Product
high
advisory
Arbitrary Code Execution in openssl-encrypt via Symlink Following
3 TTPs 1 CVEThe openssl-encrypt Python package before version 1.4.9 is vulnerable to a symlink-following flaw in its verify-usb functionality, allowing attackers with physical access to removable drives to achieve arbitrary code execution via crafted __pycache__ files.
openssl-encrypt +3
supply-chain
code-execution
python
3t
1c
critical
threat
CVE-2026-81702 Key Substitution in openssl_encrypt
1 TTP 1 CVEThe openssl_encrypt library before 1.4.9 is vulnerable to key substitution attacks due to improper fingerprint validation when loading identities from local identity.json files.
exploited
openssl_encrypt +2
cryptographic-vulnerability
credential-theft
cve-2026-81689
vulnerability
cryptography
denial-of-service
cve-2026-81699
1t
1c