{"schema_version":1,"title":"Openvpn vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 15 vulnerabilities in Openvpn: 0 in the last 7 days and 14 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-82325, was published on 7 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/openvpn","json_url":"https://junglewise.ai/threats/vendors/openvpn.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/openvpn","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":0,"all_time":15,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":9,"last_90_days":14,"last_365_days":15},"latest":[{"cve":"CVE-2026-82325","epss":0.0014,"slug":"cve-2026-82325-openvpn-ovpn-dco-win-use-after-free-in-driver","title":"OpenVPN ovpn-dco-win use-after-free in driver","severity":"info","exploited":false,"published_at":"2026-09-07T11:17:37.363+00:00","url":"https://junglewise.ai/threats/cve-2026-82325-openvpn-ovpn-dco-win-use-after-free-in-driver"},{"cve":"CVE-2026-84732","epss":0.0054,"slug":"cve-2026-84732-openvpn-ack-packet-retransmission-denial-of-service","title":"OpenVPN ACK packet retransmission denial of service","severity":"info","exploited":false,"published_at":"2026-09-07T09:17:16.84+00:00","url":"https://junglewise.ai/threats/cve-2026-84732-openvpn-ack-packet-retransmission-denial-of-service"},{"cve":"CVE-2026-84256","cvss":0,"epss":0.0038,"slug":"cve-2026-84256-openvpn-argument-parsing-vulnerability-on-windows","title":"OpenVPN argument parsing vulnerability on Windows","severity":"info","exploited":false,"published_at":"2026-09-07T08:17:13.777+00:00","url":"https://junglewise.ai/threats/cve-2026-84256-openvpn-argument-parsing-vulnerability-on-windows"},{"cve":"CVE-2026-84226","epss":0.0014,"slug":"cve-2026-84226-openvpn-binary-planting-on-windows","title":"OpenVPN binary planting on Windows","severity":"info","exploited":false,"published_at":"2026-09-07T08:17:13.653+00:00","url":"https://junglewise.ai/threats/cve-2026-84226-openvpn-binary-planting-on-windows"},{"cve":"CVE-2026-82312","epss":0.001,"slug":"cve-2026-82312-openvpn-denial-of-service-via-null-dacl-on-windows-ipc","title":"OpenVPN denial of service via NULL DACL on Windows IPC","severity":"info","exploited":false,"published_at":"2026-09-07T08:17:13.527+00:00","url":"https://junglewise.ai/threats/cve-2026-82312-openvpn-denial-of-service-via-null-dacl-on-windows-ipc"},{"cve":"CVE-2026-81830","epss":0.0015,"slug":"cve-2026-81830-openvpn-windows-interactive-service-path-validation-bypass","title":"OpenVPN Windows interactive service path validation bypass","severity":"info","exploited":false,"published_at":"2026-09-07T08:17:13.41+00:00","url":"https://junglewise.ai/threats/cve-2026-81830-openvpn-windows-interactive-service-path-validation-bypass"},{"cve":"CVE-2026-81738","epss":0.0033,"slug":"cve-2026-81738-openvpn-out-of-bounds-write-in-tap-windows6-driver","title":"OpenVPN out-of-bounds write in tap-windows6 driver","severity":"info","exploited":false,"published_at":"2026-09-07T08:17:13.27+00:00","url":"https://junglewise.ai/threats/cve-2026-81738-openvpn-out-of-bounds-write-in-tap-windows6-driver"},{"cve":"CVE-2026-78221","epss":0.0012,"slug":"cve-2026-78221-openvpn-windows-interactive-service-buffer-size-miscalculation","title":"OpenVPN Windows Interactive Service buffer size miscalculation","severity":"info","exploited":false,"published_at":"2026-09-07T08:17:12.813+00:00","url":"https://junglewise.ai/threats/cve-2026-78221-openvpn-windows-interactive-service-buffer-size-miscalculation"},{"cve":"CVE-2026-78043","epss":0.0017,"slug":"cve-2026-78043-openvpn-windows-interactive-service-configuration-bypass","title":"OpenVPN