These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A use-after-free vulnerability in OpenVPN ovpn-dco-win driver versions 2.5.0 through 2.8.6 allows local authenticated users to cause a system crash via crafted control messages. This vulnerability has a medium CVSS score of 6.8 and can potentially lead to denial-of-service attacks. Defenders and administrators of systems using OpenVPN ovpn-dco-win driver versions 2.5.0 through 2.8.6 should assess exposure [truncated]
CVE-2026-84732 is a high-severity denial of service vulnerability in OpenVPN versions through 2.6.22 and 2.7.6. The vulnerability allows remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a timeout integer overflow. Defenders should assess exposure and potential impact. Official sources suggest a need for caution and verification. The CVE record was published on [truncated]
CVE-2026-84256 debrief based on the supplied source corpus. The CVE record was published on 2026-09-07T08:17:13.777Z and has not been modified since then. This high-severity vulnerability in OpenVPN allows remote authenticated users to execute arbitrary commands via a crafted certificate subject on Windows systems, impacting versions 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6. Defenders responsi [truncated]
OpenVPN vulnerability allows local authenticated users to perform binary planting attacks during network configuration on Windows systems. This high-severity issue affects OpenVPN versions 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6. Defenders should verify OpenVPN versions, restrict network configuration access, and monitor for suspicious activity. The vulnerability enables attackers to exploit dur [truncated]
OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial of service via a NULL DACL on named IPC objects. This issue has a CVSS score of 1.8 and is considered LOW severity. The CVE record was published on 2026-09-07T08:17:13.527Z and has not been modified since then. Defenders responsible for Windows systems with OpenVPN installations, especia [truncated]
CVE-2026-81830 is a medium-severity vulnerability affecting OpenVPN 2.4.0 through 2.6.22 on Windows. It allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation. Defenders should assess the vulnerability's impact and take necessary actions. The CVE record and NVD entry provide limited information, and additional details may be needed to f [truncated]
OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries. This CVE has a CVSS score of 2.3 and is considered LOW severity. The CVE was published on 2026-09-07T08:17:13.270Z and has not been modified since then. Defenders should prioritize verifying OpenVPN versions and configurations, especially on Windows sys [truncated]
A vulnerability in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs. Defenders should assess exposure, prioritize verification, and consider remediation to prevent potential security consequences. This vulnerability affects OpenVPN deployments, particularly those with local authentication, and may lead to [truncated]
CVE-2026-78043 is a medium-severity vulnerability in OpenVPN 2.7_alpha1 through 2.7.6 that allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via specially crafted paths. This vulnerability impacts OpenVPN installations, particularly affecting systems where local authenticated users could exploit this to load unauthorized config [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-14T23:16:32.507Z and has not been modified since then. The Windows interactive service in OpenVPN allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via crafted options that bypass whitelist checks. This vulnerability affe [truncated]
The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 is vulnerable to a remote attack that can cause persistent DNS state pollution or a service crash. This occurs when a crafted search domain is provided during the disconnection process. The vulnerability has a CVSS score of 5.1 and a medium severity. Affected product deployments should be reviewed for exposure, and owners should be assign [truncated]
The CVE-2026-13117 vulnerability affects OpenVPN, specifically versions 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4. An incomplete guard allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage. OpenVPN users and administrators should be aware of this vulnerability and take steps to patch or mitigate it t [truncated]
A use-after-free vulnerability in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry. This vulnerability affects OpenVPN deployments, particularly those using versions 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4. The vulnerability's impact includ [truncated]
OpenVPN versions 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 are vulnerable to an off-by-one buffer write issue related to NTLM proxy authentication. This could potentially cause a crash via a crafted NTLM response from a malicious proxy server. The CVSS score for this vulnerability is 7, indicating high severity. OpenVPN has addressed this issue in versions 2.6.21 and 2.7.5. Users and administrator [truncated]
CVE-2026-13122 is a denial-of-service vulnerability in OpenVPN versions 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4. The vulnerability allows remote attackers to trigger a reachable assertion when external-auth is enabled via a malformed authentication token. This issue can cause a denial of service, potentially disrupting VPN services. Users of affected OpenVPN versions should apply patches or miti [truncated]
A memory leak vulnerability was discovered in OpenVPN versions 2.5.0 through 2.5.11, 2.6.0 through 2.6.20, and 2.7_alpha1 through 2.7.4. This vulnerability allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service. The vulnerability is caused by a memory leak in OpenVPN, which can be exploited by remote attackers to potentially cause a denial of service. Users o [truncated]
CVE-2026-11604 is a medium-severity vulnerability in OpenVPN ovpn-dco-win versions 2.0.0 through 2.8.3. An incorrect buffer size calculation in the epoch key generator allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted data packet, resulting in a system crash (denial of service). The CVSS score for this vulnerability is 5.6, indicating a m [truncated]
CVE-2026-40215 is a medium-severity vulnerability in OpenVPN, allowing remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion. The vulnerability affects OpenVPN versions 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1.
CVE-2026-35058 is a medium-severity vulnerability in OpenVPN, affecting versions 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1. The vulnerability is caused by improper validation of packet length during tls-crypt-v2 key extraction, allowing authenticated attackers to trigger a fatal assertion and cause a denial of service via a specially crafted packet. The CVSS score for this vulnerability is 6.9, in [truncated]
CVE-2016-6329 is a confidentiality issue in OpenVPN tied to the use of 64-bit block ciphers. NVD describes it as making it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, with an HTTP-over-OpenVPN Blowfish-CBC example of the Sweet32 class of attacks. The NVD record lists affected OpenVPN versions up to 2.3.14 when configured with a vuln [truncated]