complete certificate chain for the popular Russian site habr.com was obtained and replicated using a locally generated self-signed CA that matched all subject attributes, extensions, and validity dates. The forged chain was served by an nginx instance configured with proxy_pass to the real site while the attacker’s CA was added to the system trust store. The browser displayed a fully secure connection with no warnings, and HSTS offered no protection because the presented certificate satisfied the browser’s basic checks.
The attack was also reproduced in a public environment hosted on Yandex Cloud. Users can test the bypass by setting a CNAME record for habr.com pointing to the provided cloud endpoint or by editing /etc/hosts. A simple curl command confirms the substitution returns a page stating “I’m not Habr!”.
Conclusions on Current CT Effectiveness
While CT logs may eventually help identify certificates obtained by deceiving an honest CA, they currently offer no reliable mechanism for browsers to reject certificates from a malicious or coerced CA. The gap between the advertised protection and observed behavior indicates that additional client-side enforcement or alternative transparency mechanisms are still required.
Related articles
Critical CVE-2026-61500 in Rejetto HFS Allows Admin Session Forgery Leading to Remote Code Execution
A critical vulnerability tracked as CVE-2026-61500 is being actively exploited in Rejetto HTTP File Server (HFS), enabling unauthenticated attackers to forge administrator sessions and achieve remote code execution. The flaw impacts versions 3.0.0 through 3.2.0 and was addressed in release 3.2.1, making immediate updates essential for any internet-exposed instances. The root cause lies in the use of JavaScript Math.random() to generate the session cookie signing key instead of a cryptographically secure random number generator. Attackers can reconstruct the internal state of this weak PRNG from login responses, allowing them to create valid admin cookies. Once authenticated as an administrator, the attacker can abuse the server_code functionality to execute arbitrary JavaScript on the server. Exploitation activity was first observed on October 1, 2026, targeting U.S. systems and attributed to an unidentified actor based in China, following the public release of a Python proof-of-concept in late September.
Dell Patches Six Critical Flaws in Container Storage Modules for Kubernetes
Dell has fixed six vulnerabilities in its Container Storage Modules that integrate storage systems with Kubernetes clusters. Two of the issues received the maximum CVSS score of 10.0, allowing remote unauthenticated attackers to obtain full administrative credentials for registered storage backends. Additional flaws enable privilege escalation to root on cluster nodes, exposure of hardcoded credentials, and leakage of Kubernetes secrets across the entire cluster. All versions prior to 1.17.0 are affected, with the fixes delivered in version 1.18.0. No workarounds exist, and Dell recommends rotating JWT signing keys after applying the update because the previous keys must be considered compromised.
Critical Sandbox Bypass Flaw in GitLab AI Gateway Enables Remote Command Execution
GitLab has released patches for a critical vulnerability in its GitLab AI Gateway component that allows authenticated users to bypass sandbox restrictions and execute arbitrary commands. The flaw, tracked as CVE-2026-90970, resides in the custom flow prompt template processing of the Duo Agent Platform and carries a CVSS v3.1 base score of 9.9. Self-hosted deployments are affected, while GitLab’s own hosted AI Gateway service has already been updated. The company urges immediate upgrades to versions 19.4.1, 19.3.2, or 19.2.4. The vulnerability can be triggered under specific conditions by users with access to the Duo Agent Platform through crafted flow configurations.
WebPros Releases Critical Patches for Three Vulnerabilities in cPanel & WHM
WebPros International has published security updates addressing three critical vulnerabilities in its cPanel & WHM hosting management platform. All three issues received the highest severity rating of Critical. The flaws include CVE-2026-93698, an input validation weakness in the Multilang adminbin component that could allow root-level operating system command execution. Two additional stored cross-site scripting vulnerabilities were also fixed, one of which is CVE-2026-93697 affecting the Mass Modify Accounts interface in WHM. Successful exploitation of the XSS flaws could let low-privileged accounts hijack administrator sessions. The updates were made available on September 29, 2026, and carry CVSS v3.0 base scores reaching 9.9.