CVE-2026-84226 is a CWE-426 untrusted search path vulnerability in the Windows tapctl utility shipped with OpenVPN. In affected releases, tapctl starts netsh through CreateProcess() with a NULL application name and without an absolute executable path. Windows therefore resolves the executable using its search path rather than explicitly invoking the trusted system copy. A local authenticated attacker able to place a malicious executable named netsh.exe in a directory searched before the Windows system directory can cause it to run when tapctl performs network-adapter renaming or other network-configuration operations. Affected versions are OpenVPN 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows OpenVPN tapctl flaw caused by invoking netsh.exe without an absolute path, enabling potential binary hijacking or path abuse.
A Windows OpenVPN tapctl utility flaw in which netsh.exe is invoked without a fully qualified path, creating potential binary hijacking or path-abuse risk.
A binary planting vulnerability in OpenVPN for Windows that allows a local authenticated user to conduct an attack during network-configuration operations.
A Windows binary-planting vulnerability in OpenVPN that permits a locally authenticated user to compromise confidentiality, integrity, and availability during network-configuration operations.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.