{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/openssl-3.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-14457"},{"cvss":7.5,"id":"CVE-2026-18798"},{"cvss":7.5,"id":"CVE-2026-54874"},{"cvss":7.5,"id":"CVE-2026-63072"},{"id":"CVE-2026-63073"},{"cvss":5.9,"id":"CVE-2026-63074"},{"id":"CVE-2026-75803"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenSSL 1.0.2","OpenSSL 1.1.1","OpenSSL 3.0","OpenSSL 3.4","OpenSSL 3.5","OpenSSL 3.6","OpenSSL 4.0","OpenSSL"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["OpenSSL"],"content_html":"\u003cp\u003eThe OpenSSL project has released a security advisory addressing multiple vulnerabilities affecting several legacy and current versions of the OpenSSL cryptographic library. These vulnerabilities allow remote attackers to trigger denial of service (DoS) conditions or bypass established security policies. Affected branches include 1.0.2, 1.1.1, 3.0, 3.4, 3.5, 3.6, and 4.0. Given the ubiquity of OpenSSL in enterprise infrastructure, including web servers, load balancers, VPNs, and application runtimes, these vulnerabilities present a significant risk. Defenders should prioritize auditing systems for the specific vulnerable versions and applying the updates outlined in the OpenSSL security advisory dated August 25, 2026.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities could result in the disruption of services due to DoS or the potential bypass of security controls, such as cryptographic validation or authentication mechanisms. Given that OpenSSL is a foundational library, the impact of these vulnerabilities spans nearly all sectors that utilize secure communications and encryption.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all instances of OpenSSL within the environment, including those bundled with third-party applications, using software composition analysis (SCA) tools or file system inventory.\u003c/li\u003e\n\u003cli\u003eUpgrade all instances of OpenSSL to the patched versions as specified in the August 25, 2026, OpenSSL advisory: 1.0.2zr, 1.1.1zi, 3.0.22, 3.4.7, 3.5.8, 3.6.4, or 4.0.2.\u003c/li\u003e\n\u003cli\u003eMonitor vendor security portals for applications that depend on these affected OpenSSL versions to ensure timely updates are applied once they become available.\u003c/li\u003e\n\u003cli\u003ePrioritize patching of internet-facing services and critical security infrastructure.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-26T14:06:06Z","date_published":"2026-08-26T13:58:54Z","id":"https://feed.craftedsignal.io/briefs/2026-08-openssl-vulnerabilities/","summary":"Multiple vulnerabilities across several OpenSSL branches allow remote attackers to cause denial of service or bypass security policies.","title":"Multiple Vulnerabilities in OpenSSL","url":"https://feed.craftedsignal.io/briefs/2026-08-openssl-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - OpenSSL 3.4","version":"https://jsonfeed.org/version/1.1"}