SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-74895

CRITICAL · CVSS 9.8 EPSS 0.41% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

OpenSSL versions prior to 1.4.0 are vulnerable due to insufficient sandbox restrictions in the default process isolation mode, allowing attackers to execute malicious plugins with full access to the filesystem, network, and Python modules. This critical vulnerability poses a significant risk to any application utilizing affected OpenSSL versions, particularly those that rely on plugin execution. Organizations using these versions should prioritize immediate updates to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-74895
Severity
CRITICAL
CVSS
9.8
EPSS
0.41%
OpenSSL

Original NVD Description

openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can execute malicious plugins with unrestricted access to the filesystem, network, subprocess execution, and all Python modules.

Related CVEs

Other vulnerabilities affecting the same vendor(s)