VENDOR

OpenSSL vulnerabilities: CVEs, exploitation and patches

Every OpenSSL CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.

  1. CVE-2026-63073
    OpenSSL CMP format-string denial of service OpenSSL OpenSSL ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  2. CVE-2026-63072
    OpenSSL CMS heap out-of-bounds write via CMS_decrypt OpenSSL OpenSSL ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.5
2 CVEs · page 1 of 1