CyberRota Analysis
AI-GeneratedOpenVPN versions 2.6.22 and 2.7.6 are vulnerable to a denial of service attack due to an integer overflow triggered by retransmissions of ACK packet IDs, allowing remote unauthenticated attackers to disrupt service. Organizations using these versions should prioritize patching to mitigate the risk of service interruptions. Immediate action is recommended for environments relying on OpenVPN for secure communications.
CVE
CVE-2026-84732
Severity
HIGH
CVSS
8.7
EPSS
0.54%
Original NVD Description
Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a timeout integer overflow