OpenVPN released version 2.7.7 to remediate seven vulnerabilities in its cross-platform reliability layer and Windows-specific components. The most broadly exposed issue, CVE-2026-84732, affects OpenVPN through versions 2.6.22 and 2.7.6: a remote unauthenticated attacker can send crafted ACK packet-ID retransmissions that cause a TLS reliability-layer timeout integer overflow and disrupt VPN service on Linux, macOS, and Windows.
Six additional flaws affect Windows deployments, including command-line quoting weaknesses, restricted configuration-path validation bypass, potential netsh.exe path abuse, permissive object ACLs enabling local cross-user denial of service, a buffer overread, and a one-byte buffer overflow. The update also adds Linux netlink-reply validation alongside networking, resource-use, and key-management improvements; organizations should prioritize upgrading OpenVPN clients and servers to 2.7.7.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-81830 was published as an unpatched vulnerability associated with Ubuntu OpenVPN packages across Ubuntu LTS releases 14.04 through 26.04. The Nessus record assigns it a CVSS v3.0 score of 9.8 for network-accessible exploitation without privileges or user interaction, while stating that no known exploits are available.
Fedora published advisory FEDORA-2026-17203fb331 for the OpenVPN package on Fedora 45. The patch and vulnerability publication dates are listed as September 7, 2026, and no known exploits are available.
Fedora published security advisory FEDORA:2026-725faae162 for the OpenVPN package on Fedora 44. The available advisory metadata does not specify the vulnerability, impact, CVE, or remediated package version.
OpenVPN received the CVE record for CVE-2026-84732 via security@openvpn.net. The flaw affects OpenVPN through versions 2.6.22 and 2.7.6 and can allow a remote unauthenticated attacker to cause denial of service with crafted ACK packet inputs.
OpenVPN released version 2.7.7, fixing seven vulnerabilities across its cross-platform TLS reliability layer and Windows components. The update addresses CVE-2026-84732, a remotely exploitable denial-of-service issue involving unbounded TLS timeouts and invalid ACK handling, along with six Windows-specific flaws including path validation bypass, netsh.exe path abuse, local denial of service, buffer overread, and buffer overflow issues.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcecyber.gc.ca
Open sourceacn.gov.it
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.