PatchSiren cyber security CVE debrief
CVE-2026-54073 veracrypt CVE debrief
VeraCrypt disk encryption was found to have a weakness in file-hosted hidden volume creation, which could potentially weaken plausible deniability during forensic inspection. This issue has been fixed in version 1.26.29. The vulnerability allows attackers to exploit the predictable 128 MiB intervals of raw zeroed sectors, leaving deterministic plaintext markers that can weaken plausible deniability during forensic inspection. Defenders should assess exposure and verify their version to ensure the fix is applied.
- Vendor
- veracrypt
- Product
- Unknown
- CVSS
- MEDIUM 4.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-09-25
Who should care
Defenders responsible for VeraCrypt deployments, particularly those using hidden volumes, should assess exposure and verify their version to ensure the fix is applied. This includes reviewing hidden volume creation and forensic inspection procedures. Security teams and vulnerability management teams should prioritize verifying their VeraCrypt version and assessing exposure.
Why it matters
Defenders should prioritize verifying their VeraCrypt version and assessing exposure, with a focus on hidden volume creation and forensic inspection, due to the potential weakening of plausible deniability.
- Verification of VeraCrypt version and hidden volume creation procedures
- Assessment of forensic inspection procedures
- Potential weakening of plausible deniability
- Remediation priority for versions prior to 1.26.29
Technical summary
VeraCrypt file-hosted hidden volume creation forces quick format and uses WriteFile to place raw zeroed sectors at predictable 128 MiB intervals, leaving deterministic plaintext markers that can weaken plausible deniability during forensic inspection. The vulnerability was introduced in version 1.26.6 and fixed in version 1.26.29. The affected functions are FormatNoFs in src/Common/Format.c and FormatFat in src/Common/Fat.c. These functions bypass the normal EncryptDataUnits formatting path, resulting in deterministic plaintext markers.
Defensive priority
Defenders should prioritize verifying their VeraCrypt version and assessing exposure, with a focus on hidden volume creation and forensic inspection.
Recommended defensive actions
- Verify VeraCrypt version and assess exposure
- Review hidden volume creation and forensic inspection procedures
- Update to version 1.26.29 if necessary
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the VeraCrypt vulnerability, including its description and fixed version. The vulnerability was introduced in version 1.26.6 and fixed in version 1.26.29. The issue involves the FormatNoFs function in src/Common/Format.c and FormatFat function in src/Common/Fat.c using WriteFile to place raw zeroed sectors at predictable 128 MiB intervals. These writes bypass the normal EncryptDataUnits formatting path, leaving deterministic plaintext markers in an area expected to resemble random The N
Sources and references
Verified primary and authoritative sources
-
CVE-2026-54073 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-54073
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-54073 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-54073
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/veracrypt/VeraCrypt/commit/689a59cd584f090ca5f9214d5f2f3a9eac499e53
-
Source reference
Unverified legacy reference
URL: https://github.com/veracrypt/VeraCrypt/releases/tag/VeraCrypt_1.26.29
-
Source reference
Unverified legacy reference
URL: https://github.com/veracrypt/VeraCrypt/security/advisories/GHSA-jjcr-75w7-58jp
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.