{"schema_version":1,"title":"OpenVPN vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 19 vulnerabilities in OpenVPN: 0 in the last 7 days and 17 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-84732, was published on 7 September 2026.","url":"https://junglewise.ai/threats/technologies/openvpn","json_url":"https://junglewise.ai/threats/technologies/openvpn.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/openvpn","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":19,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":8,"last_90_days":17,"last_365_days":19},"latest":[{"cve":"CVE-2026-84732","epss":0.0054,"slug":"cve-2026-84732-openvpn-ack-packet-retransmission-denial-of-service","title":"OpenVPN ACK packet retransmission denial of service","severity":"info","exploited":false,"published_at":"2026-09-07T09:17:16.84+00:00","url":"https://junglewise.ai/threats/cve-2026-84732-openvpn-ack-packet-retransmission-denial-of-service"},{"cve":"CVE-2026-84256","cvss":0,"epss":0.0038,"slug":"cve-2026-84256-openvpn-argument-parsing-vulnerability-on-windows","title":"OpenVPN argument parsing vulnerability on Windows","severity":"info","exploited":false,"published_at":"2026-09-07T08:17:13.777+00:00","url":"https://junglewise.ai/threats/cve-2026-84256-openvpn-argument-parsing-vulnerability-on-windows"},{"cve":"CVE-2026-84226","epss":0.0014,"slug":"cve-2026-84226-openvpn-binary-planting-on-windows","title":"OpenVPN binary planting on Windows","severity":"info","exploited":false,"published_at":"2026-09-07T08:17:13.653+00:00","url":"https://junglewise.ai/threats/cve-2026-84226-openvpn-binary-planting-on-windows"},{"cve":"CVE-2026-82312","epss":0.001,"slug":"cve-2026-82312-openvpn-denial-of-service-via-null-dacl-on-windows-ipc","title":"OpenVPN denial of service via NULL DACL on Windows IPC","severity":"info","exploited":false,"published_at":"2026-09-07T08:17:13.527+00:00","url":"https://junglewise.ai/threats/cve-2026-82312-openvpn-denial-of-service-via-null-dacl-on-windows-ipc"},{"cve":"CVE-2026-81830","epss":0.0015,"slug":"cve-2026-81830-openvpn-windows-interactive-service-path-validation-bypass","title":"OpenVPN Windows interactive service path validation bypass","severity":"info","exploited":false,"published_at":"2026-09-07T08:17:13.41+00:00","url":"https://junglewise.ai/threats/cve-2026-81830-openvpn-windows-interactive-service-path-validation-bypass"},{"cve":"CVE-2026-81738","epss":0.0033,"slug":"cve-2026-81738-openvpn-out-of-bounds-write-in-tap-windows6-driver","title":"OpenVPN out-of-bounds write in tap-windows6 driver","severity":"info","exploited":false,"published_at":"2026-09-07T08:17:13.27+00:00","url":"https://junglewise.ai/threats/cve-2026-81738-openvpn-out-of-bounds-write-in-tap-windows6-driver"},{"cve":"CVE-2026-78221","epss":0.0012,"slug":"cve-2026-78221-openvpn-windows-interactive-service-buffer-size-miscalculation","title":"OpenVPN Windows Interactive Service buffer size miscalculation","severity":"info","exploited":false,"published_at":"2026-09-07T08:17:12.813+00:00","url":"https://junglewise.ai/threats/cve-2026-78221-openvpn-windows-interactive-service-buffer-size-miscalculation"},{"cve":"CVE-2026-78043","epss":0.0017,"slug":"cve-2026-78043-openvpn-windows-interactive-service-configuration-bypass","title":"OpenVPN Windows Interactive Service configuration bypass","severity":"info","exploited":false,"published_at":"2026-09-07T08:17:12.637+00:00","url":"https://junglewise.ai/threats/cve-2026-78043-openvpn-windows-interactive-service-configuration-bypass"},{"cve":"CVE-2026-63650","epss":0.0036,"slug":"cve-2026-63650-openvpn-authentication-identity-lookup-bypass-in-mbedtls","title":"OpenVPN authentication identity lookup bypass in mbedTLS","severity":"info","exploited":false,"published_at":"2026-08-14T23:16:32.653+00:00","url":"https://junglewise.ai/threats/cve-2026-63650-openvpn-authentication-identity-lookup-bypass-in-mbedtls"},{"cve":"CVE-2026-63649","epss":0.0033,"slug":"cve-2026-63649-openvpn-windows-interactive-service-configuration-bypass","title":"OpenVPN Windows interactive service configuration bypass","severity":"info","exploited":false,"published_at":"2026-08-14T23:16:32.507+00:00","url":"https://junglewise.ai/threats/cve-2026-63649-openvpn-windows-interactive-service-configuration-bypass"},{"cve":"CVE-2026-13379","cvss":5.1,"slug":"cve-2026-13379-openvpn-windows-interactive-service-dns-pollution-and-denial-of","title":"OpenVPN Windows interactive service DNS pollution and denial of service","severity":"info","exploited":false,"published_at":"2026-07-30T17:16:28.707+00:00","url":"https://junglewise.ai/threats/cve-2026-13379-openvpn-windows-interactive-service-dns-pollution-and-denial-of"},{"cve":"CVE-2026-13117","cvss":6,"slug":"cve-2026-13117-openvpn-use-after-free-during-tls-session-promotion","title":"OpenVPN use-after-free during TLS session promotion","severity":"info","exploited":false,"published_at":"2026-07-30T17:16:28.58+00:00","url":"https://junglewise.ai/threats/cve-2026-13117-openvpn-use-after-free-during-tls-session-promotion"},{"cve":"CVE-2026-12996","cvss":6,"slug":"cve-2026-12996-openvpn-use-after-free-in-tls-session-handling","title":"OpenVPN use-after-free in TLS session handling","severity":"info","exploited":false,"published_at":"2026-07-30T17:16:28.45+00:00","url":"https://junglewise.ai/threats/cve-2026-12996-openvpn-use-after-free-in-tls-session-handling"},{"cve":"CVE-2026-12932","cvss":7.1,"slug":"cve-2026-12932-openvpn-memory-leak-in-tls-crypt-v2-client-key-extraction","title":"OpenVPN memory leak in tls-crypt-v2 client key extraction","severity":"info","exploited":false,"published_at":"2026-07-30T17:16:27.92+00:00","url":"https://junglewise.ai/threats/cve-2026-12932-openvpn-memory-leak-in-tls-crypt-v2-client-key-extraction"},{"cve":"CVE-2026-11771","cvss":7,"slug":"cve-2026-11771-openvpn-off-by-one-buffer-write-in-ntlm-proxy-authentication","title":"OpenVPN off-by-one buffer write in NTLM proxy authentication","severity":"info","exploited":false,"published_at":"2026-07-30T17:16:27.61+00:00","url":"https://junglewise.ai/threats/cve-2026-11771-openvpn-off-by-one-buffer-write-in-ntlm-proxy-authentication"},{"cve":"CVE-2026-13122","cvss":5.9,"slug":"cve-2026-13122-openvpn-reachable-assertion-denial-of-service-in-external-auth","title":"OpenVPN reachable assertion denial of service in external-auth","severity":"info","exploited":false,"published_at":"2026-07-06T16:16:28.677+00:00","url":"https://junglewise.ai/threats/cve-2026-13122-openvpn-reachable-assertion-denial-of-service-in-external-auth"},{"cve":"CVE-2026-13698","cvss":6,"slug":"cve-2026-13698-openvpn-memory-leak-in-tls-crypt-v2-handling","title":"OpenVPN memory leak in tls-crypt-v2 handling","severity":"info","exploited":false,"published_at":"2026-07-06T15:16:35.14+00:00","url":"https://junglewise.ai/threats/cve-2026-13698-openvpn-memory-leak-in-tls-crypt-v2-handling"},{"cve":"CVE-2026-40215","cvss":6.1,"slug":"cve-2026-40215-openvpn-race-condition-and-use-after-free-in-tls-session","title":"OpenVPN race condition and use-after-free in TLS session promotion","severity":"info","exploited":false,"published_at":"2026-06-08T21:16:45.453+00:00","url":"https://junglewise.ai/threats/cve-2026-40215-openvpn-race-condition-and-use-after-free-in-tls-session"},{"cve":"CVE-2026-35058","cvss":6.9,"slug":"cve-2026-35058-openvpn-denial-of-service-via-reachable-assertion-in-tls-crypt-v2","title":"OpenVPN denial of service via reachable assertion in tls-crypt-v2","severity":"info","exploited":false,"published_at":"2026-06-08T20:17:00.497+00:00","url":"https://junglewise.ai/threats/cve-2026-35058-openvpn-denial-of-service-via-reachable-assertion-in-tls-crypt-v2"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":8},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"OpenVPN","slug":"openvpn","vendor":{"name":"Openvpn","slug":"openvpn","url":"https://junglewise.ai/threats/vendors/openvpn"},"aliases":[],"category":"network-software","homepage":"https://openvpn.net/","repo_url":"https://github.com/OpenVPN/openvpn","description":"OpenVPN is an open-source software application that implements virtual private network (VPN) techniques for creating secure point-to-point or site-to-site connections.","url":"https://junglewise.ai/threats/technologies/openvpn"},"most_severe":[{"cve":"CVE-2026-12932","cvss":7.1,"slug":"cve-2026-12932-openvpn-memory-leak-in-tls-crypt-v2-client-key-extraction","title":"OpenVPN memory leak in tls-crypt-v2 client key extraction","severity":"info","exploited":false,"published_at":"2026-07-30T17:16:27.92+00:00","url":"https://junglewise.ai/threats/cve-2026-12932-openvpn-memory-leak-in-tls-crypt-v2-client-key-extraction"},{"cve":"CVE-2026-11771","cvss":7,"slug":"cve-2026-11771-openvpn-off-by-one-buffer-write-in-ntlm-proxy-authentication","title":"OpenVPN off-by-one buffer write in NTLM proxy authentication","severity":"info","exploited":false,"published_at":"2026-07-30T17:16:27.61+00:00","url":"https://junglewise.ai/threats/cve-2026-11771-openvpn-off-by-one-buffer-write-in-ntlm-proxy-authentication"},{"cve":"CVE-2026-35058","cvss":6.9,"slug":"cve-2026-35058-openvpn-denial-of-service-via-reachable-assertion-in-tls-crypt-v2","title":"OpenVPN denial of service via reachable assertion in tls-crypt-v2","severity":"info","exploited":false,"published_at":"2026-06-08T20:17:00.497+00:00","url":"https://junglewise.ai/threats/cve-2026-35058-openvpn-denial-of-service-via-reachable-assertion-in-tls-crypt-v2"},{"cve":"CVE-2026-40215","cvss":6.1,"slug":"cve-2026-40215-openvpn-race-condition-and-use-after-free-in-tls-session","title":"OpenVPN race condition and use-after-free in TLS session promotion","severity":"info","exploited":false,"published_at":"2026-06-08T21:16:45.453+00:00","url":"https://junglewise.ai/threats/cve-2026-40215-openvpn-race-condition-and-use-after-free-in-tls-session"},{"cve":"CVE-2026-13117","cvss":6,"slug":"cve-2026-13117-openvpn-use-after-free-during-tls-session-promotion","title":"OpenVPN use-after-free during TLS session promotion","severity":"info","exploited":false,"published_at":"2026-07-30T17:16:28.58+00:00","url":"https://junglewise.ai/threats/cve-2026-13117-openvpn-use-after-free-during-tls-session-promotion"},{"cve":"CVE-2026-12996","cvss":6,"slug":"cve-2026-12996-openvpn-use-after-free-in-tls-session-handling","title":"OpenVPN use-after-free in TLS session handling","severity":"info","exploited":false,"published_at":"2026-07-30T17:16:28.45+00:00","url":"https://junglewise.ai/threats/cve-2026-12996-openvpn-use-after-free-in-tls-session-handling"},{"cve":"CVE-2026-13698","cvss":6,"slug":"cve-2026-13698-openvpn-memory-leak-in-tls-crypt-v2-handling","title":"OpenVPN memory leak in tls-crypt-v2 handling","severity":"info","exploited":false,"published_at":"2026-07-06T15:16:35.14+00:00","url":"https://junglewise.ai/threats/cve-2026-13698-openvpn-memory-leak-in-tls-crypt-v2-handling"},{"cve":"CVE-2026-13122","cvss":5.9,"slug":"cve-2026-13122-openvpn-reachable-assertion-denial-of-service-in-external-auth","title":"OpenVPN reachable assertion denial of service in external-auth","severity":"info","exploited":false,"published_at":"2026-07-06T16:16:28.677+00:00","url":"https://junglewise.ai/threats/cve-2026-13122-openvpn-reachable-assertion-denial-of-service-in-external-auth"},{"cve":"CVE-2026-13379","cvss":5.1,"slug":"cve-2026-13379-openvpn-windows-interactive-service-dns-pollution-and-denial-of","title":"OpenVPN Windows interactive service DNS pollution and denial of service","severity":"info","exploited":false,"published_at":"2026-07-30T17:16:28.707+00:00","url":"https://junglewise.ai/threats/cve-2026-13379-openvpn-windows-interactive-service-dns-pollution-and-denial-of"},{"cve":"CVE-2026-84256","cvss":0,"epss":0.0038,"slug":"cve-2026-84256-openvpn-argument-parsing-vulnerability-on-windows","title":"OpenVPN argument parsing vulnerability on Windows","severity":"info","exploited":false,"published_at":"2026-09-07T08:17:13.777+00:00","url":"https://junglewise.ai/threats/cve-2026-84256-openvpn-argument-parsing-vulnerability-on-windows"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}