Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Greggs to close four UK factories with potential for 740 job losses | Greggs

    September 30, 2026

    EU to offer single-market access to candidate countries – POLITICO

    September 30, 2026

    Andy Burnham says rejoining the EU among all ‘the options’ being considered – UK politics live | Politics

    September 30, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Greggs to close four UK factories with potential for 740 job losses | Greggs
    • EU to offer single-market access to candidate countries – POLITICO
    • Andy Burnham says rejoining the EU among all ‘the options’ being considered – UK politics live | Politics
    • Will reforming the triple lock pay for social care reform?
    • LG Promo Codes and Coupons for October 2026
    • Perplexity Introduces Photon: A Rust-Based Retrieval Engine That Cuts p99 Latency From 800 ms to 65 ms
    • Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution
    • Anthropic Lost $42 Billion Last Year. It Wants to Go Public at $2 Trillion
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 30
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 30, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The developers of the OpenSSL and WolfSSL open source cryptographic libraries announced patches for roughly a dozen vulnerabilities each, including high-severity flaws.

    Of the 14 vulnerabilities fixed in OpenSSL, one has been assigned a high severity rating. Tracked as CVE-2026-84782, it could allow a remote peer to obtain fragments of heap memory or crash applications that use Datagram TLS (DTLS), a protocol commonly found in VPNs, VoIP and IoT products.

    The flaw is triggered during the DTLS handshake, when OpenSSL retransmits a message while sending another one is stalled. This can cause leftover heap data to be sent to the other party in plaintext. If the read reaches unmapped memory, the application crashes, resulting in a denial-of-service (DoS) condition.

    The issue has a CVSS score of 8.2 and can be exploited over the network without authentication or user interaction.

    The latest OpenSSL releases also fix a medium-severity vulnerability identified as CVE-2026-84783. A remote, unauthenticated peer could exploit the weakness to crash a multi-threaded TLS client and cause a DoS condition.

    The remaining security holes have a low severity rating. They mostly lead to DoS conditions, caused by excessive memory or CPU consumption, process crashes, or the termination of DTLS 1.2 connections. The rest could let attackers abuse QUIC servers for DDoS amplification or exploit timing side channels to gather information that could lead to private key recovery.

    Advertisement. Scroll to continue reading.

    WolfSSL security patches

    WolfSSL developers released version 5.9.4 on September 25. In addition to new features, the latest version patches 11 vulnerabilities, including three classified as high severity.

    The high-severity issues can allow attackers to bypass peer authentication in certain WolfSSL configurations.

    CVE-2026-93302 exists because WolfSSL ignores the public key when matching a certificate against a trusted peer certificate. A malicious server that knows which CAs a client trusts can present a forged CA clone and bypass authentication. Affected builds include those created for integration with Nginx, HAProxy, Stunnel, Apache httpd, and other applications.

    CVE-2026-89102 allows an attacker holding any certificate (and its private key) that chains to a CA trusted by the client to forge certificates for arbitrary identities. CVE-2026-89136 lets a malicious server bypass authentication on clients with Raw Public Key support enabled by selecting an RPK certificate type the client never requested.

    Four medium-severity flaws involve certificate validation defects and a handshake sequencing error. They could allow attackers to bypass name constraints, plant an unverified CA in the shared certificate manager, or complete a TLS 1.2 or DTLS 1.2 handshake in place of the legitimate server and send data the client accepts as authentic.

    The four low-severity bugs could lead to a use-after-free during connection shutdown, skipped CRL revocation checks, acceptance of certificates with invalid signatures, and server impersonation. Most require specific configurations or legacy API usage.

    Related: OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability

    Related: OpenSSL Patches High-Severity Vulnerability Found With AI

    Related: Data Leakage Vulnerability Patched in OpenSSL

    HighSeverity OpenSSL Patched Vulnerabilities WolfSSL
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

    Pentagon Personnel Agency Data Breach Impacts 3 Million People

    RemoteThreat Launches With $7 Million for Offensive Operations Platform

    Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development

    Signal adds encypted local backup support to iOS, desktop apps

    Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Greggs to close four UK factories with potential for 740 job losses | Greggs

    September 30, 2026

    EU to offer single-market access to candidate countries – POLITICO

    September 30, 2026

    Andy Burnham says rejoining the EU among all ‘the options’ being considered – UK politics live | Politics

    September 30, 2026

    Will reforming the triple lock pay for social care reform?

    September 30, 2026
    Latest Posts

    Bitcoin collateral: MARA’s $600M Long Ridge financing

    August 7, 2026

    Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix

    August 7, 2026

    The best classic slasher movie you’ll never watch

    August 7, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Greggs to close four UK factories with potential for 740 job losses | Greggs

    September 30, 2026

    EU to offer single-market access to candidate countries – POLITICO

    September 30, 2026

    Andy Burnham says rejoining the EU among all ‘the options’ being considered – UK politics live | Politics

    September 30, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.