SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-13117

HIGH · CVSS 8.1 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

OpenVPN versions 2.6.0 to 2.6.20 and 2.7_alpha1 to 2.7.4 are vulnerable due to an incomplete guard that permits remote authenticated peers to exploit a use-after-free condition during TLS session promotion. This vulnerability may result in denial of service or memory leakage, impacting the confidentiality and availability of the affected systems. Organizations using these OpenVPN versions should prioritize patching to mitigate potential risks associated with this flaw.

CVE
CVE-2026-13117
Severity
HIGH
CVSS
8.1
EPSS
0.40%

Original NVD Description

An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage

Related CVEs

Other vulnerabilities affecting the same vendor(s)