PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-54073 veracrypt CVE debrief

VeraCrypt disk encryption was found to have a weakness in file-hosted hidden volume creation, which could potentially weaken plausible deniability during forensic inspection. This issue has been fixed in version 1.26.29. The vulnerability allows attackers to exploit the predictable 128 MiB intervals of raw zeroed sectors, leaving deterministic plaintext markers that can weaken plausible deniability during forensic inspection. Defenders should assess exposure and verify their version to ensure the fix is applied.

Vendor
veracrypt
Product
Unknown
CVSS
MEDIUM 4.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-21
Original CVE updated
2026-09-25
Advisory published
2026-08-21
Advisory updated
2026-09-25

Who should care

Defenders responsible for VeraCrypt deployments, particularly those using hidden volumes, should assess exposure and verify their version to ensure the fix is applied. This includes reviewing hidden volume creation and forensic inspection procedures. Security teams and vulnerability management teams should prioritize verifying their VeraCrypt version and assessing exposure.

Why it matters

Defenders should prioritize verifying their VeraCrypt version and assessing exposure, with a focus on hidden volume creation and forensic inspection, due to the potential weakening of plausible deniability.

  • Verification of VeraCrypt version and hidden volume creation procedures
  • Assessment of forensic inspection procedures
  • Potential weakening of plausible deniability
  • Remediation priority for versions prior to 1.26.29

Technical summary

VeraCrypt file-hosted hidden volume creation forces quick format and uses WriteFile to place raw zeroed sectors at predictable 128 MiB intervals, leaving deterministic plaintext markers that can weaken plausible deniability during forensic inspection. The vulnerability was introduced in version 1.26.6 and fixed in version 1.26.29. The affected functions are FormatNoFs in src/Common/Format.c and FormatFat in src/Common/Fat.c. These functions bypass the normal EncryptDataUnits formatting path, resulting in deterministic plaintext markers.

Defensive priority

Defenders should prioritize verifying their VeraCrypt version and assessing exposure, with a focus on hidden volume creation and forensic inspection.

Recommended defensive actions

  • Verify VeraCrypt version and assess exposure
  • Review hidden volume creation and forensic inspection procedures
  • Update to version 1.26.29 if necessary
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the VeraCrypt vulnerability, including its description and fixed version. The vulnerability was introduced in version 1.26.6 and fixed in version 1.26.29. The issue involves the FormatNoFs function in src/Common/Format.c and FormatFat function in src/Common/Fat.c using WriteFile to place raw zeroed sectors at predictable 128 MiB intervals. These writes bypass the normal EncryptDataUnits formatting path, leaving deterministic plaintext markers in an area expected to resemble random The N

Sources and references

Verified primary and authoritative sources

  • CVE-2026-54073 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-54073

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-54073 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-54073

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.