OpenSSL and WolfSSL have released patches for a combined 25 vulnerabilities, including multiple high-severity flaws that could enable memory disclosure, denial of service, and authentication bypass. The most serious issues affect DTLS, TLS, and certificate validation paths, putting VPNs, VoIP, IoT products, and software using Nginx, HAProxy, Stunnel, and Apache httpd at risk. #OpenSSL #WolfSSL #CVE-2026-84782 #CVE-2026-93302 #CVE-2026-89102 #CVE-2026-89136
Keypoints
- OpenSSL fixed 14 vulnerabilities, including CVE-2026-84782 with a high CVSS score of 8.2.
- CVE-2026-84782 can leak heap memory or crash DTLS applications during handshake retransmissions.
- OpenSSL also patched CVE-2026-84783, which can crash multi-threaded TLS clients.
- WolfSSL 5.9.4 fixes 11 vulnerabilities, including three high-severity authentication bypass flaws.
- The WolfSSL issues can affect builds used with Nginx, HAProxy, Stunnel, Apache httpd, and similar applications.
Read More: https://www.securityweek.com/high-severity-vulnerabilities-patched-in-openssl-wolfssl/