Critical OpenSSL Vulnerabilities Enable Remote Denial of Service Attacks

Critical OpenSSL Vulnerabilities Enable Remote Denial of Service Attacks

First seen 26 Aug 2026, 04:54 UTC UbuntuCybersecuritynews 68.0

Article Content

Browse articles
ThreatCluster

OpenSSL has disclosed multiple vulnerabilities affecting various versions of its cryptographic library, including OpenSSL 4.0, 3.6, 3.5, 3.4, and 3.0, as well as the legacy 1.1.1 line. The vulnerabilities include issues that could lead to denial of service (DoS) and heap buffer overflows. Specifically, CVE-2026-14456, CVE-2026-14457, and CVE-2026-18798 are notable for causing excessive resource usage or crashes in OpenSSL when handling QUIC packets and Raw Public Keys. Additionally, CVE-2026-63072 poses a risk of heap corruption. These vulnerabilities were published on August 25, 2026, and affect Ubuntu 26.04 LTS among other systems. Patching is critical as these issues could be exploited by remote attackers. The advisory emphasizes the urgency of applying the updates to mitigate potential attacks.

Key Points: • OpenSSL vulnerabilities could lead to remote denial of service attacks. • Affected versions include OpenSSL 4.0, 3.x, and legacy 1.1.1. • Patching is urgent following the August 25, 2026 disclosure.

Timeline

2026-08-13
CVE-2026-14456 published
OpenSSL disclosed a vulnerability affecting resource handling in QUIC server channels.
Ubuntu
2026-08-25
Multiple CVEs published
OpenSSL published several vulnerabilities including CVE-2026-14457 and CVE-2026-63072, affecting various versions.
Cybersecuritynews
2026-08-25
Patch released
OpenSSL released patches for the disclosed vulnerabilities, urging immediate updates.
Cybersecuritynews
2026-08-25
CVE-2026-75803 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-63072 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-14457 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-63073 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-63076 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-54874 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-63074 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE