SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-11771

HIGH · CVSS 7.5 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

OpenVPN versions 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 are vulnerable to an off-by-one buffer write in the NTLM proxy authentication process, which can be exploited by attackers to crash the application using a specially crafted NTLM response from a malicious proxy server. Organizations utilizing these OpenVPN versions should prioritize patching this vulnerability to prevent potential service disruptions and ensure the integrity of their VPN connections.

CVE
CVE-2026-11771
Severity
HIGH
CVSS
7.5
EPSS
0.38%

Original NVD Description

OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server

Related CVEs

Other vulnerabilities affecting the same vendor(s)