Skip to content
Threat Feed
medium advisory

OpenVPN Reliability Layer Vulnerability CVE-2026-84732

OpenVPN versions 2.6.22 and 2.7.6 and earlier contain a vulnerability in the reliability layer that can be triggered by unbounded TLS timeouts and acknowledgments for non-outstanding packets, potentially leading to denial-of-service.

CVE search metadata

CVE search record: CVE-2026-84732. EPSS: 0.54%. KEV: no. Product: OpenVPN (<= 2.6.22), OpenVPN (<= 2.7.6). Brief: OpenVPN Reliability Layer Vulnerability CVE-2026-84732. Brief link: https://feed.craftedsignal.io/briefs/2026-09-openvpn-vulnerability/

OpenVPN has disclosed a security vulnerability identified as CVE-2026-84732, affecting versions 2.6.22 and earlier, and 2.7.6 and earlier. The vulnerability exists within the software's reliability layer, specifically concerning how the application handles TLS timeouts and packet acknowledgments. By sending specially crafted traffic that exploits the lack of bounds on TLS timeouts or by forcing acknowledgments for packets that are not currently outstanding, an unauthenticated remote attacker could potentially trigger a denial-of-service (DoS) condition on the OpenVPN service. This issue is significant for organizations relying on OpenVPN for secure remote access and site-to-site connectivity, as exploitation could disrupt network infrastructure availability. Defenders should monitor vendor release channels for patches addressing this specific reliability layer defect.

Impact

The vulnerability poses a high risk of service disruption. Successful exploitation allows a remote, unauthenticated attacker to exhaust resources or destabilize the OpenVPN daemon, rendering the VPN tunnel unusable for legitimate users. This impacts organizations across all sectors utilizing OpenVPN for connectivity. If the service is a critical gateway, the resulting outage could cause widespread loss of remote access functionality.

Recommendation

Prioritized actions for security teams include:

  • Monitor the OpenVPN official security advisories for the release of patched versions addressing CVE-2026-84732.
  • Review network infrastructure logs for abnormal spikes in TLS handshake failures or malformed packet patterns targeting OpenVPN endpoints.
  • Patch all affected instances of OpenVPN to the latest available version once released by the vendor to mitigate the risk of denial-of-service.

Immediate actions

Monitor vendor advisories for specific version releases addressing CVE-2026-84732.

IT Operations 24h

Mitigations

Upgrade OpenVPN software to the fixed version once officially released by OpenVPN.

immediate IT Operations

CVE-2026-84732