# OpenSSL patches multiple DoS and bypass flaws

Published: 2026-08-26 · Severity: routine · Sectors: technology, infrastructure
Canonical: https://vorant.io/reports/8d9ca3a9-26ef-55f1-9fbd-0d575152659d/openssl-patches-multiple-dos-and-bypass-flaws

> ANSSI advisory details multiple OpenSSL vulnerabilities allowing remote denial of service and security policy bypass, patched in new releases.

ANSSI (CERT-FR) issued an advisory covering multiple vulnerabilities in OpenSSL affecting versions 1.0.2, 1.1.1, 3.0.x, 3.4.x, 3.5.x, 3.6.x, and 4.0.x prior to their respective patched releases. The vulnerabilities, tracked under nine separate CVEs, allow an attacker to trigger a remote denial of service condition or bypass security policy enforcement within affected OpenSSL implementations. No indication of active exploitation in the wild is provided in this advisory.

OpenSSL is a foundational cryptographic library used across a vast range of software, servers, and embedded systems, meaning these flaws have broad potential exposure across sectors relying on TLS/SSL communications. The OpenSSL project released a security advisory on 25 August 2026 with corresponding patches; ANSSI recommends organizations apply the vendor-provided fixes to the specified minimum versions (1.0.2zr, 1.1.1zi, 3.0.22, 3.4.7, 3.5.8, 3.6.4, 4.0.2) as soon as possible.

Given the ubiquity of OpenSSL in internet-facing and internal infrastructure, defenders should inventory affected versions across their environment, prioritize patching for internet-facing services, and monitor for anomalous connection failures or crashes that might indicate exploitation attempts against the denial-of-service vectors.

## Mentioned in this report

- Vulnerabilities: CVE-2026-14457, CVE-2026-18798, CVE-2026-54874, CVE-2026-63072, CVE-2026-63073, CVE-2026-63074, CVE-2026-63075, CVE-2026-63076, CVE-2026-75803

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1079

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/8d9ca3a9-26ef-55f1-9fbd-0d575152659d/openssl-patches-multiple-dos-and-bypass-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
