Skip to content
OpenSSL: Prepared signature can pave way for malware

OpenSSL: Prepared signature can pave way for malware

Heise.De June 11, 2026

The free software OpenSSL for SSL/TLS implementations is vulnerable. Most of the vulnerabilities now closed are classified as “ low ” threat. However, malware can also reach devices. So far, there are no indications of attacks. However, this can change at any time, so admins should not delay installing the repaired versions too long.

The developers list the security vulnerabilities in the security section of the OpenSSL website . Only one vulnerability (CVE-2026-45447) is classified as “ high ” threat. It is located in the PKCS7_verify() function .

Attackers can exploit this with a prepared PKCS#7 signature. During verification, a memory error (use-after-free) occurs, and malware can reach systems. The description of the vulnerability suggests that remote attacks are possible.

Furthermore, attackers can decrypt signed messages with an victim's RSA key (CVE-2026-42768 “ low ”). Replacing a root certificate by attackers is also conceivable (CVE-2026-42769 “ low ”).

The developers assure that the security vulnerabilities have been closed in the following versions:

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.

Extracted Entities

Attack Types (1)

CWE Weaknesses (1)

Domains (1)