Back to advisories

High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL

OpenSSL and WolfSSL released patches for high-severity vulnerabilities affecting cryptographic operations. CVE-2026-84782 causes heap memory leaks and crashes in DTLS implementations; CVE-2026-93302 and related flaws bypass peer authentication in WolfSSL. Any environment running these libraries is at immediate risk of DoS, information disclosure, or authentication bypass.

HIGHAdvisorySep 30, 2026
Action required
Immediately identify all systems running OpenSSL and WolfSSL. Prioritize patching systems handling TLS/DTLS traffic or authentication. For unpatched systems, isolate or monitor for anomalous connection patterns and memory exhaustion events.
Affected products
OpenSSLWolfSSLNginx