OpenSSL security advisory (AV26-846)
Canada's Cyber Centre relayed an OpenSSL advisory (AV26-846) covering vulnerabilities fixed across seven branches, urging users to update to patched releases.
Canadian Centre for Cyber Security bulletin AV26-846 states that OpenSSL is affected by vulnerabilities fixed in 1.0.2zr, 1.1.1zi, 3.0.22, 3.4.7, 3.5.8, 3.6.4, and 4.0.2. Given OpenSSL's ubiquity in TLS stacks, administrators should review the OpenSSL advisories and apply updates. The bulletin includes no exploitation details or CVE identifiers.
- Affected branches span 1.0.2, 1.1.1, 3.0, 3.4, 3.5, 3.6, and 4.0
- Patched versions: 1.0.2zr, 1.1.1zi, 3.0.22, 3.4.7, 3.5.8, 3.6.4, 4.0.2
- No exploit details or CVEs listed in the bulletin
Serial Number: AV26-846 Date: August 25, 2026 As of August 25, 2026, OpenSSL is affected by vulnerabilities in the following product: OpenSSL Prior to 1.0.2zr Prior to 1.1.1zi Prior to 3.0.22 Prior to 3.4.7 Prior to 3.5.8 Prior to 3.6.4 Prior to 4.0.2 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Vulnerabilities | OpenSSL Library
This source does not provide full text. Read it at cyber.gc.ca.