OpenSSL released fixes for eight Moderate- and Low-severity vulnerabilities across supported branches, affecting QUIC, CMS, CMP, DTLS, TLS Raw Public Key processing, and AEAD decryption. The most significant issues are a QUIC INITIAL-packet double free (CVE-2026-18798), a CMS key-unwrapping heap buffer overflow (CVE-2026-63072), and a CMP invalid-pointer dereference triggered through a crafted protectionAlg value (CVE-2026-63076). Most flaws can cause denial of service through crashes, heap corruption, or memory exhaustion.
Organizations should upgrade to OpenSSL 4.0.2, 3.6.4, 3.5.8, 3.4.7, or 3.0.22; premium-support customers using legacy branches should update to 1.1.1zi or 1.0.2zr where applicable. Affected releases include versions before those fixes across the 1.0.2, 1.1.1, 3.0, 3.4, 3.5, 3.6, and 4.0 branches. OpenSSL stated that none of the disclosed vulnerabilities affects its FIPS module, as the vulnerable paths are outside the FIPS boundary or involve non-FIPS-approved algorithms.

See real exploitation activity before you spend the cycle.
7 events from the most recent confirmed update back to the earliest known activity.
Debian issued DSA-6465-1 for Debian 13 (trixie), addressing ten OpenSSL vulnerabilities, including CVE-2026-54874 and CVE-2026-63072 through CVE-2026-63076. The issues were fixed in OpenSSL version 3.5.7-1~deb13u2, and administrators were advised to upgrade affected OpenSSL packages.
The Canadian Centre for Cyber Security published advisory AV26-846 concerning OpenSSL vulnerabilities affecting releases prior to 1.0.2zr, 1.1.1zi, 3.0.22, 3.4.7, 3.5.8, 3.6.4, and 4.0.2. It encouraged users and administrators to review OpenSSL vulnerability information and apply necessary updates.
The OpenSSL Software Foundation published the CVE-2026-54874 record, documenting that forged future-epoch DTLS records can cause vulnerable endpoints to retain approximately 16 KB buffers for up to 100 records per association. The record estimates roughly 1.7 MB retained memory per connection and a network-to-memory amplification factor of about 1200, enabling remote memory-exhaustion denial of service.
The OpenSSL Software Foundation published CVE-2026-63072, documenting a CWE-787 heap buffer overflow in CMS_decrypt() when AES-WRAP-PAD is selected. A crafted CMS message can cause a deterministic eight-byte zero write beyond a heap buffer, typically causing denial of service; OpenSSL fixed it by allocating the unwrap buffer for worst-case output size.
OpenSSL issued a security advisory disclosing eight Moderate- and Low-severity vulnerabilities affecting QUIC, CMS, CMP, DTLS, TLS Raw Public Key handling, and AEAD behavior. The advisory recommended upgrading to OpenSSL 4.0.2, 3.6.4, 3.5.8, 3.4.7, or 3.0.22, and to 1.1.1zi or 1.0.2zr for applicable premium-support customers.
OpenSSL committed a0c8ec5 to the openssl-3.0 branch to fix CVE-2026-63072 in CMS AES-WRAP-PAD unwrapping. The patch allocates the larger of the predicted output length and input length, preventing an integrity-failure path from causing an eight-byte out-of-bounds heap write.
Amazon Web Services reported CVE-2026-54874, a DTLS handshake resource-consumption vulnerability that can enable remote memory-exhaustion denial of service, to OpenSSL. Matt Caswell developed the fix.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
15 references tracked. Mallory keeps watching after this page renders.
gmcsirt.gm
Open sourcecybersecuritynews.com
Open sourcecirt.gy
Open sourcemalware.news
Open sourcetenable.com
Open sourcecve.org
Open sourcegithub.com
Open sourceopenssl-library.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.