Linuxsecurity Critical pyOpenSSL Vulnerabilities Affect Ubuntu Users
Article Content
- •CVE-2026-27448 and CVE-2026-27459 affect Ubuntu 24.04 LTS and 25.10.
- •Exploiting these vulnerabilities can lead to denial of service or arbitrary code execution.
- •Users should update to the latest package versions to mitigate risks.
Two vulnerabilities were discovered in pyOpenSSL, affecting Ubuntu 24.04 LTS and 25.10. CVE-2026-27448 allows connections to be accepted after an exception in the tlsext_servername callback, contrary to expectations. CVE-2026-27459 involves improper handling of DTLS cookie generation, where attackers can exploit cookie values over 256 bytes to crash pyOpenSSL, leading to denial of service or potential arbitrary code execution. Both issues were published on 2026-03-17. The vulnerabilities primarily impact Ubuntu users, particularly those on the specified versions. A standard system update is recommended to mitigate these vulnerabilities. Ubuntu Pro offers extended security coverage for affected packages. Users are urged to update their systems to the latest package versions to ensure security.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Ubuntu and CVE-2026-27448 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…