Description:
OpenSSL has released 1.0.2zr, 1.1.1zi, 3.0.22, 3.4.7, 3.5.8, 3.6.4 and 4.0.2 to fix the vulnerabilities in various versions of OpenSSL. The details of the security update can be found at:
https://openssl-library.org/news/secadv/20260825.txt
Affected Systems:
- OpenSSL 1.0.2 prior to version 1.0.2zr
- OpenSSL 1.1.1 prior to version 1.1.1zi
- OpenSSL 3.0.0 prior to version 3.0.22
- OpenSSL 3.4.0 prior to version 3.4.7
- OpenSSL 3.5.0 prior to version 3.5.8
- OpenSSL 3.6.0 prior to version 3.6.4
- OpenSSL 4.0.0 prior to version 4.0.2
Impact:
Successful exploitation of the vulnerabilities could lead to denial of service or security restriction bypass on an affected system.
Recommendation:
Patches for affected software are available. System administrators of affected systems should follow the recommendations provided by the software vendor and take immediate actions to mitigate the risk.
More Information:
- https://openssl-library.org/news/secadv/20260825.txt
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14457
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18798
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54874
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63072 (to CVE-2026-63076)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-75803