Skip to content
OpenVPN Vulnerabilities Lead to Denial of Service Risks

OpenVPN Vulnerabilities Lead to Denial of Service Risks

First seen 30 Sep 2026, 21:37 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 30, 2026 at 22:31 UTC

On September 30, 2026, two vulnerabilities in OpenVPN were disclosed. The first, an use-after-free vulnerability in TLS session handling (CVE-2026-84471), could allow attackers to crash OpenVPN or execute arbitrary code. The second vulnerability (CVE-2026-84732) involves improper handling of ACK packet ID retransmissions, potentially leading to a timeout integer overflow and denial of service. These vulnerabilities affect multiple versions of OpenVPN across Ubuntu 26.04 LTS and earlier. Users are advised to update their systems to mitigate risks. A system restart is required after applying the updates. The vulnerabilities were published on September 7, 2026, with a CVSS score of 8.7, indicating a high severity level. No has been reported as of now.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-07
CVE-2026-84471 and CVE-2026-84732 published
OpenVPN vulnerabilities disclosed, allowing potential denial of service and code execution.
Ubuntu
2026-09-30
OpenVPN vulnerabilities disclosed
OpenVPN vulnerabilities detailed in security advisories, urging users to update systems.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track CVE-2026-84471 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which OpenVPN versions are affected?
OpenVPN versions included in Ubuntu 26.04 LTS and earlier are affected.
Is there any active exploitation of these vulnerabilities?
No active exploitation has been reported as of now.
What should users do to protect themselves?
Users should update their OpenVPN installations and restart the service to apply the fixes.