The free software OpenSSL for SSL/TLS implementations is vulnerable. Most of the vulnerabilities now closed are classified as “ low ” threat. However, malware can also reach devices. So far, there are no indications of attacks. However, this can change at any time, so admins should not delay installing the repaired versions too long.
The developers list the security vulnerabilities in the security section of the OpenSSL website . Only one vulnerability (CVE-2026-45447) is classified as “ high ” threat. It is located in the PKCS7_verify() function .
Attackers can exploit this with a prepared PKCS#7 signature. During verification, a memory error (use-after-free) occurs, and malware can reach systems. The description of the vulnerability suggests that remote attacks are possible.
Furthermore, attackers can decrypt signed messages with an victim's RSA key (CVE-2026-42768 “ low ”). Replacing a root certificate by attackers is also conceivable (CVE-2026-42769 “ low ”).
The developers assure that the security vulnerabilities have been closed in the following versions:
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
