SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-13379

CRITICAL · CVSS 9.1 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The Windows interactive service in OpenVPN versions 2.7_alpha1 to 2.7.4 is vulnerable to remote attacks that can lead to persistent DNS state pollution or service crashes when a crafted search domain is processed during disconnection. Organizations using these versions of OpenVPN should prioritize patching to mitigate potential disruptions and ensure network integrity. This vulnerability poses a risk primarily to environments relying on OpenVPN for secure communications.

CVE
CVE-2026-13379
Severity
CRITICAL
CVSS
9.1
EPSS
0.34%
Windows

Original NVD Description

The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnection process

Related CVEs

Other vulnerabilities affecting the same vendor(s)