OPENSSL and WolfSSL have released patches addressing roughly a dozen vulnerabilities in each library. In OpenSSL, 14 issues were fixed, with one classified as high severity: CVE-2026-84782. This flaw could allow a remote, unauthenticated peer to obtain fragments of heap memory or crash applications using Datagram TLS (DTLS) by triggering a retransmission during a stalled handshake, potentially exposing data in plaintext and causing a denial-of-service.
A second medium-severity issue, CVE-2026-84783, could enable a remote, unauthenticated peer to crash a multi-threaded TLS client, also leading to a DoS scenario. The remaining OpenSSL bugs are low severity, typically involving DoS via memory or CPU exhaustion, DTLS 1.2 connection termination, or exposure of timing side channels that could aid private-key recovery in some scenarios.
WolfSSL followed with version 5.9.4 on 25 September, patching 11 vulnerabilities, including three high-severity flaws. Notably, CVE-2026-93302 arises because WolfSSL may ignore the public key when matching a certificate against a trusted peer, enabling a forged CA clone to bypass authentication in affected builds used with Nginx, HAProxy, Stunnel, Apache httpd, and similar deployments.
Additional high-severity issues (CVE-2026-89102, CVE-2026-89136) could permit certificate forgery or authentication bypass under certain configurations, such as RPK support. Four medium-severity and four low-severity bugs accompany these, including name-constraint bypass and possible use-after-free conditions.
Practically, organisations should deploy the updated OpenSSL and WolfSSL releases to mitigate remote code execution and denial-of-service risks, while reviewing configurations that rely on legacy API usage or specific certificate-handling behaviours.