{"schema_version":1,"title":"Openbsd vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 11 vulnerabilities in Openbsd: 0 in the last 7 days and 1 in the last 90 days, 2 of them critical and 1 exploited in the wild. The most recent, CVE-2026-56101, was published on 8 September 2026.","url":"https://junglewise.ai/threats/technologies/openbsd","json_url":"https://junglewise.ai/threats/technologies/openbsd.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/openbsd","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":3,"all_time":11,"critical":2,"exploited":1,"last_7_days":0,"last_30_days":1,"last_90_days":1,"last_365_days":3},"latest":[{"cve":"CVE-2026-56101","cvss":5.3,"epss":0.0061,"slug":"cve-2026-56101-openbsd-tkip-mic-failure-countermeasure-inverted-comparison","title":"OpenBSD TKIP MIC-failure countermeasure inverted comparison","severity":"medium","exploited":false,"published_at":"2026-09-08T16:18:09.523+00:00","url":"https://junglewise.ai/threats/cve-2026-56101-openbsd-tkip-mic-failure-countermeasure-inverted-comparison"},{"cve":"CVE-2026-57589","cvss":7.4,"slug":"cve-2026-57589-openbsd-use-after-free-in-system-v-semaphore-implementation","title":"OpenBSD use-after-free in System V semaphore implementation","severity":"high","exploited":false,"published_at":"2026-06-25T01:16:26.537+00:00","url":"https://junglewise.ai/threats/cve-2026-57589-openbsd-use-after-free-in-system-v-semaphore-implementation"},{"cve":"CVE-2026-55706","cvss":5.8,"epss":0.0024,"slug":"cve-2026-55706-openbsd-auth-bypass-and-heap-over-read-in-sppp-pap-input","title":"OpenBSD auth bypass and heap over-read in sppp_pap_input","severity":"medium","exploited":false,"published_at":"2026-06-17T13:20:52.117+00:00","url":"https://junglewise.ai/threats/cve-2026-55706-openbsd-auth-bypass-and-heap-over-read-in-sppp-pap-input"},{"cve":"CVE-2020-7247","cvss":9.8,"slug":"cve-2020-7247-opensmtpd-remote-code-execution-vulnerability","title":"OpenSMTPD Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2022-03-25T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2020-7247-opensmtpd-remote-code-execution-vulnerability"},{"cve":"CVE-1999-0323","cvss":10,"slug":"cve-1999-0323-freebsd-and-netbsd-file-integrity-bypass-in-mmap-function","title":"FreeBSD and NetBSD file integrity bypass in mmap function","severity":"critical","exploited":false,"published_at":"1998-02-20T05:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0323-freebsd-and-netbsd-file-integrity-bypass-in-mmap-function"},{"cve":"CVE-1999-0304","cvss":7.2,"slug":"cve-1999-0304-bsd-mmap-memory-modification-via-kmem-devices","title":"BSD mmap memory modification via kmem devices","severity":"high","exploited":false,"published_at":"1998-02-01T05:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0304-bsd-mmap-memory-modification-via-kmem-devices"},{"cve":"CVE-1999-0305","cvss":5,"slug":"cve-1999-0305-bsd-sysctl-improper-restriction-of-source-routed-packets","title":"BSD sysctl improper restriction of source routed packets","severity":"medium","exploited":false,"published_at":"1998-02-01T05:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0305-bsd-sysctl-improper-restriction-of-source-routed-packets"},{"cve":"CVE-1999-0061","cvss":5.1,"slug":"cve-1999-0061-bsd-lpd-remote-command-execution-and-file-manipulation","title":"BSD lpd remote command execution and file manipulation","severity":"medium","exploited":false,"published_at":"1997-10-02T04:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0061-bsd-lpd-remote-command-execution-and-file-manipulation"},{"cve":"CVE-1999-1214","cvss":2.1,"slug":"cve-1999-1214-bsd-kernel-improper-credential-validation-in-asynchronous-i-o","title":"BSD Kernel Improper Credential Validation in Asynchronous I/O","severity":"low","exploited":false,"published_at":"1997-09-15T04:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-1214-bsd-kernel-improper-credential-validation-in-asynchronous-i-o"},{"cve":"CVE-1999-1225","cvss":5,"slug":"cve-1999-1225-linux-and-ultrix-information-disclosure-in-rpc-mountd","title":"Linux and Ultrix Information Disclosure in rpc.mountd","severity":"medium","exploited":false,"published_at":"1997-08-24T04:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-1225-linux-and-ultrix-information-disclosure-in-rpc-mountd"},{"cve":"CVE-1999-1296","cvss":7.2,"slug":"cve-1999-1296-mit-kerberos-buffer-overflow-in-kerberos-iv-compatibility-library","title":"MIT Kerberos buffer overflow in Kerberos IV compatibility