Windows Interactive Service configuration bypass","severity":"info","exploited":false,"published_at":"2026-09-07T08:17:12.637+00:00","url":"https://junglewise.ai/threats/cve-2026-78043-openvpn-windows-interactive-service-configuration-bypass"},{"cve":"CVE-2026-63650","epss":0.0036,"slug":"cve-2026-63650-openvpn-authentication-identity-lookup-bypass-in-mbedtls","title":"OpenVPN authentication identity lookup bypass in mbedTLS","severity":"info","exploited":false,"published_at":"2026-08-14T23:16:32.653+00:00","url":"https://junglewise.ai/threats/cve-2026-63650-openvpn-authentication-identity-lookup-bypass-in-mbedtls"},{"cve":"CVE-2026-63649","epss":0.0033,"slug":"cve-2026-63649-openvpn-windows-interactive-service-configuration-bypass","title":"OpenVPN Windows interactive service configuration bypass","severity":"info","exploited":false,"published_at":"2026-08-14T23:16:32.507+00:00","url":"https://junglewise.ai/threats/cve-2026-63649-openvpn-windows-interactive-service-configuration-bypass"},{"cve":"CVE-2026-12932","cvss":7.1,"slug":"cve-2026-12932-openvpn-memory-leak-in-tls-crypt-v2-client-key-extraction","title":"OpenVPN memory leak in tls-crypt-v2 client key extraction","severity":"info","exploited":false,"published_at":"2026-07-30T17:16:27.92+00:00","url":"https://junglewise.ai/threats/cve-2026-12932-openvpn-memory-leak-in-tls-crypt-v2-client-key-extraction"},{"cve":"CVE-2026-11771","cvss":7,"slug":"cve-2026-11771-openvpn-off-by-one-buffer-write-in-ntlm-proxy-authentication","title":"OpenVPN off-by-one buffer write in NTLM proxy authentication","severity":"info","exploited":false,"published_at":"2026-07-30T17:16:27.61+00:00","url":"https://junglewise.ai/threats/cve-2026-11771-openvpn-off-by-one-buffer-write-in-ntlm-proxy-authentication"},{"cve":"CVE-2025-3110","cvss":6.9,"slug":"cve-2025-3110-openvpn-access-server-http-request-smuggling-via-bare-line-feed","title":"OpenVPN Access Server HTTP request smuggling via bare line-feed sequences","severity":"info","exploited":false,"published_at":"2026-07-08T17:17:19.65+00:00","url":"https://junglewise.ai/threats/cve-2025-3110-openvpn-access-server-http-request-smuggling-via-bare-line-feed"},{"cve":"CVE-2026-11604","cvss":5.6,"slug":"cve-2026-11604-openvpn-ovpn-dco-win-heap-overflow-in-epoch-key-generator","title":"OpenVPN ovpn-dco-win heap overflow in epoch key generator","severity":"info","exploited":false,"published_at":"2026-06-10T22:16:55.643+00:00","url":"https://junglewise.ai/threats/cve-2026-11604-openvpn-ovpn-dco-win-heap-overflow-in-epoch-key-generator"}],"vendor":{"hub":true,"name":"Openvpn","slug":"openvpn","homepage":"https://openvpn.net/","description":"An open-source project that provides virtual private network (VPN) solutions to create secure point-to-point or site-to-site connections.","url":"https://junglewise.ai/threats/vendors/openvpn"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":9},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-12932","cvss":7.1,"slug":"cve-2026-12932-openvpn-memory-leak-in-tls-crypt-v2-client-key-extraction","title":"OpenVPN memory leak in tls-crypt-v2 client key extraction","severity":"info","exploited":false,"published_at":"2026-07-30T17:16:27.92+00:00","url":"https://junglewise.ai/threats/cve-2026-12932-openvpn-memory-leak-in-tls-crypt-v2-client-key-extraction"},{"cve":"CVE-2026-11771","cvss":7,"slug":"cve-2026-11771-openvpn-off-by-one-buffer-write-in-ntlm-proxy-authentication","title":"OpenVPN