CVE-2026-84256 is an OS command-injection vulnerability in OpenVPN on Windows versions 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6. The Windows command-line construction logic used by CreateProcess() quotes arguments containing spaces but fails to safely quote characters interpreted specially by cmd.exe, including command separators and redirection characters. When OpenVPN passes a certificate subject to a batch or command-script validation hook, such as a TLS verification hook, a crafted subject can be reinterpreted as additional commands.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows OpenVPN command-line quoting flaw involving cmd.exe special characters that can cause unintended behavior under specific validation-script and rogue-CA conditions.
A Windows OpenVPN command-line quoting flaw in CreateProcess() that can cause unexpected behavior when cmd.exe special characters are combined with a validation script and a rogue certificate authority.
A Windows OpenVPN argument-parsing vulnerability that permits remote authenticated command execution through a crafted certificate subject.
An OS command-injection vulnerability in OpenVPN for Windows. Insufficient quoting of cmd.exe metacharacters in wide_cmd_line() can allow a crafted X.509 certificate subject supplied to a hook script, such as --tls-verify, to execute an additional command through cmd.exe. It affects OpenVPN for Windows versions earlier than 2.6.14 and 2.7.5.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.