Critical Vulnerabilities in OpenSSL: CVE-2026-74880 and CVE-2026-74888

Critical Vulnerabilities in OpenSSL: CVE-2026-74880 and CVE-2026-74888

First seen 17 Aug 2026, 20:17 UTC Cvefeedwww.vulncheck.com 89% similarity 69.8

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities, CVE-2026-74880 and CVE-2026-74888, were published on August 17, 2026, affecting OpenSSL versions prior to 1.4.0. CVE-2026-74880 allows attackers to extract sensitive refresh tokens from URL query parameters, potentially leading to unauthorized access. CVE-2026-74888 involves a weak PBKDF2 key derivation method, making it easier for attackers to crack passwords protecting legacy encrypted files. No specific affected products have been listed yet. Both vulnerabilities are associated with significant weaknesses in cryptographic practices. Security professionals are urged to monitor for potential exploits and implement mitigations as they become available. The vulnerabilities have been documented on GitHub, indicating a risk of proof-of-concept exploits emerging soon.

Key Points: • CVE-2026-74880 exposes refresh tokens via URL query parameters, risking unauthorized access. • CVE-2026-74888 features a weak PBKDF2 key derivation method, making password cracking easier. • No specific affected products have been identified, but both vulnerabilities are critical.

ThreatCluster AI How this analysis works

Timeline

2026-08-17
CVE-2026-74880 published
CVE-2026-74880 disclosed, allowing token leakage via URL query parameters in OpenSSL versions before 1.4.0.
Cvefeed
2026-08-17
CVE-2026-74888 published
CVE-2026-74888 disclosed, involving a weak PBKDF2 key derivation method in OpenSSL versions before 1.4.0.
Cvefeed

Community

Browse all →