# CERT-FR Advisory: Multiple OpenSSL Vulnerabilities Patched

Published: 2026-09-30 · Severity: routine · Sectors: technology, infrastructure
Canonical: https://vorant.io/reports/0d4340c8-393e-5316-ac1d-03e0ef82ea6c/cert-fr-advisory-multiple-openssl-vulnerabilities-patched

> CERT-FR issued an advisory on 14 OpenSSL CVEs affecting versions 1.0.2 through 4.0.x that can cause denial of service, data confidentiality and integrity breaches.

CERT-FR published an advisory referencing an OpenSSL security bulletin dated 29 September 2026, disclosing multiple vulnerabilities across several OpenSSL branches: 1.0.2x prior to 1.0.2zs, 1.1.1x prior to 1.1.1zj, 3.0.x prior to 3.0.23, 3.4.x prior to 3.4.8, 3.5.x prior to 3.5.9, 3.6.x prior to 3.6.5, and 4.0.x prior to 4.0.3. Fourteen CVEs are listed (CVE-2026-35189, -35191, -42772, -54872, -54873, -54875, -72897, -75804, -75805, -75806, -77696, -84782, -84783, -84784). The advisory summarizes the impact categories as remote denial of service, breach of data confidentiality, breach of data integrity, and security policy bypass, without providing per-CVE technical detail.

Given OpenSSL's ubiquity across servers, appliances, and embedded systems performing TLS/cryptographic operations, this advisory has broad applicability. No indication of active in-the-wild exploitation is given in the bulletin; it is a standard vendor-coordinated disclosure and patch release. Defenders should identify all systems and third-party products bundling the affected OpenSSL versions and prioritize patching based on internet-facing exposure and the specific CVEs applicable to their deployed branch, referring to the official OpenSSL security advisory for per-vulnerability technical details and applicability.

Recommended action is to upgrade to the fixed versions (1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, or 4.0.3 depending on branch) as soon as possible, and to inventory dependent applications/appliances that statically link or bundle OpenSSL, since patching the OS package alone will not remediate vendor products with embedded copies.

## Mentioned in this report

- Vulnerabilities: CVE-2026-35189, CVE-2026-35191, CVE-2026-42772, CVE-2026-54872, CVE-2026-54873, CVE-2026-54875, CVE-2026-72897, CVE-2026-75804, CVE-2026-75805, CVE-2026-75806, CVE-2026-77696, CVE-2026-84782, CVE-2026-84783, CVE-2026-84784

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1241

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/0d4340c8-393e-5316-ac1d-03e0ef82ea6c/cert-fr-advisory-multiple-openssl-vulnerabilities-patched.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
