Critical Vulnerabilities Patched in OpenSSL and WolfSSL Libraries
A wave of high-severity vulnerabilities has been patched in the widely-used OpenSSL and WolfSSL open source cryptographic libraries. The fixes address a total of 25 security holes, including one critical flaw that could allow attackers to intercept sensitive data or crash applications. Developers are urged to update their systems as soon as possible to prevent potential exploitation.
The most severe vulnerability, tracked as CVE-2026-84782, affects OpenSSL and has a CVSS score of 8.2. It can be exploited remotely without authentication or user interaction, allowing an attacker to obtain fragments of heap memory or crash applications that use Datagram TLS (DTLS). This protocol is commonly found in VPNs, VoIP, and IoT products.
The issue arises during the DTLS handshake when OpenSSL retransmits a message while another one is stalled. As a result, leftover heap data is sent to the other party in plaintext. If the read reaches unmapped memory, the application crashes, resulting in a denial-of-service (DoS) condition. This flaw has significant implications for organizations relying on DTLS-protected communication.
The latest OpenSSL releases also fix a medium-severity vulnerability identified as CVE-2026-84783. A remote, unauthenticated peer could exploit this weakness to crash a multi-threaded TLS client and cause a DoS condition. While the remaining security holes have a low severity rating, they can still lead to issues such as excessive memory or CPU consumption, process crashes, or termination of DTLS 1.2 connections.
WolfSSL developers released version 5.9.4 on September 25, which patches 11 vulnerabilities, including three classified as high severity. The critical flaws in WolfSSL allow attackers to bypass peer authentication in certain configurations. CVE-2026-93302 exists because WolfSSL ignores the public key when matching a certificate against a trusted peer certificate. This can be exploited by a malicious server presenting a forged CA clone and bypassing authentication.
Developers of applications that integrate with Nginx, HAProxy, Stunnel, Apache httpd, and other systems should ensure they have updated to the latest WolfSSL version to prevent potential exploitation. Organizations relying on these cryptographic libraries are advised to review their configurations and update their systems as soon as possible to mitigate the risks associated with these vulnerabilities.
The patching of these critical flaws serves as a reminder for developers and organizations to stay up-to-date with security patches and updates. Failing to do so can lead to significant security breaches, highlighting the importance of maintaining secure cryptographic libraries in modern software development.
Source: SecurityWeek — 2026-09-30