Vulnerabilities
Summary — last 7 days
New vulnerabilities3,332▲ 359 vs. last week
Critical / high1,490▲ 132 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 120 vs. last week
111 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | Medium (6.8) | 0.14% | — | Openvpn Ovpn-dco-winAI | 9/7/2026 | 9/8/2026 | A use-after-free vulnerability in the OpenVPN ovpn-dco-win driver version 2.5.0 through 2.8.6 allows local authenticated users to cause a system crash via crafted control messages | |
| Awaiting Analysis | High (8.7) | 0.54% | — | OpenvpnAI | 9/7/2026 | 9/8/2026 | Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a timeout integer overflow | |
| Awaiting Analysis | High (7.7) | 0.38% | — | OpenvpnAI | 9/7/2026 | 9/8/2026 | An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a crafted certificate subject | |
| Awaiting Analysis | High (8.5) | 0.14% | — | OpenvpnAI | 9/7/2026 | 9/8/2026 | OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps | |
| Awaiting Analysis | Low (1.8) | 0.10% | — | OpenvpnAI | 9/7/2026 | 9/8/2026 | OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial of service via a NULL DACL on named IPC objects | |
| Awaiting Analysis | Medium (5.6) | 0.15% | — | OpenvpnAI | 9/7/2026 | 9/8/2026 | The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation | |
| Awaiting Analysis | Low (2.3) | 0.33% | — | OpenvpnAITAP Windows6AI | 9/7/2026 | 9/8/2026 | OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries | |
| Awaiting Analysis | Medium (5.9) | 0.12% | — | OpenvpnAI | 9/7/2026 | 9/8/2026 | An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs. | |
| Awaiting Analysis | Medium (5.6) | 0.17% | — | OpenvpnAI | 9/7/2026 | 9/8/2026 | The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via specially crafted paths | |
| Awaiting Analysis | Low (2) | 0.36% | — | OpenvpnAIARM MbedtlsAI | 8/14/2026 | 9/1/2026 | OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field | |
| Awaiting Analysis | Medium (4.1) | 0.33% | — | OpenvpnAI | 8/14/2026 | 9/1/2026 | The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via crafted options that bypass whitelist checks | |
| Deferred | Critical (9.4) | 0.62% | — | Luci-app-openvpnAI | 8/13/2026 | 9/30/2026 | luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers can upload malicious payloads to gain persistent root code execution by placing SSH keys in system… | |
| Analyzed | Medium (5.1) | 0.59% | — | Openvpn | 7/30/2026 | 8/5/2026 | The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnection process | |
| Analyzed | Medium (6) | 0.64% | — | Openvpn | 7/30/2026 | 8/5/2026 | An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage | |
| Analyzed | Medium (6) | 0.81% | — | OpenvpnDebian Linux | 7/30/2026 | 8/5/2026 | A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry | |
| Analyzed | High (7.1) | 0.75% | — | Openvpn | 7/30/2026 | 8/5/2026 | A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets | |
| Analyzed | High (7) | 0.68% | — | Openvpn | 7/30/2026 | 8/5/2026 | OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server | |
| Analyzed | Medium (6.9) | 0.45% | — | Openvpn Access Server | 7/8/2026 | 9/29/2026 | OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy | |
| Analyzed | Medium (5.9) | 0.46% | — | Openvpn | 7/6/2026 | 7/9/2026 | OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled | |
| Analyzed | Medium (6) | 0.55% | — | Openvpn | 7/6/2026 | 7/9/2026 | A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service | |
| Deferred | High (8.7) | 2.7% | — | Openwrt Luci-proto-openvpnAI | 6/29/2026 | 7/14/2026 | luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the generateKey ubus method where the cl_meta parameter is interpolated into a shell command without proper escaping or quoting. An authenticated LuCI user with OpenVPN protocol configuration access can inject… | |
| Analyzed | Medium (5.6) | 0.34% | — | Openvpn Ovpn-dco-win | 6/10/2026 | 9/24/2026 | An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted data packet, resulting in a system crash (denial of service). | |
| Analyzed | Medium (6.1) | 0.59% | — | Openvpn | 6/8/2026 | 8/11/2026 | A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion. | |
| Analyzed | Medium (6.9) | 0.60% | — | Openvpn | 6/8/2026 | 8/11/2026 | Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and cause a denial of service via a specially crafted packet. | |
| Deferred | Low (2.1) | 1.2% | — | OpenvpnAIGl-inet Mt3000AI | 6/6/2026 | 7/23/2026 | A vulnerability was determined in GL.iNet MT3000 up to 4.4.5. This vulnerability affects unknown code of the file ovpnclient.sh of the component OpenVPN Client Import Workflow. This manipulation causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be… |