DIRAS TAKE
Urgent: public exploit code exists and the vulnerable routine is reachable from CMS_decrypt without special configuration, so prioritize upgrades to the fixed releases or apply mitigations immediately.
What is CVE-2026-63072?
An attacker who supplies a specially crafted CMS (Cryptographic Message Syntax) message can cause OpenSSL to perform an 8-byte write past a heap buffer during CMS_decrypt, potentially corrupting memory and causing denial of service; this issue is tracked as CVE-2026-63072. The bug affects OpenSSL releases 4.0.0 through before 4.0.2, 3.6.0 through before 3.6.4, 3.5.0 through before 3.5.8, 3.4.0 through before 3.4.7, 3.0.0 through before 3.0.22, and 1.1.1 through before 1.1.1zi. Exploitation requires sending a malicious CMS payload to software that performs CMS_decrypt. The weakness is classified as CWE-787 (Out-of-bounds Write).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Which versions of OpenSSL OpenSSL are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 4.x | 4.0.0 – before 4.0.2 | 4.0.2 |
| 3.x | 3.6.0 – before 3.6.4 | 3.6.4 |
| 3.x | 3.5.0 – before 3.5.8 | 3.5.8 |
| 3.x | 3.4.0 – before 3.4.7 | 3.4.7 |
| 3.x | 3.0.0 – before 3.0.22 | 3.0.22 |
| 1.x | 1.1.1 – before 1.1.1zi | 1.1.1zi |
Is CVE-2026-63072 being exploited?
Public exploit code is available.
How to fix CVE-2026-63072
- Upgrade OpenSSL to a fixed release: 4.0.2, 3.6.4, 3.5.8, 3.4.7, 3.0.22, or 1.1.1zi.
- If you cannot upgrade immediately, restrict network exposure of services that accept CMS input and block untrusted CMS messages.
- Monitor application logs and crash reports for CMS_decrypt failures, heap corruption symptoms, and unexplained process crashes.
- Apply vendor guidance and rebuild any applications that statically link or bundle OpenSSL after patching.
Frequently asked questions
Is CVE-2026-63072 being actively exploited?
Public exploit code is available for CVE-2026-63072.
Which OpenSSL versions are affected by CVE-2026-63072?
Affected versions include 4.0.0 up to before 4.0.2; 3.6.0 up to before 3.6.4; 3.5.0 up to before 3.5.8; 3.4.0 up to before 3.4.7; 3.0.0 up to before 3.0.22; and 1.1.1 up to before 1.1.1zi.
Is there a patch for CVE-2026-63072?
Yes. Fixed releases are 4.0.2, 3.6.4, 3.5.8, 3.4.7, 3.0.22, and 1.1.1zi.
Does CVE-2026-63072 require authentication?
No special authentication is required; the vulnerability is triggered when an application calls OpenSSL's CMS_decrypt on attacker-supplied CMS data.
References
- nvd.nist.gov/vuln/detail/CVE-2026-63072
- cve.org/CVERecord?id=CVE-2026-63072
- openssl-library.org/news/secadv/20260825.txt
- github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335
- github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756
- github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42
- github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a
- github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382
- All OpenSSL CVEs on CVE Radar
- CVEs published in September 2026