SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-74885

LOW · CVSS 3.6 EPSS 0.12% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

OpenSSL versions prior to 1.4.0 are vulnerable due to a logging bug in the `restore_hidden_modules()` function, which inaccurately logs module counts, potentially corrupting audit trails. Additionally, a race condition may allow blocked modules to be re-imported in multi-threaded environments, posing a risk of unauthorized access. Organizations using affected versions should prioritize this vulnerability to ensure the integrity of their logging and module management processes.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-74885
Severity
LOW
CVSS
3.6
EPSS
0.12%
OpenSSL

Original NVD Description

openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after clearing, always showing zero restored modules and corrupting audit trails. Additionally, a race condition exists between module hiding and import hook installation where another thread could re-import blocked modules in multi-threaded environments.

Related CVEs

Other vulnerabilities affecting the same vendor(s)