Multiples vulnérabilités dans OpenSSL (26 août 2026)
Multiple vulnerabilities have been discovered in OpenSSL, allowing for denial of service attacks and policy bypasses. These vulnerabilities affect various OpenSSL versions and could be exploited by attackers. Users are advised to apply the security updates provided by the vendor.
A security advisory from CERT-FR details multiple vulnerabilities within the OpenSSL cryptographic library. These vulnerabilities could be exploited to cause a denial of service and to circumvent security policies. The advisory lists specific OpenSSL versions affected, including versions prior to 1.0.2zr, 1.1.1zi, 3.0.22, 3.4.7, 3.5.8, 3.6.4, and 4.0.2.
CERT-FR has provided a link to the OpenSSL security bulletin for August 25, 2026, which details the vulnerabilities and recommended solutions. The advisory includes a list of CVE identifiers, including CVE-2026-14457, CVE-2026-18798, CVE-2026-54874, CVE-2026-63072, CVE-2026-63073, CVE-2026-63074, and CVE-2026-63075.
Users are strongly encouraged to consult the linked bulletin for detailed information and to apply the necessary security updates promptly to mitigate these risks.