Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
OpenSSL Vulnerabilities Pose Risks to Servers

OpenSSL Vulnerabilities Pose Risks to Servers

Posted on August 26, 2026 By CWS

OpenSSL has released a new security advisory detailing seven vulnerabilities in its cryptographic library. These issues range from a heap corruption bug to memory exhaustion vulnerabilities affecting its QUIC and DTLS implementations.

Impact on Popular OpenSSL Versions

The discovered vulnerabilities affect popular OpenSSL branches, including versions 4.0, 3.6, 3.5, 3.4, and 3.0. Some issues also extend to the older 1.1.1 line, making it crucial for organizations utilizing TLS, CMS, or CMP services to promptly apply patches.

The most critical flaw, identified as CVE-2026-63072 and rated as Moderate, is found in OpenSSL’s CMS decryption code. It arises from a mismatch in expected and actual output buffer sizes during key unwrapping, potentially allowing attackers to perform an 8-byte out-of-bounds heap write.

Details of Other Identified Flaws

Another Moderate-severity flaw, CVE-2026-63076, impacts the Certificate Management Protocol (CMP). This flaw is due to inadequate verification of a protection algorithm parameter, leading to the possibility of an invalid pointer dereference.

Several Low-severity vulnerabilities include CVE-2026-14457, which causes a null pointer dereference in TLS configurations using Raw Public Keys without certificates. Other issues involve excessive memory usage in DTLS (CVE-2026-54874) and untrusted sender validation in CMP responses (CVE-2026-63073).

Security Recommendations

OpenSSL has released patched versions for all affected branches: 4.0.2, 3.6.4, 3.5.8, 3.4.7, and 3.0.22. Additionally, premium support customers using versions 1.1.1 and 1.0.2 have received specific backports.

Given the widespread impact and the potential for remote exploitation, it is imperative for security teams to inventory their OpenSSL deployments. Immediate application of the relevant patches is advised to secure systems against potential attacks.

By prioritizing updates, organizations can mitigate risks associated with these vulnerabilities, ensuring the continued security and functionality of their server operations.

Cyber Security News Tags:CMP, CVE-2026-63072, Cybersecurity, DTLS, heap corruption, OpenSSL, security patches, server security, TLS, Vulnerabilities

Post navigation

Previous Post: CISA Alerts on Active Gitea Vulnerability Exploitation
Next Post: CoreRAT Malware Empowers Hackers with Full System Control

Related Posts

Auraboros RAT Unveiled: Live Surveillance and Data Theft Auraboros RAT Unveiled: Live Surveillance and Data Theft Cyber Security News
ChatGPT’s New Support for MCP Tools Let Attackers Exfiltrate All Private Details From Email ChatGPT’s New Support for MCP Tools Let Attackers Exfiltrate All Private Details From Email Cyber Security News
Windows Remote Desktop Services Vulnerability Let Attackers Escalate Privileges Windows Remote Desktop Services Vulnerability Let Attackers Escalate Privileges Cyber Security News
Lighthouse Studio RCE Vulnerability Let Attackers Gain Access to Hosting Servers Lighthouse Studio RCE Vulnerability Let Attackers Gain Access to Hosting Servers Cyber Security News
Anthropic Challenges U.S. ‘Supply Chain Risk’ Designation Anthropic Challenges U.S. ‘Supply Chain Risk’ Designation Cyber Security News
pgAdmin 4 Update: Security Enhancements and New Features pgAdmin 4 Update: Security Enhancements and New Features Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CoreRAT Malware Empowers Hackers with Full System Control
  • OpenSSL Vulnerabilities Pose Risks to Servers
  • CISA Alerts on Active Gitea Vulnerability Exploitation
  • Linux Celebrates 35 Years: From Hobby to Global Powerhouse
  • Security Flaw in Tata’s B2B Platform Exposed User Accounts

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CoreRAT Malware Empowers Hackers with Full System Control
  • OpenSSL Vulnerabilities Pose Risks to Servers
  • CISA Alerts on Active Gitea Vulnerability Exploitation
  • Linux Celebrates 35 Years: From Hobby to Global Powerhouse
  • Security Flaw in Tata’s B2B Platform Exposed User Accounts

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark