ZeroHour
Canadian Centre for Cyber Securitypublished ()ingested Canadian Centre for Cyber Security

OpenVPN security advisory (AV26-889)

lowAdvisoryimportance 15CVE-2026-84732
AI summary · glm-5.3-flash

Canada's Cyber Centre advisory AV26-889 flags CVE-2026-84732 in OpenVPN 2.6.22 and earlier and 2.7.6 and earlier, urging administrators to apply updates.

The Canadian Centre for Cyber Security issued advisory AV26-889 noting that OpenVPN versions up to and including 2.6.22 and 2.7.6 are affected by CVE-2026-84732. The flaw involves unbounded TLS timeouts and acknowledgements for non-outstanding packets in the reliability layer. Administrators are encouraged to review the linked OpenVPN guidance and apply updates as they become available. No exploitation is reported.

  • CVE-2026-84732 affects OpenVPN up to 2.6.22 and 2.7.6
  • Flaw involves unbounded TLS timeout and ACKs for non-outstanding packets
  • CCCS urges users to review OpenVPN guidance and patch
  • No exploitation or severity details provided
VendorsOpenVPN
ProductsOpenVPN
CountriesCanada

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-84732
Unauthenticated denial of service in OpenVPN 2.6/2.7 via ACK packet-ID integer overflow

OpenVPN versions through 2.6.22 and through 2.7.6 contain an integer overflow (CWE-190) in the retransmission handling of ACK packet IDs, which can cause a timeout value to wrap. A remote, unauthenticated attacker who can reach a listening OpenVPN service can send crafted inputs that trigger the overflow, causing the service to time out or fail and disrupting VPN connectivity. The impact is availability-only; the CVSS 4.0 vector shows no confidentiality or integrity impact to the tunnel or data. All deployments running affected 2.6.x releases up to and including 2.6.22, or 2.7.x releases up to and including 2.7.6, are potentially exposed. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only a 0.5% probability of exploitation in the next 30 days.

Do: Upgrade OpenVPN servers and clients to a fixed 2.6-series release newer than 2.6.22 or a fixed 2.7-series release newer than 2.7.6, per the OpenVPN security advisory (AV26-889). Until patched, restrict exposure of OpenVPN service ports to trusted source networks and monitor for unexpected process crashes or restarts. Operators of third-party products (appliances, router firmware) that bundle affected OpenVPN versions should apply vendor updates when they ship fixes.

8.7<1%
  • OpenVPN (OpenVPN project / [email protected]) OpenVPN VPN server/client 2.6.x through and including 2.6.22
  • OpenVPN (OpenVPN project / [email protected]) OpenVPN VPN server/client 2.7.x through and including 2.7.6
masslikely millions of installations (OpenVPN is among the most widely deployed open-source VPNs, with on the order of hundreds of thousands of OpenVPN services…
Full article74 words · extracted from cyber.gc.ca · click to collapse

Serial Number: AV26-889
Date: September 8, 2026

As of September 7, 2026, OpenVPN is affected by vulnerabilities in the following product:

  • OpenVPN
    • Prior to or equal to 2.6.22
    • Prior to or equal to 2.7.6

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/openvpn-security-advisory-av26-889