OpenSSL released fixes for CVE-2026-84782, a high-severity DTLS handshake retransmission flaw that can allow a connected peer to disclose adjacent heap memory in plaintext or crash an affected application. The out-of-bounds read occurs when retransmission starts while transmission of a fragmented handshake message is suspended, leaving OpenSSL with an incorrect buffer position. CISA assigned the issue a CVSS score of 8.2; no exploitation was known as of September 29, 2026, and OpenSSL has published no workaround.
Organizations should update to OpenSSL 4.0.3, 3.6.5, 3.5.9, or 3.4.8, or install their vendor’s corrected package. The flaw also affects 3.0, 1.1.1, and 1.0.2, but patches for those older branches require premium support. OpenSSL 3.0 reached public end of life on September 7, 2026 and no longer receives publicly available security fixes, increasing upgrade urgency; OpenSSL recommends moving to the 3.5 LTS release, supported through April 2030, or OpenSSL 4.0. The vulnerable DTLS logic lies outside the FIPS module boundary.

See affected versions and whether adversaries are exploiting it.
9 events from the most recent confirmed update back to the earliest known activity.
A vulnerability identified as CVE-2026-54873 was published affecting OpenSSL-related and associated platform packages on CentOS 7 and 8 and RHEL 7 through 10. The notice reported no known exploits and did not provide technical details or remediation guidance.
The September 29 OpenSSL releases also fixed CVE-2026-84783, a moderate-severity flaw that can crash certain multi-threaded TLS clients or servers requesting client certificates, and CVE-2026-75806, a low-severity DTLS 1.2 connection-termination issue.
Ubuntu fixed CVE-2026-84782 in libssl3t64 packages for Ubuntu 26.04 LTS and 24.04 LTS, and in libssl3 for Ubuntu 22.04 LTS. Ubuntu advised users to reboot after installing the updates.
CISA assigned CVE-2026-84782 a CVSS score of 8.2 and recorded no known exploitation at that time.
OpenSSL disclosed CVE-2026-84782, a high-severity DTLS out-of-bounds read that can expose adjacent heap memory to a connected peer or crash the process. It released public fixes in 4.0.3, 3.6.5, 3.5.9, and 3.4.8; fixes for 3.0, 1.1.1, and 1.0.2 were restricted to premium-support customers.
OpenSSL 3.0 reached end of life after its five-year LTS support period and stopped receiving publicly available security fixes. Extended paid support remained available.
Laurent Gaffie of Secorizon reported the DTLS retransmission vulnerability later assigned CVE-2026-84782 to OpenSSL. Ryan Hooper subsequently developed the correction.
OpenSSL released the 3.0 series as a long-term-support version, beginning its five-year public-support period.
Debian fixed CVE-2026-84782 in Debian 13 through openssl version 3.5.7-1~deb13u3, released as DSA-6531-1. Debian 12 remained listed as vulnerable as of September 30.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
mkd-cirt.mk
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcetenable.com
Open sourcetenable.com
Open sourceopenssl-library.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.