SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84256

HIGH · CVSS 7.7 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

OpenVPN versions 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows are vulnerable due to an argument parsing issue that allows remote authenticated users to execute arbitrary commands through a specially crafted certificate subject. This vulnerability poses a high risk, as it can lead to unauthorized command execution on affected systems. Organizations using these OpenVPN versions on Windows should prioritize immediate remediation to mitigate potential exploitation.

CVE
CVE-2026-84256
Severity
HIGH
CVSS
7.7
EPSS
0.38%
Windows

Original NVD Description

An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a crafted certificate subject