High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL
OpenSSL and WolfSSL patch multiple high-severity vulnerabilities.
Summary
OpenSSL and WolfSSL have released patches for numerous vulnerabilities, including several high-severity flaws. OpenSSL's critical CVE-2026-84782 could lead to heap memory leaks or application crashes in DTLS, while WolfSSL's CVE-2026-93302 and others allow for peer authentication bypasses in specific configurations.
Full text
The developers of the OpenSSL and WolfSSL open source cryptographic libraries announced patches for roughly a dozen vulnerabilities each, including high-severity flaws. Of the 14 vulnerabilities fixed in OpenSSL, one has been assigned a high severity rating. Tracked as CVE-2026-84782, it could allow a remote peer to obtain fragments of heap memory or crash applications that use Datagram TLS (DTLS), a protocol commonly found in VPNs, VoIP and IoT products. The flaw is triggered during the DTLS handshake, when OpenSSL retransmits a message while sending another one is stalled. This can cause leftover heap data to be sent to the other party in plaintext. If the read reaches unmapped memory, the application crashes, resulting in a denial-of-service (DoS) condition. The issue has a CVSS score of 8.2 and can be exploited over the network without authentication or user interaction. The latest OpenSSL releases also fix a medium-severity vulnerability identified as CVE-2026-84783. A remote, unauthenticated peer could exploit the weakness to crash a multi-threaded TLS client and cause a DoS condition. The remaining security holes have a low severity rating. They mostly lead to DoS conditions, caused by excessive memory or CPU consumption, process crashes, or the termination of DTLS 1.2 connections. The rest could let attackers abuse QUIC servers for DDoS amplification or exploit timing side channels to gather information that could lead to private key recovery.Advertisement. Scroll to continue reading. WolfSSL security patches WolfSSL developers released version 5.9.4 on September 25. In addition to new features, the latest version patches 11 vulnerabilities, including three classified as high severity. The high-severity issues can allow attackers to bypass peer authentication in certain WolfSSL configurations. CVE-2026-93302 exists because WolfSSL ignores the public key when matching a certificate against a trusted peer certificate. A malicious server that knows which CAs a client trusts can present a forged CA clone and bypass authentication. Affected builds include those created for integration with Nginx, HAProxy, Stunnel, Apache httpd, and other applications. CVE-2026-89102 allows an attacker holding any certificate (and its private key) that chains to a CA trusted by the client to forge certificates for arbitrary identities. CVE-2026-89136 lets a malicious server bypass authentication on clients with Raw Public Key support enabled by selecting an RPK certificate type the client never requested. Four medium-severity flaws involve certificate validation defects and a handshake sequencing error. They could allow attackers to bypass name constraints, plant an unverified CA in the shared certificate manager, or complete a TLS 1.2 or DTLS 1.2 handshake in place of the legitimate server and send data the client accepts as authentic. The four low-severity bugs could lead to a use-after-free during connection shutdown, skipped CRL revocation checks, acceptance of certificates with invalid signatures, and server impersonation. Most require specific configurations or legacy API usage. Related: OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Related: OpenSSL Patches High-Severity Vulnerability Found With AI Related: Data Leakage Vulnerability Patched in OpenSSL Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier TrainingApple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’ Nvidia Unveils AI Agent Safety Platform With Hardware-Based WatchdogCitrix Confirms 2 NetScaler Zero-Days After Admins Pulled the PlugMicrosoft SharePoint Flaw CVE-2026-65660 Now Exploited in AttacksNorth Korea Suspected in $351 Million Bitget Crypto HeistCISA Election Security Plan Flags Patching Barriers, Voter Database AttacksWindows, Linux, Android File Notification Systems Leak User Activity Latest News Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI DevelopmentOpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer ConferenceDARPA Selects Xint to Use AI in Securing Military Messaging AppsNew Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data LeaksRemoteThreat Launches With $7 Million for Offensive Operations PlatformReco Raises $55 Million for Agentic SecurityHackers Use ChatGPT Custom GPTs in ClickFix AttacksPentagon Personnel Agency Data Breach Impacts 3 Million People Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveSherman Chu joined The Port Authority of New York & New Jersey as CISO.Doppel has named Joey Rachid as Chief Security Advisor and Field Chief Information Security Officer.Delinea has appointed Timothy Regan as Chief Financial Officer.More People On The MoveExpert Insights Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- cve — CVE-2026-84782
- cve — CVE-2026-84783
- cve — CVE-2026-93302
- cve — CVE-2026-89102
- cve — CVE-2026-89136