VORANT. Threat Intelligence Sign in Get the full feed

OpenSSL DoS flaw awaits patch

routine vulnerability

A newly disclosed OpenSSL vulnerability allows remote attackers to trigger denial of service, and fixes are not yet available.

ANSSI/CERT-FR has issued an advisory for a remote denial-of-service vulnerability affecting OpenSSL, one of the most widely deployed cryptographic libraries underpinning TLS/SSL communications across countless applications and services. The flaw impacts OpenSSL versions 3.5.x prior to 3.5.8, 3.6.x prior to 3.6.4, and 4.0.x prior to 4.0.2.

Notably, the vendor has not yet released patches for this issue, leaving affected organizations without an immediate remediation path. Given OpenSSL's ubiquity in servers, network appliances, and applications handling encrypted traffic, the vulnerability could be leveraged to disrupt services relying on the library, though no active exploitation has been reported. Organizations should monitor the referenced OpenSSL security advisory for forthcoming patch availability and prepare to apply updates promptly once released.

Mentioned in this report

Vulnerabilities CVE-2026-14456

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1026

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free