TL;DR
OpenSSL fixed 14 OpenSSL vulnerabilities in a security advisory on September 29, 2026. One is rated High: a DTLS flaw that can leak heap memory to a peer or crash the process. The rest are one Moderate and twelve Low issues, mostly denial of service and timing side channels.
- Total: 14 CVEs
- Severity: 4 High · 3 Medium · 3 Low · 4 Unrated
- Actively exploited: None confirmed
- Highest severity: 8.2 (High · CVSSv3) — CVE-2026-84782
- Action: Apply the latest security updates now
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-84782 | 8.2 | CWE-125 | 4.0.3, 3.6.5, 3.5.9 (+4) | Not exploited |
| CVE-2026-84783 | 7.5 | CWE-416 | 4.0.3 | Not exploited |
| CVE-2026-72897 | 7.5 | CWE-787 | 4.0.3, 3.6.5, 3.5.9 (+1) | Not exploited |
| CVE-2026-84784 | 7.5 | CWE-770 | 4.0.3, 3.6.5, 3.5.9 (+1) | Not exploited |
| CVE-2026-75804 | 5.3 | CWE-770 | 4.0.3, 3.6.5, 3.5.9 (+1) | Not exploited |
| CVE-2026-75805 | 5.3 | CWE-476 | 4.0.3, 3.6.5, 3.5.9 (+2) | Not exploited |
| CVE-2026-75806 | 5.3 | CWE-1284 | 4.0.3, 3.6.5, 3.5.9 (+3) | Not exploited |
| CVE-2026-54872 | 3.7 | CWE-208 | 4.0.3, 3.6.5, 3.5.9 (+4) | Not exploited |
Why These OpenSSL Vulnerabilities Matter
OpenSSL underpins TLS across servers, network gear, and embedded devices. The High-severity bug reaches every supported branch, back to 1.0.2.
How the Attacks Work
CVE-2026-84782: DTLS Retransmit Reads Past the Buffer (High)
DTLS can pause a handshake write partway through when the transport is busy. If the retransmit timer fires during that pause, OpenSSL resent an earlier message from the wrong buffer position. That resend could run past the end of the buffer. According to the advisory, it “can disclose a heap memory to the peer as plaintext handshake data or cause a crash.” Laurent Gaffie reported the flaw.
CVE-2026-84783: X.509 Cache Use-After-Free (Moderate)
In OpenSSL 4.0, several threads could build the extension cache for a shared CA certificate at once. One thread could free data another was still reading. A remote peer could crash a multi-threaded TLS client, or a server that requests client certificates.
Low-Severity Fixes
Five Low issues hit the QUIC stack, mainly memory and CPU exhaustion plus an amplification-limit bug. Three are timing side channels in SM2 and generic-curve ECDSA signing. The NIST curves P-256, P-384, and P-521 are not affected. The rest cover crafted certificates, a CMP client crash, a short-record DTLS 1.2 teardown, and an SSL_CTX switching bug.
Affected Versions and Exploitation Status
CVE-2026-84782 affects OpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1, and 1.0.2. CVE-2026-84783 affects only 4.0. None of the issues touch the FIPS module. The advisory reports no exploitation in the wild, and no public proof-of-concept has been confirmed.
Patch and Mitigation Steps
Upgrade to OpenSSL 4.0.3, 3.6.5, 3.5.9, or 3.4.8. Premium support customers on older branches should move to 3.0.23, 1.1.1zj, or 1.0.2zs. Full details are in the OpenSSL security advisory for September 29, 2026. Prioritize DTLS and QUIC services, since most of these OpenSSL vulnerabilities target those protocols.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!