| 2026-09-21 | Critical | Eijen hash-09 | Symmetric (sponge, Sponge-F) | Trivial collisions in all Eijen implementations |
| 2026-09-21 | Critical | MasterCube hash-17 | Symmetric (sponge, AndRX permutation) | Trivial collisions at every rate boundary |
| 2026-09-21 | Critical | Aigis-Enc+ kem-01 | Lattice (Module-LWE) | Ineffective implicit rejection breaks IND-CCA security |
| 2026-09-21 | Critical | CheetahKEM kem-09 | Lattice (Ring/Module-LWE) | Partial rejection mask leaks the candidate shared secret |
| 2026-09-21 | Critical | HEP-QC kem-17 | Code-based (quasi-cyclic) | Publicly reproducible secret keys |
| 2026-09-21 | Critical | LoongKEM kem-18 | Lattice (LWE) | Partial rejection mask leaks the candidate shared secret |
| 2026-09-21 | Critical | Polar-KEM kem-29 | Lattice (polar-code-defined) | The submission ships a complete public-key-only break |
| 2026-09-21 | Critical | AFS-KEX kex-02 | Lattice (Module-LWE AKE) | The ephemeral key is generated once as long-term state |
| 2026-09-21 | Critical | CreTAKE kex-03 | Lattice (composite AKE: KEM + signature) | Bits-versus-bytes error reduces the ephemeral secret to 64 bits |
| 2026-09-21 | Critical | CEDRUS+C sign-03 | Hash-based (stateless) | Hypertree index collapse causes repeated few-time keys |
| 2026-09-21 | Critical | Galas sign-12 | Symmetric (MPC/VOLE-in-the-Head) | Publicly reproducible signing keys |
| 2026-09-21 | Critical | MORNING-ATLAS sign-15 | Lattice (Module-LWR, Fiat-Shamir) | Returned-length error causes an out-of-bounds heap disclosure |
| 2026-09-21 | Critical | MORNING-ATLAS sign-15 | Lattice (Module-LWR, Fiat-Shamir) | Trivial hint-padding malleability violates SUF-CMA |
| 2026-09-21 | Critical | SQIsign2D2 sign-25 | Isogeny | Verifier accepts modified messages and an all-zero signature |
| 2026-09-21 | Critical | UVW sign-32 | Multivariate (F3) | Every signature is accepted |
| 2026-09-21 | Critical | VDOO sign-33 | Multivariate (UOV family) | Publicly reproducible signing keys |
| 2026-09-21 | High | CHAMP hash-04 | Symmetric (Cayley graph / matrix products) | Fixed-length outputs occupy only one determinant fiber |
| 2026-09-21 | High | CHAMP hash-04 | Symmetric (Cayley graph / matrix products) | Projective positive-word collision lead for CHAMP-512 |
| 2026-09-21 | High | MEGASCON hash-18 | Symmetric (sponge) | The 384-bit digest is a prefix of the 512-bit digest |
| 2026-09-21 | High | MOZI hash-20 | Symmetric (sponge) | The 384-bit digest is a prefix of the 512-bit digest |
| 2026-09-21 | High | MORNING-Scabbard kem-24 | Lattice (Module-LWR) | Encryption omits the specified rounding constant |
| 2026-09-21 | High | QCTM kem-32 | Code-based (quasi-cyclic twisted McEliece) | Debug path retains the secret error vector |
| 2026-09-21 | High | WeaverKEM kem-39 | Lattice (Module-LWR) | PRF substream reuse violates the IND-CPA proof's independence premise |
| 2026-09-21 | High | NEV-AKE kex-07 | Lattice (NTRU/Ring-LWE AKE) | Both party identities are hard-wired to zero |
| 2026-09-21 | High | Aigis-Sig+ sign-01 | Lattice (Module-LWE/SIS, Fiat-Shamir) | Trivial signature malleability violates SUF-CMA |
| 2026-09-21 | High | CS sign-07 | Lattice (Module-LWE, Fiat-Shamir) | Trivial signature malleability violates SUF-CMA |