OPENSSL released a security update on August 25, 2026, addressing nine vulnerabilities, primarily related to denial of service (DoS). Among the issues, two are classified as Moderate: a QUIC double free (CVE-2026-18798) that can crash QUIC servers, and a heap buffer overflow (CVE-2026-63072) affecting CMS key unwrapping. The remaining Low-severity bugs pertain to other protocols like CMP and DTLS, enabling potential service crashes. No active exploitation in the wild has been reported.
Affected OpenSSL versions include 4.0, 3.6, 3.5, 3.4, and 3.0, with specific patch recommendations provided for each version. Admins are urged to apply updates promptly.