OpenSSL disclosed a broad set of vulnerabilities affecting ASN.1 parsing, PKCS#12, CMS/PKCS#7, QUIC, OCSP, CMP/CRMF, DH key validation, AEAD cipher handling, and certificate and email validation across the 4.0, 3.6, 3.5, 3.4, and 3.0 branches. The most severe issue, CVE-2026-45447, is a high-severity heap use-after-free in PKCS7_verify() that can be triggered by specially crafted PKCS#7 or S/MIME signed messages and could lead to crashes, heap corruption, or potentially remote code execution.
The advisory also details moderate-severity flaws that could enable forged CMS AuthEnvelopedData messages, denial-of-service conditions in QUIC and OCSP processing, a TLS client double-free via OCSP stapling, a QUIC server NULL dereference, and cryptographic failures in AES-OCB when applications use the EVP_Cipher() one-shot API, alongside numerous lower-severity parsing, validation, and bounds-checking bugs. OpenSSL said most issues were fixed in 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21, with 1.1.1zh and 1.0.2zq issued for supported legacy customers; most flaws were reported as outside the OpenSSL FIPS module boundary, except CVE-2026-42770, which affects FIPS modules in multiple supported branches.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The advisory states that fixes were made available in OpenSSL 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21, with 1.1.1zh and 1.0.2zq also provided for older premium-support branches where applicable. OpenSSL recommended upgrading to these versions to address the disclosed flaws.
On 2026-06-09, OpenSSL published a security advisory covering numerous vulnerabilities across PKCS#7, CMS, QUIC, OCSP, ASN.1, PKCS#12, CMP/CRMF, DH key validation, AEAD cipher handling, and certificate/email validation. The most severe issue disclosed was CVE-2026-45447, a high-severity heap use-after-free in PKCS7_verify() that could lead to crashes, heap corruption, or potentially remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityonline.info
Open sourceopenssl-library.org
Open sourceseclists.org
Open sourcefreebsd.org
Open sourcecvefeed.io
Open sourceopenssl-library.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.