library","severity":"high","exploited":false,"published_at":"1997-04-29T04:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-1296-mit-kerberos-buffer-overflow-in-kerberos-iv-compatibility-library"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"OpenBSD OpenSSH","slug":"openssh","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/openssh"}],"technology":{"hub":true,"name":"Openbsd","slug":"openbsd","vendor":{"name":"OpenBSD","slug":"openbsd","url":"https://junglewise.ai/threats/vendors/openbsd"},"aliases":[],"category":"operating-system","homepage":"https://www.openbsd.org/","repo_url":"https://github.com/openbsd/src","description":"OpenBSD is a free and open-source Unix-like operating system based on the Berkeley Software Distribution (BSD).","url":"https://junglewise.ai/threats/technologies/openbsd"},"most_severe":[{"cve":"CVE-2020-7247","cvss":9.8,"slug":"cve-2020-7247-opensmtpd-remote-code-execution-vulnerability","title":"OpenSMTPD Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2022-03-25T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2020-7247-opensmtpd-remote-code-execution-vulnerability"},{"cve":"CVE-1999-0323","cvss":10,"slug":"cve-1999-0323-freebsd-and-netbsd-file-integrity-bypass-in-mmap-function","title":"FreeBSD and NetBSD file integrity bypass in mmap function","severity":"critical","exploited":false,"published_at":"1998-02-20T05:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0323-freebsd-and-netbsd-file-integrity-bypass-in-mmap-function"},{"cve":"CVE-2026-57589","cvss":7.4,"slug":"cve-2026-57589-openbsd-use-after-free-in-system-v-semaphore-implementation","title":"OpenBSD use-after-free in System V semaphore implementation","severity":"high","exploited":false,"published_at":"2026-06-25T01:16:26.537+00:00","url":"https://junglewise.ai/threats/cve-2026-57589-openbsd-use-after-free-in-system-v-semaphore-implementation"},{"cve":"CVE-1999-0304","cvss":7.2,"slug":"cve-1999-0304-bsd-mmap-memory-modification-via-kmem-devices","title":"BSD mmap memory modification via kmem devices","severity":"high","exploited":false,"published_at":"1998-02-01T05:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0304-bsd-mmap-memory-modification-via-kmem-devices"},{"cve":"CVE-1999-1296","cvss":7.2,"slug":"cve-1999-1296-mit-kerberos-buffer-overflow-in-kerberos-iv-compatibility-library","title":"MIT Kerberos buffer overflow in Kerberos IV compatibility library","severity":"high","exploited":false,"published_at":"1997-04-29T04:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-1296-mit-kerberos-buffer-overflow-in-kerberos-iv-compatibility-library"},{"cve":"CVE-2026-55706","cvss":5.8,"epss":0.0024,"slug":"cve-2026-55706-openbsd-auth-bypass-and-heap-over-read-in-sppp-pap-input","title":"OpenBSD auth bypass and heap over-read in sppp_pap_input","severity":"medium","exploited":false,"published_at":"2026-06-17T13:20:52.117+00:00","url":"https://junglewise.ai/threats/cve-2026-55706-openbsd-auth-bypass-and-heap-over-read-in-sppp-pap-input"},{"cve":"CVE-2026-56101","cvss":5.3,"epss":0.0061,"slug":"cve-2026-56101-openbsd-tkip-mic-failure-countermeasure-inverted-comparison","title":"OpenBSD TKIP MIC-failure countermeasure inverted comparison","severity":"medium","exploited":false,"published_at":"2026-09-08T16:18:09.523+00:00","url":"https://junglewise.ai/threats/cve-2026-56101-openbsd-tkip-mic-failure-countermeasure-inverted-comparison"},{"cve":"CVE-1999-0061","cvss":5.1,"slug":"cve-1999-0061-bsd-lpd-remote-command-execution-and-file-manipulation","title":"BSD lpd remote command execution and file manipulation","severity":"medium","exploited":false,"published_at":"1997-10-02T04:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0061-bsd-lpd-remote-command-execution-and-file-manipulation"},{"cve":"CVE-1999-0305","cvss":5,"slug":"cve-1999-0305-bsd-sysctl-improper-restriction-of-source-routed-packets","title":"BSD sysctl improper restriction of source routed packets","severity":"medium","exploited":false,"published_at":"1998-02-01T05:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0305-bsd-sysctl-improper-restriction-of-source-routed-packets"},{"cve":"CVE-1999-1225","cvss":5,"slug":"cve-1999-1225-linux-and-ultrix-information-disclosure-in-rpc-mountd","title":"Linux and Ultrix Information Disclosure in rpc.mountd","severity":"medium","exploited":false,"published_at":"1997-08-24T04:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-1225-linux-and-ultrix-information-disclosure-in-rpc-mountd"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}