INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Memory

| 2026-09-30 06:55 CRITICAL LOW VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
A high-severity OpenSSL flaw, tracked as CVE-2026-84782, was discovered on August 17 and fixed in versions 4.0.3, 3.6.5, 3.5.9, and 3.4.8 by September 30. The vulnerability affects software using OpenSSL for DTLS, potentially leaking heap memory to the other side of a connection or causing a crash when sending a resend message while another part of the handshake is stuck. As of September 29, CISA gave the flaw a CVSS score of 8.2 out of 10, rating its impact on confidentiality Low and availability High; no exploitation was reported at that time. The affected software versions include OpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1, and 1.0.2, with fixed versions available for some branches only to customers who pay for premium support; the flaw does not limit itself to DTLS clients or servers.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-89102, CVE-2026-84782 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-89102CVE-2026-89102 CVE-2026-84782CVE-2026-84782 CVE-2026-75806CVE-2026-75806 CVE-2026-93302CVE-2026-93302 CVE-2026-89136CVE-2026-89136 CVE-2026-84783CVE-2026-84783
Target & Sectors
Global Scope
Incident Timeline
‎August 17
Laurent Gaffie of Secorizon reported a high-severity vulnerability in OpenSSL and WolfSSL on August 17.
‎August 25
OpenSSL 3.0 users who installed the August 25, 2022 public release (version 3.0.22) are advised to apply available patches for high-severity vulnerabilities.
infrastructure 3.0
general_metric 3.0 OpenSSL
infrastructure 3.0.22
victims 3.0 Users
‎September 7, 2026
Public support for OpenSSL version 1.1.1zj ended on September 7, 2026.
infrastructure 1.1.1
infrastructure 1.1
‎September 7
OpenSSL 3.0 stopped receiving public security fixes on September 7, marking the end of its support period.
general_metric 3.0 OpenSSL
‎September 25
WolfSSL developers released version 5.9.4 on September 25, addressing high-severity vulnerabilities in the software.
infrastructure 5.9.4
‎September 29
Threat actors did not explicitly target any entities in the provided snippet, but a High-severity OpenSSL flaw (CVE-2026-84782) was disclosed on September 29.
vulnerability CVSS score of 8.2
infrastructure 26.04
infrastructure 3.5.5-1ubuntu3
infrastructure 24.04
infrastructure 3.0.13-0ubuntu3
infrastructure 22.04
infrastructure 3.0.2-0ubuntu1
general_metric 26.04 Ubuntu LTS
general_metric 24.04 libssl3t64 Ubuntu LTS
general_metric 22.04 LTS
vulnerability CVE-2026-84782
general_metric 14 vulnerabilities
general_metric 6 Entities
general_metric 13 Debian
‎September 30
Debian 12 remained listed as vulnerable to high-severity vulnerabilities in OpenSSL and WolfSSL until at least September 30.
general_metric 12 Debian
‎2026/09/30
Threat actors could exploit the DTLS 1.2 vulnerability, CVE-2026-84782, to crash a multi-threaded TLS client and cause a denial-of-service (DoS) condition by sending data that is accepted as authentic through an AEAD cipher suite in established connections using Raw Public Key support enabled by selecting an RPK certificate type the client never requested.
organisation CRL
organisation DTLS
organisation IoT
infrastructure 4.0.3
infrastructure 3.6.5
infrastructure 3.5.9
infrastructure 3.4.8
organisation CVSS
organisation CVE-2026
organisation Raw Public Key
organisation RPK
organisation DoS
organisation TLS
organisation UDP
organisation CPU
organisation AEAD
organisation Nginx
organisation HAProxy
organisation Stunnel
organisation API
infrastructure 4.0
infrastructure 3.0
infrastructure 1.1.1
infrastructure 1.0.2
infrastructure 3.6
infrastructure 3.5
infrastructure 3.4
infrastructure 3.0.23
infrastructure 3.5.7-1
financial 1 DSA-6531
organisation Ubuntu
‎October 22, 2026
The OpenSSL project released a new long-term support version, 3.4.8, which is publicly available for download and supported until October 22, 2026.
‎November 1, 2026
The OpenSSL and WolfSSL libraries were made publicly available for download, with specific versions supported until November 1, 2026.
‎May 14, 2027
The OpenSSL and WolfSSL libraries have been patched with a new version, 4.0.3 for the former and 3.6.5 for the latter, which are publicly available for download until May 14, 2027 and November 1, 2026 respectively.
‎April 8, 2030
The OpenSSL and WolfSSL projects released a long-term support version, supported until April 8, 2030.
Tactical Metrics
Metrics
infrastructure
‎5.9.4
Software Version
Metrics
infrastructure
‎4.0.3
Software Version
Metrics
infrastructure
‎3.6.5
Software Version
Metrics
infrastructure
‎3.5.9
Software Version
Metrics
infrastructure
‎3.4.8
Software Version
Metrics
infrastructure
‎3.0
Software Version
Metrics
infrastructure
‎1.1.1
Software Version
Metrics
infrastructure
‎1.0.2
Software Version
Metrics
infrastructure
‎4.0
Software Version
Metrics
infrastructure
‎3.6
Software Version
Metrics
infrastructure
‎3.5
Software Version
Metrics
infrastructure
‎3.4
Software Version
Metrics
infrastructure
‎3.0.23
Software Version
Metrics
infrastructure
‎1.1
Software Version
Metrics
infrastructure
‎26.04
Software Version
Metrics
infrastructure
‎3.5.5-1ubuntu3
Software Version
Metrics
infrastructure
‎24.04
Software Version
Metrics
infrastructure
‎3.0.13-0ubuntu3
Software Version
Metrics
infrastructure
‎22.04
Software Version
Metrics
infrastructure
‎3.0.2-0ubuntu1
Software Version
Metrics
infrastructure
‎3.5.7-1
Software Version
Metrics
financial
1
Dsa-6531
Metrics
infrastructure
‎3.0.22
Software Version
Metrics
victims
3
Users
Intelligence Sources