Skip to content
Threat Feed
medium advisory

Multiple Vulnerabilities in OpenSSL

Multiple security flaws in various OpenSSL versions allow remote attackers to perform denial of service, compromise confidentiality, and breach data integrity.

CVE search metadata

CVE search record: CVE-2026-35189. Severity: medium. CVSS: 5.3. EPSS: 0.27%. KEV: no. Product: OpenSSL (1.0.2x < 1.0.2zs), OpenSSL (1.1.1x < 1.1.1zj), OpenSSL (3.0.x < 3.0.23), OpenSSL (3.4.x < 3.4.8), OpenSSL (3.5.x < 3.5.9), OpenSSL (3.6.x < 3.6.5), OpenSSL (4.0.x < 4.0.3), OpenSSL. Brief: Multiple Vulnerabilities in OpenSSL. Brief link: https://feed.craftedsignal.io/briefs/2026-09-openssl-vulnerabilities/

CVE search record: CVE-2026-75806. Severity: medium. CVSS: 5.3. EPSS: 0.39%. KEV: no. Product: OpenSSL (1.0.2x < 1.0.2zs), OpenSSL (1.1.1x < 1.1.1zj), OpenSSL (3.0.x < 3.0.23), OpenSSL (3.4.x < 3.4.8), OpenSSL (3.5.x < 3.5.9), OpenSSL (3.6.x < 3.6.5), OpenSSL (4.0.x < 4.0.3), OpenSSL. Brief: Multiple Vulnerabilities in OpenSSL. Brief link: https://feed.craftedsignal.io/briefs/2026-09-openssl-vulnerabilities/

CVE search record: CVE-2026-77696. Severity: low. CVSS: 3.7. EPSS: 0.24%. KEV: no. Product: OpenSSL (1.0.2x < 1.0.2zs), OpenSSL (1.1.1x < 1.1.1zj), OpenSSL (3.0.x < 3.0.23), OpenSSL (3.4.x < 3.4.8), OpenSSL (3.5.x < 3.5.9), OpenSSL (3.6.x < 3.6.5), OpenSSL (4.0.x < 4.0.3), OpenSSL. Brief: Multiple Vulnerabilities in OpenSSL. Brief link: https://feed.craftedsignal.io/briefs/2026-09-openssl-vulnerabilities/

CVE search record: CVE-2026-84782. Severity: high. CVSS: 8.2. EPSS: 0.39%. KEV: no. Product: OpenSSL (1.0.2x < 1.0.2zs), OpenSSL (1.1.1x < 1.1.1zj), OpenSSL (3.0.x < 3.0.23), OpenSSL (3.4.x < 3.4.8), OpenSSL (3.5.x < 3.5.9), OpenSSL (3.6.x < 3.6.5), OpenSSL (4.0.x < 4.0.3), OpenSSL. Brief: Multiple Vulnerabilities in OpenSSL. Brief link: https://feed.craftedsignal.io/briefs/2026-09-openssl-vulnerabilities/

CVE search record: CVE-2026-84783. Severity: high. CVSS: 7.5. EPSS: 0.23%. KEV: no. Product: OpenSSL (1.0.2x < 1.0.2zs), OpenSSL (1.1.1x < 1.1.1zj), OpenSSL (3.0.x < 3.0.23), OpenSSL (3.4.x < 3.4.8), OpenSSL (3.5.x < 3.5.9), OpenSSL (3.6.x < 3.6.5), OpenSSL (4.0.x < 4.0.3), OpenSSL. Brief: Multiple Vulnerabilities in OpenSSL. Brief link: https://feed.craftedsignal.io/briefs/2026-09-openssl-vulnerabilities/

What's new

  • 1. added CVE-2026-75806 Oct 1, 14:18 via cccs
  • 2. added CVE-2026-35189 +3 Sep 30, 16:25 via bsi

The OpenSSL project has released security advisories addressing multiple vulnerabilities across several versions of its library, ranging from legacy releases to current development branches. These vulnerabilities, identified as CVE-2026-35189, CVE-2026-35191, CVE-2026-42772, CVE-2026-54872, CVE-2026-54873, CVE-2026-54875, CVE-2026-72897, CVE-2026-75804, CVE-2026-75805, CVE-2026-75806, CVE-2026-77696, CVE-2026-84782, CVE-2026-84783, and CVE-2026-84784, enable a variety of attack vectors. Depending on the specific flaw, remote attackers may be able to induce denial-of-service conditions through resource exhaustion or crash-inducing malformed inputs, bypass security policies, or compromise the confidentiality and integrity of encrypted communications. Given the widespread use of OpenSSL in critical infrastructure, web servers, and distributed systems, these vulnerabilities pose a significant risk of service disruption and unauthorized data access across diverse enterprise environments.

Impact

Successful exploitation of these vulnerabilities can lead to full service downtime for applications relying on the vulnerable OpenSSL library, the exposure of sensitive session data or keys, and the potential for unauthorized manipulation of data flows. Due to the nature of cryptographic libraries, any service using these versions is potentially exposed. Organizations should prioritize updating affected software packages to the latest patched versions as detailed in the official OpenSSL security bulletin to mitigate these risks.

Recommendation

Prioritize the identification and patching of all instances of OpenSSL using the versions specified in the affected products list.

  • Perform an inventory of all systems to identify vulnerable OpenSSL versions using local package managers or binary scanners.
  • Apply the updates provided by your OS distribution or software vendor to the fixed versions listed in the official OpenSSL advisory.
  • Upgrade affected components to: OpenSSL 1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, or 4.0.3.
  • Monitor for increased error rates or unexpected service terminations in applications linked against OpenSSL, which may indicate exploitation attempts.

Immediate actions

Inventory all systems for vulnerable OpenSSL versions

Security Engineering 24h

Mitigations

Upgrade OpenSSL to the latest indicated patch versions

immediate IT Operations

CVE-2026-35189, CVE-2026-35191, CVE-2026-42772, CVE-2026-54872, CVE-2026-54873, CVE-2026-54875, CVE-2026-72897, CVE-2026-75804, CVE-2026-75805, CVE-2026-75806, CVE-2026-77696, CVE-2026-84782, CVE-2026-84783, CVE-2026-84784