Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

TrustAsia Pulls 143 Certificates Following Critical LiteSSL ACME Vulnerability

TrustAsia has revoked 143 SSL/TLS certificates due to a critical vulnerability identified in its LiteSSL ACME service.

TrustAsia has revoked 143 SSL/TLS certificates due to a critical vulnerability identified in its LiteSSL ACME service.

The vulnerability, disclosed on Tue, Jan 21, 2026, allowed the reuse of domain validation data across different ACME accounts, facilitating unauthorized certificate issuance for domains validated by other users.

This issue contravened the CA/Browser Forum Baseline Requirements, which require unique domain validation for each certificate issuance.

The vulnerability originated from a logic error in LiteSSL's ACME service handling of Authorization objects, failing to verify whether a Certificate Signing Request (CSR) came from the same ACME account that performed the initial validation.

Attackers were able to exploit this to obtain wildcard certificates for arbitrary domains without re-triggering DNS-01 challenges. Additionally, an excessively prolonged cache for DNS-01 validation challenges was discovered, extending the exploitation window.

Field Value

Certificate Authority TrustAsia

Affected Service LiteSSL ACME

Vulnerability Type Domain Validation Reuse / Authorization Bypass

Certificates Impacted 143 total (140 revoked, 3 previously revoked)

Issuance Period After Dec 29, 2025

TrustAsia has revoked 143 SSL/TLS certificates due to a critical vulnerability identified in its LiteSSL ACME service.
Vanessa Ray · Thehackingpost

Protocol ACME (DNS-01 challenge)

Following the confirmation of the vulnerability, TrustAsia suspended ACME issuance services and initiated system remediation. Code fixes were deployed, and 140 valid certificates were revoked, with three having been previously revoked.

All ACME Authorizations were reset from VALID to REVOKED status, requiring clients to perform re-validation before certificate issuance could resume.

TrustAsia will publish a Full Incident Report, detailing root cause analysis and the non-compliance start date.

Time (UTC+8) Event Details

14:55 Report Received Community report via V2EX flagged domain validation reuse issue

15:10 Preliminary Confirmation Issue confirmed; ACME issuance service suspended immediately

15:30 Scope Investigation Impact scope identified; certificate investigation began

15:33 Initial Revocation Two certificates from community report revoked

Advertisement

21:00 Code Fix Completed Fix validated successfully in test environment

21:21 Full Scope Identified All 143 affected certificates identified; batch revocation initiated

21:30 Revocation Completed 140 valid certificates revoked (3 previously revoked)

21:41 Production Deployment Patched code deployed to production environment

22:35 Authorization Reset All ACME Authorizations reset from VALID to REVOKED; re-validation requested

22:50 Internal Validation Production environment validation completed successfully

23:00 Service Restored External ACME issuance service fully restored

TrustAsia rapidly contained the vulnerability within 8 hours and fully remediated the service. Organizations that issued certificates via LiteSSL ACME between Dec 29, 2025, and Jan 21, 2026, should verify certificate status and prepare for potential re-issuance requirements.

This incident highlights the critical importance of proper account context validation in ACME implementations and the necessity of strict separation between user domains during certificate validation workflows.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories