OpenSSL 3.0 Reaches End of Life, Urgent Upgrade Recommended
Article Content
- •OpenSSL 3.0 reached EOL on September 7, 2026, and will not receive further updates.
- •Users are encouraged to upgrade to OpenSSL 4.0 or 3.5 for continued support.
- •Remaining FIPS 140-2 certificates for OpenSSL 3.0 will be moved to the Historical List on September 21, 2026.
OpenSSL 3.0 has officially reached its End of Life (EOL) as of September 7, 2026, and will no longer receive security fixes. Users of OpenSSL 3.0 are urged to upgrade to OpenSSL 4.0 or 3.5, both of which are currently supported. OpenSSL 4.0 will be supported until May 14, 2027, while OpenSSL 3.5 is a long-term support release until April 8, 2030. The transition is particularly for those relying on the OpenSSL FIPS Provider, as remaining FIPS 140-2 certificates for 3.0 will move to the CMVP Historical List on September 21, 2026. Organizations using the EOL version are advised to consider purchasing a support contract for extended security fixes beyond the public EOL date. Failure to upgrade may expose systems to vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track OpenSSL Corporation in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What should I upgrade to?
What happens if I continue using OpenSSL 3.0?
Is there extended support available?
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…