off-by-one buffer write in NTLM proxy authentication","severity":"info","exploited":false,"published_at":"2026-07-30T17:16:27.61+00:00","url":"https://junglewise.ai/threats/cve-2026-11771-openvpn-off-by-one-buffer-write-in-ntlm-proxy-authentication"},{"cve":"CVE-2025-3110","cvss":6.9,"slug":"cve-2025-3110-openvpn-access-server-http-request-smuggling-via-bare-line-feed","title":"OpenVPN Access Server HTTP request smuggling via bare line-feed sequences","severity":"info","exploited":false,"published_at":"2026-07-08T17:17:19.65+00:00","url":"https://junglewise.ai/threats/cve-2025-3110-openvpn-access-server-http-request-smuggling-via-bare-line-feed"},{"cve":"CVE-2026-11604","cvss":5.6,"slug":"cve-2026-11604-openvpn-ovpn-dco-win-heap-overflow-in-epoch-key-generator","title":"OpenVPN ovpn-dco-win heap overflow in epoch key generator","severity":"info","exploited":false,"published_at":"2026-06-10T22:16:55.643+00:00","url":"https://junglewise.ai/threats/cve-2026-11604-openvpn-ovpn-dco-win-heap-overflow-in-epoch-key-generator"},{"cve":"CVE-2026-84256","cvss":0,"epss":0.0038,"slug":"cve-2026-84256-openvpn-argument-parsing-vulnerability-on-windows","title":"OpenVPN argument parsing vulnerability on Windows","severity":"info","exploited":false,"published_at":"2026-09-07T08:17:13.777+00:00","url":"https://junglewise.ai/threats/cve-2026-84256-openvpn-argument-parsing-vulnerability-on-windows"},{"cve":"CVE-2026-84732","epss":0.0054,"slug":"cve-2026-84732-openvpn-ack-packet-retransmission-denial-of-service","title":"OpenVPN ACK packet retransmission denial of service","severity":"info","exploited":false,"published_at":"2026-09-07T09:17:16.84+00:00","url":"https://junglewise.ai/threats/cve-2026-84732-openvpn-ack-packet-retransmission-denial-of-service"},{"cve":"CVE-2026-63650","epss":0.0036,"slug":"cve-2026-63650-openvpn-authentication-identity-lookup-bypass-in-mbedtls","title":"OpenVPN authentication identity lookup bypass in mbedTLS","severity":"info","exploited":false,"published_at":"2026-08-14T23:16:32.653+00:00","url":"https://junglewise.ai/threats/cve-2026-63650-openvpn-authentication-identity-lookup-bypass-in-mbedtls"},{"cve":"CVE-2026-81738","epss":0.0033,"slug":"cve-2026-81738-openvpn-out-of-bounds-write-in-tap-windows6-driver","title":"OpenVPN out-of-bounds write in tap-windows6 driver","severity":"info","exploited":false,"published_at":"2026-09-07T08:17:13.27+00:00","url":"https://junglewise.ai/threats/cve-2026-81738-openvpn-out-of-bounds-write-in-tap-windows6-driver"},{"cve":"CVE-2026-63649","epss":0.0033,"slug":"cve-2026-63649-openvpn-windows-interactive-service-configuration-bypass","title":"OpenVPN Windows interactive service configuration bypass","severity":"info","exploited":false,"published_at":"2026-08-14T23:16:32.507+00:00","url":"https://junglewise.ai/threats/cve-2026-63649-openvpn-windows-interactive-service-configuration-bypass"},{"cve":"CVE-2026-78043","epss":0.0017,"slug":"cve-2026-78043-openvpn-windows-interactive-service-configuration-bypass","title":"OpenVPN Windows Interactive Service configuration bypass","severity":"info","exploited":false,"published_at":"2026-09-07T08:17:12.637+00:00","url":"https://junglewise.ai/threats/cve-2026-78043-openvpn-windows-interactive-service-configuration-bypass"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"OpenVPN","slug":"openvpn","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/openvpn"}]}