SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84732

HIGH · CVSS 8.7 EPSS 0.54%

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

OpenVPN versions 2.6.22 and 2.7.6 are vulnerable to a denial of service attack due to an integer overflow triggered by retransmissions of ACK packet IDs, allowing remote unauthenticated attackers to disrupt service. Organizations using these versions should prioritize patching to mitigate the risk of service interruptions. Immediate action is recommended for environments relying on OpenVPN for secure communications.

CVE
CVE-2026-84732
Severity
HIGH
CVSS
8.7
EPSS
0.54%

Original NVD Description

Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a timeout integer overflow