Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
OpenSSL Vulnerabilities Pose Risks to Servers

OpenSSL Vulnerabilities Pose Risks to Servers

Posted on August 26, 2026 By CWS

OpenSSL has released a new security advisory detailing seven vulnerabilities in its cryptographic library. These issues range from a heap corruption bug to memory exhaustion vulnerabilities affecting its QUIC and DTLS implementations.

Impact on Popular OpenSSL Versions

The discovered vulnerabilities affect popular OpenSSL branches, including versions 4.0, 3.6, 3.5, 3.4, and 3.0. Some issues also extend to the older 1.1.1 line, making it crucial for organizations utilizing TLS, CMS, or CMP services to promptly apply patches.

The most critical flaw, identified as CVE-2026-63072 and rated as Moderate, is found in OpenSSL’s CMS decryption code. It arises from a mismatch in expected and actual output buffer sizes during key unwrapping, potentially allowing attackers to perform an 8-byte out-of-bounds heap write.

Details of Other Identified Flaws

Another Moderate-severity flaw, CVE-2026-63076, impacts the Certificate Management Protocol (CMP). This flaw is due to inadequate verification of a protection algorithm parameter, leading to the possibility of an invalid pointer dereference.

Several Low-severity vulnerabilities include CVE-2026-14457, which causes a null pointer dereference in TLS configurations using Raw Public Keys without certificates. Other issues involve excessive memory usage in DTLS (CVE-2026-54874) and untrusted sender validation in CMP responses (CVE-2026-63073).

Security Recommendations

OpenSSL has released patched versions for all affected branches: 4.0.2, 3.6.4, 3.5.8, 3.4.7, and 3.0.22. Additionally, premium support customers using versions 1.1.1 and 1.0.2 have received specific backports.

Given the widespread impact and the potential for remote exploitation, it is imperative for security teams to inventory their OpenSSL deployments. Immediate application of the relevant patches is advised to secure systems against potential attacks.

By prioritizing updates, organizations can mitigate risks associated with these vulnerabilities, ensuring the continued security and functionality of their server operations.

Cyber Security News Tags:CMP, CVE-2026-63072, Cybersecurity, DTLS, heap corruption, OpenSSL, security patches, server security, TLS, Vulnerabilities

Post navigation

Previous Post: CISA Alerts on Active Gitea Vulnerability Exploitation
Next Post: CoreRAT Malware Empowers Hackers with Full System Control

Related Posts

Nginx 1.29.8 & FreeNginx Update Bolster Security Nginx 1.29.8 & FreeNginx Update Bolster Security Cyber Security News
Samsung Zero-Day Vulnerability Actively Exploited to Execute Remote Code Samsung Zero-Day Vulnerability Actively Exploited to Execute Remote Code Cyber Security News
Magento Vulnerability Exploited for Remote Code Execution Magento Vulnerability Exploited for Remote Code Execution Cyber Security News
Critical SAP S/4HANA Vulnerability Actively Exploited to Fully Compromise Your SAP System Critical SAP S/4HANA Vulnerability Actively Exploited to Fully Compromise Your SAP System Cyber Security News
AppGuard Critiques AI Defenses & Expands Insider Release AppGuard Critiques AI Defenses & Expands Insider Release Cyber Security News
MacOS Users Targeted by New Phishing Email Scam MacOS Users Targeted by New Phishing Email Scam Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Teams Restores Services After Outage
  • Gitea Vulnerability Exploited in Cryptojacking Attack
  • CoreRAT Malware Empowers Hackers with Full System Control
  • OpenSSL Vulnerabilities Pose Risks to Servers
  • CISA Alerts on Active Gitea Vulnerability Exploitation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Teams Restores Services After Outage
  • Gitea Vulnerability Exploited in Cryptojacking Attack
  • CoreRAT Malware Empowers Hackers with Full System Control
  • OpenSSL Vulnerabilities Pose Risks to Servers
  • CISA Alerts on Active Gitea Vulnerability Exploitation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark