PT-2026-91016 · Canonical+2 · Openvpn

CVE-2026-84471

·

Published

2026-09-04

·

Updated

2026-09-30

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
It was discovered that OpenVPN had a use-after-free vulnerability in its TLS session handling. An attacker could possibly use this issue to cause OpenVPN to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-84471)
It was discovered that OpenVPN incorrectly handled retransmissions of ACK packet IDs, which could trigger a timeout integer overflow. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-84732)
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-84471
USN-8852-1

Affected Products

Openvpn