Back Securityweek High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL
The developers of the OpenSSL and WolfSSL open source cryptographic libraries announced patches for roughly a dozen vulnerabilities each, including high-severity flaws.
Of the 14 vulnerabilities fixed in OpenSSL , one has been assigned a high severity rating. Tracked as CVE-2026-84782, it could allow a remote peer to obtain fragments of heap memory or crash applications that use Datagram TLS (DTLS), a protocol commonly found in VPNs, VoIP and IoT products.
The flaw is triggered during the DTLS handshake, when OpenSSL retransmits a message while sending another one is stalled. This can cause leftover heap data to be sent to the other party in plaintext. If the read reaches unmapped memory, the application crashes, resulting in a denial-of-service (DoS) condition.
The issue has a CVSS score of 8.2 and can be exploited over the network without authentication or user interaction.
The latest OpenSSL releases also fix a medium-severity vulnerability identified as CVE-2026-84783. A remote, unauthenticated peer could exploit the weakness to crash a multi-threaded TLS client and cause a DoS condition.
The remaining security holes have a low severity rating. They mostly lead to DoS conditions, caused by excessive memory or CPU consumption, process crashes, or the termination of DTLS 1.2 connections. The rest could let attackers abuse QUIC servers for DDoS amplification or exploit timing side channels to gather information that could lead to private key recovery.
WolfSSL security patches
WolfSSL developers released version 5.9.4 on September 25. In addition to new features, the latest version patches 11 vulnerabilities, including three classified as high severity.
The high-severity issues can allow attackers to bypass peer authentication in certain WolfSSL configurations.
CVE-2026-93302 exists because WolfSSL ignores the public key when matching a certificate against a trusted peer certificate. A malicious server that knows which CAs a client trusts can present a forged CA clone and bypass authentication. Affected builds include those created for integration with Nginx, HAProxy, Stunnel, Apache httpd, and other applications.
CVE-2026-89102 allows an attacker holding any certificate (and its private key) that chains to a CA trusted by the client to forge certificates for arbitrary identities. CVE-2026-89136 lets a malicious server bypass authentication on clients with Raw Public Key support enabled by selecting an RPK certificate type the client never requested.
Four medium-severity flaws involve certificate validation defects and a handshake sequencing error. They could allow attackers to bypass name constraints, plant an unverified CA in the shared certificate manager, or complete a TLS 1.2 or DTLS 1.2 handshake in place of the legitimate server and send data the client accepts as authentic.
The four low-severity bugs could lead to a use-after-free during connection shutdown, skipped CRL revocation checks, acceptance of certificates with invalid signatures, and server impersonation. Most require specific configurations or legacy API usage.
Related : OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability
Related : OpenSSL Patches High-Severity Vulnerability Found With AI
Related : Data Leakage Vulnerability Patched in OpenSSL
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
The extortion group has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273.
Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability
The company says the measure was precautionary and that it has no evidence of Kiteworks or customer systems being compromised.
Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug
Citrix has released patches for the critical NetScaler vulnerabilities tracked as CVE-2026-88771 and CVE-2026-88772.
Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28.
Artificial Intelligence
‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
Three vulnerabilities in Salesforce Agentforce allowed hackers to hijack trusted agents, steal data, and launch phishing attacks.
Roundcube Webmail Vulnerability in Attackers’ Crosshairs
Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication.
SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted
The vulnerabilities, tracked as CVE-2026-28324 and CVE-2026-28325, can be exploited without authentication.
Critical WordPress Vulnerability Exploited Immediately After Disclosure
Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
