VORANT. Threat Intelligence Research Sign in Create a free account

CERT-FR Advisory: Multiple OpenSSL Vulnerabilities Patched

routine vulnerability technologyinfrastructure

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

CERT-FR issued an advisory on 14 OpenSSL CVEs affecting versions 1.0.2 through 4.0.x that can cause denial of service, data confidentiality and integrity breaches.

CERT-FR published an advisory referencing an OpenSSL security bulletin dated 29 September 2026, disclosing multiple vulnerabilities across several OpenSSL branches: 1.0.2x prior to 1.0.2zs, 1.1.1x prior to 1.1.1zj, 3.0.x prior to 3.0.23, 3.4.x prior to 3.4.8, 3.5.x prior to 3.5.9, 3.6.x prior to 3.6.5, and 4.0.x prior to 4.0.3. Fourteen CVEs are listed (CVE-2026-35189, -35191, -42772, -54872, -54873, -54875, -72897, -75804, -75805, -75806, -77696, -84782, -84783, -84784). The advisory summarizes the impact categories as remote denial of service, breach of data confidentiality, breach of data integrity, and security policy bypass, without providing per-CVE technical detail.

Given OpenSSL's ubiquity across servers, appliances, and embedded systems performing TLS/cryptographic operations, this advisory has broad applicability. No indication of active in-the-wild exploitation is given in the bulletin; it is a standard vendor-coordinated disclosure and patch release. Defenders should identify all systems and third-party products bundling the affected OpenSSL versions and prioritize patching based on internet-facing exposure and the specific CVEs applicable to their deployed branch, referring to the official OpenSSL security advisory for per-vulnerability technical details and applicability.

Recommended action is to upgrade to the fixed versions (1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, or 4.0.3 depending on branch) as soon as possible, and to inventory dependent applications/appliances that statically link or bundle OpenSSL, since patching the OS package alone will not remediate vendor products with embedded copies.

Mentioned in this report

Vulnerabilities CVE-2026-35189CVE-2026-35191CVE-2026-42772CVE-2026-54872CVE-2026-54873CVE-2026-54875CVE-2026-72897CVE-2026-75804CVE-2026-75805CVE-2026-75806CVE-2026-77696CVE-2026-84782CVE-2026-84783CVE-2026-84784

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1241

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 11,423 reports from 154 sources, 2,072 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs