VORANT. Threat Intelligence Sign in Get the full feed

OpenSSL patches multiple DoS and bypass flaws

routine vulnerability technologyinfrastructure

ANSSI advisory details multiple OpenSSL vulnerabilities allowing remote denial of service and security policy bypass, patched in new releases.

ANSSI (CERT-FR) issued an advisory covering multiple vulnerabilities in OpenSSL affecting versions 1.0.2, 1.1.1, 3.0.x, 3.4.x, 3.5.x, 3.6.x, and 4.0.x prior to their respective patched releases. The vulnerabilities, tracked under nine separate CVEs, allow an attacker to trigger a remote denial of service condition or bypass security policy enforcement within affected OpenSSL implementations. No indication of active exploitation in the wild is provided in this advisory.

OpenSSL is a foundational cryptographic library used across a vast range of software, servers, and embedded systems, meaning these flaws have broad potential exposure across sectors relying on TLS/SSL communications. The OpenSSL project released a security advisory on 25 August 2026 with corresponding patches; ANSSI recommends organizations apply the vendor-provided fixes to the specified minimum versions (1.0.2zr, 1.1.1zi, 3.0.22, 3.4.7, 3.5.8, 3.6.4, 4.0.2) as soon as possible.

Given the ubiquity of OpenSSL in internet-facing and internal infrastructure, defenders should inventory affected versions across their environment, prioritize patching for internet-facing services, and monitor for anomalous connection failures or crashes that might indicate exploitation attempts against the denial-of-service vectors.

Mentioned in this report

Vulnerabilities CVE-2026-14457CVE-2026-18798CVE-2026-54874CVE-2026-63072CVE-2026-63073CVE-2026-63074CVE-2026-63075CVE-2026-63076CVE-2026-75803

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1079

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free