Skip to content
ThreatCluster

OpenSSL 3.0 Reaches End of Life, Urgent Upgrade Recommended

First seen 30 Sep 2026, 17:30 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 30, 2026 at 21:38 UTC
  • •OpenSSL 3.0 reached EOL on September 7, 2026, and will not receive further updates.
  • •Users are encouraged to upgrade to OpenSSL 4.0 or 3.5 for continued support.
  • •Remaining FIPS 140-2 certificates for OpenSSL 3.0 will be moved to the Historical List on September 21, 2026.

OpenSSL 3.0 has officially reached its End of Life (EOL) as of September 7, 2026, and will no longer receive security fixes. Users of OpenSSL 3.0 are urged to upgrade to OpenSSL 4.0 or 3.5, both of which are currently supported. OpenSSL 4.0 will be supported until May 14, 2027, while OpenSSL 3.5 is a long-term support release until April 8, 2030. The transition is particularly for those relying on the OpenSSL FIPS Provider, as remaining FIPS 140-2 certificates for 3.0 will move to the CMVP Historical List on September 21, 2026. Organizations using the EOL version are advised to consider purchasing a support contract for extended security fixes beyond the public EOL date. Failure to upgrade may expose systems to vulnerabilities.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-07
OpenSSL 3.0 EOL declared
OpenSSL 3.0 reached its End of Life and will no longer receive security updates.
openssl-library.org
2026-09-21
FIPS 140-2 certificates moved
Remaining FIPS 140-2 certificates for OpenSSL 3.0 transitioned to the CMVP Historical List.
openssl-library.org

More articles in this cluster (2)

Following this threat?

Track OpenSSL Corporation in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What should I upgrade to?
Upgrade to OpenSSL 4.0 or 3.5 for continued support and security fixes.
What happens if I continue using OpenSSL 3.0?
Continuing to use OpenSSL 3.0 may expose your systems to unpatched vulnerabilities.
Is there extended support available?
Yes, organizations can purchase a support contract for extended security fixes beyond the public EOL date.