SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-12996

HIGH · CVSS 8.1 EPSS 0.46%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

OpenVPN versions 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 are vulnerable to a use-after-free issue that can be exploited by remote authenticated peers, potentially leading to denial of service or memory leakage during TLS session promotion or expiry. Organizations using these versions should prioritize patching to mitigate risks associated with this vulnerability, particularly those relying on OpenVPN for secure communications.

CVE
CVE-2026-12996
Severity
HIGH
CVSS
8.1
EPSS
0.46%

Original NVD Description

A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry

Related CVEs

Other vulnerabilities affecting the same vendor(s)