ZeroHour

CVE-2026-84732

mass

Unauthenticated denial of service in OpenVPN 2.6/2.7 via ACK packet-ID integer overflow

CVSS 4.0
8.7 high
EPSS
<1%p44
Published
()
Modified
AI analysis

OpenVPN versions through 2.6.22 and through 2.7.6 contain an integer overflow (CWE-190) in the retransmission handling of ACK packet IDs, which can cause a timeout value to wrap. A remote, unauthenticated attacker who can reach a listening OpenVPN service can send crafted inputs that trigger the overflow, causing the service to time out or fail and disrupting VPN connectivity. The impact is availability-only; the CVSS 4.0 vector shows no confidentiality or integrity impact to the tunnel or data. All deployments running affected 2.6.x releases up to and including 2.6.22, or 2.7.x releases up to and including 2.7.6, are potentially exposed. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only a 0.5% probability of exploitation in the next 30 days.

What to do: Upgrade OpenVPN servers and clients to a fixed 2.6-series release newer than 2.6.22 or a fixed 2.7-series release newer than 2.7.6, per the OpenVPN security advisory (AV26-889). Until patched, restrict exposure of OpenVPN service ports to trusted source networks and monitor for unexpected process crashes or restarts. Operators of third-party products (appliances, router firmware) that bundle affected OpenVPN versions should apply vendor updates when they ship fixes.

Affected
OpenVPN (OpenVPN project / [email protected]) OpenVPN VPN server/client2.6.x through and including 2.6.22
OpenVPN (OpenVPN project / [email protected]) OpenVPN VPN server/client2.7.x through and including 2.7.6
Estimated exposure
masslikely millions of installations (OpenVPN is among the most widely deployed open-source VPNs, with on the order of hundreds of thousands of OpenVPN services… — OpenVPN is embedded across enterprise VPN gateways, cloud images, and consumer/prosumer router firmware, and public internet scans have historically indexed hundreds of thousands of OpenVPN services, so the population of affected installs…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a timeout integer overflow

Weakness
CWE-190
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

OpenVPN security advisory (AV26-889)

Canada's Cyber Centre advisory AV26-889 flags CVE-2026-84732 in OpenVPN 2.6.22 and earlier and 2.7.6 and earlier, urging administrators to apply updates.

The Canadian Centre for Cyber Security issued advisory AV26-889 noting that OpenVPN versions up to and including 2.6.22 and 2.7.6 are affected by CVE-2026-84732. The flaw involves unbounded TLS timeouts and acknowledgements for non-outstanding packets in the reliability layer. Administrators are encouraged to review the linked OpenVPN guidance and apply updates as they become available. No exploitation is reported.