A critical vulnerability in FORT Validator can silently remove valid routes of a selected carrier from RPKI data, creating conditions for loss of connectivity or even aiding route. The issue is documented as CVE-2026-53499 and affects versions up to 1.6.7.

The vulnerability is in the way the validator processes RRDP, the protocol used to retrieve RPKI objects. According to the NVD, version 1.6.8 fixes the issue by rejecting snapshot and delta addresses that come from a different source.
See also: Research on attackers attempting BGP hijacks
What is the FORT Validator vulnerability?
FORT Validator is a Resource Public Key Infrastructure relying party , a tool that checks whether route announcements on the Internet are accompanied by a valid cryptographic authorization. The result of these checks, known as VRPs, is used by origin validation infrastructures to distinguish valid from suspect routes.
CVE -2026-53499 concerns an origin validation error in RRDP processing. A legitimate authorized CA, under the same Trust Anchor Locator as the victim, can reference the victim's public notification and snapshot addresses. This information is not secret; it can be found from the victim's certificate.
The attack does not require access to the victim's private key, publishing point, or resources. The attacker needs their own legitimate CA and the ability to publish a child certificate and a modified RRDP notification. Thus, the vulnerability is not a simple configuration error, but a problem with file origin control.

How can routing be affected?
The trick is triggered when the victim agent makes a regular post and increments the RRDP sequence number. FORT Validator deletes the victim's local workspace, but its cache may indicate that the required file has already been downloaded. The reconstruction attempt fails without necessarily displaying an explicit error.
The result is that the VRPs and other signed objects of that CA disappear from the output. Other CAs under the same TAL remain unaffected, which is why the attack is targeted. The GitHub security bulletin describes the scenario as a persistent, selective denial of service in the RRDP cache.
If the networks receiving the results implement a policy to reject routes without valid state, this can lead to a loss of reachability. In environments where routes from "unknown" origins are allowed, the absence of valid data can create an opportunity for route hijacking. NVD rates the vulnerability as 7.2, high, with an attack condition and need for privilege.
See also: Tools that enhance Internet routing security

The version that fixes the problem
Administrators using FORT Validator up to version 1.6.7 should plan to upgrade to version 1.6.8 or later. The fix rejects snapshot and delta addresses from different origins so that one CA cannot influence another CA's cache through a misleading report.
As a temporary measure, the project announcement suggests disabling HTTP/RRDP with the parameter --http.enabled=false, while keeping rsync enabled where available. This option is not equivalent to a full fix: in places where rsync support is not available, data may be out of date or unavailable.
After the upgrade, infrastructure managers should verify that RRDP updates complete normally and that the expected VRPs are returned by the validator. The absence of an error log is not sufficient as an indication of security, as this scenario can occur silently.
See also: New hacking techniques affecting network connections
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The issue is of particular importance for entities that rely on path origin validation because the attack targets data integrity, not just application availability. The SecNews technical team recommends immediately inventorying FORT Validator installations, upgrading to 1.6.8, and verifying the results after the change.
