Vulnerabilities & PatchesEmerging1 src
CVE-2026-53499 - FORT-validator Vulnerable to RRDP Shared Snapshot Cache Poisoning
CVE ID : CVE-2026-53499
Published : Aug. 21, 2026, 11:16 p. m.
• 1 hour, 54 minutes ago
Description : FORT Validator is a Resource Public Key Infrastructure (RPKI) relying-party validator that produces validated route-origin data. FORT Validator versions through 1. 6.
7 contain an origin-validation error in their RRDP processing: a delegated CA under the same Trust Anchor Locator (TAL) can reference a victim CA’s public RRDP notification and snapshot URLs, causing FORT’s URL-based download cache to report success after deleting the victim’s local snapshot.
Following a routine victim publication, this can silently remove the victim’s VRPs and other signed objects from FORT’s output, potentially enabling route hijacking or loss of reachability. Version 1. 6.