{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/openssl-4.0.x--4.0.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":5.3,"id":"CVE-2026-35189"},{"cvss":5.3,"id":"CVE-2026-75806"},{"cvss":3.7,"id":"CVE-2026-77696"},{"cvss":8.2,"id":"CVE-2026-84782"},{"cvss":7.5,"id":"CVE-2026-84783"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenSSL (1.0.2x \u003c 1.0.2zs)","OpenSSL (1.1.1x \u003c 1.1.1zj)","OpenSSL (3.0.x \u003c 3.0.23)","OpenSSL (3.4.x \u003c 3.4.8)","OpenSSL (3.5.x \u003c 3.5.9)","OpenSSL (3.6.x \u003c 3.6.5)","OpenSSL (4.0.x \u003c 4.0.3)","OpenSSL"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","openssl","patch-management"],"_cs_type":"advisory","_cs_vendors":["OpenSSL"],"content_html":"\u003cp\u003eThe OpenSSL project has released security advisories addressing multiple vulnerabilities across several versions of its library, ranging from legacy releases to current development branches. These vulnerabilities, identified as CVE-2026-35189, CVE-2026-35191, CVE-2026-42772, CVE-2026-54872, CVE-2026-54873, CVE-2026-54875, CVE-2026-72897, CVE-2026-75804, CVE-2026-75805, CVE-2026-75806, CVE-2026-77696, CVE-2026-84782, CVE-2026-84783, and CVE-2026-84784, enable a variety of attack vectors. Depending on the specific flaw, remote attackers may be able to induce denial-of-service conditions through resource exhaustion or crash-inducing malformed inputs, bypass security policies, or compromise the confidentiality and integrity of encrypted communications. Given the widespread use of OpenSSL in critical infrastructure, web servers, and distributed systems, these vulnerabilities pose a significant risk of service disruption and unauthorized data access across diverse enterprise environments.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities can lead to full service downtime for applications relying on the vulnerable OpenSSL library, the exposure of sensitive session data or keys, and the potential for unauthorized manipulation of data flows. Due to the nature of cryptographic libraries, any service using these versions is potentially exposed. Organizations should prioritize updating affected software packages to the latest patched versions as detailed in the official OpenSSL security bulletin to mitigate these risks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification and patching of all instances of OpenSSL using the versions specified in the affected products list.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePerform an inventory of all systems to identify vulnerable OpenSSL versions using local package managers or binary scanners.\u003c/li\u003e\n\u003cli\u003eApply the updates provided by your OS distribution or software vendor to the fixed versions listed in the official OpenSSL advisory.\u003c/li\u003e\n\u003cli\u003eUpgrade affected components to: OpenSSL 1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, or 4.0.3.\u003c/li\u003e\n\u003cli\u003eMonitor for increased error rates or unexpected service terminations in applications linked against OpenSSL, which may indicate exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T14:18:09Z","date_published":"2026-09-30T16:19:31Z","id":"https://feed.craftedsignal.io/briefs/2026-09-openssl-vulnerabilities/","summary":"Multiple security flaws in various OpenSSL versions allow remote attackers to perform denial of service, compromise confidentiality, and breach data integrity.","title":"Multiple Vulnerabilities in OpenSSL","url":"https://feed.craftedsignal.io/briefs/2026-09-openssl-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - OpenSSL (4.0.x \u003c 4.0.3)","version":"https://jsonfeed.org/version/1.1"}