Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-84732
OpenVPN vulnerability analysis and mitigation

Overview

CVE-2026-84732 is a denial-of-service vulnerability in OpenVPN caused by a timeout integer overflow triggered through crafted ACK packet retransmissions. It affects OpenVPN versions through 2.6.22 and through 2.7.6, and allows remote unauthenticated attackers to crash or hang the OpenVPN service without any user interaction. The vulnerability was published on September 7, 2026, and is currently awaiting full NVD analysis. It carries a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is an integer overflow or wraparound (CWE-190) in OpenVPN's handling of ACK packet ID retransmissions. When an attacker sends crafted ACK packets with specific retransmission patterns, the timeout calculation overflows, causing the service to enter an unresponsive or crashed state. The attack requires no authentication, no privileges, no user interaction, and no special network positioning — it is exploitable directly over the network with low complexity. This maps to CAPEC-92 (Forced Integer Overflow) (GitHub Advisory, Red Hat Bugzilla).

Impact

Successful exploitation results in a denial of service, causing the OpenVPN service to crash or become unresponsive. This would disrupt all VPN tunnels relying on the affected server, potentially cutting off remote access for users and systems dependent on the VPN for connectivity. There is no evidence of confidentiality or integrity impact — the vulnerability is limited to availability, with a high impact on the vulnerable system and a low subsequent impact on dependent systems (GitHub Advisory).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment classifies exploitation as "none" at this time, though the attack is rated as automatable due to its network-accessible, unauthenticated nature. The EPSS score is approximately 0.54%, placing it in the 44th percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. A Nessus detection plugin (ID 342763) is available (Tenable).

Exploitation steps

  1. Reconnaissance: Identify internet-facing OpenVPN servers running versions ≤2.6.22 or ≤2.7.6 using network scanning tools such as Shodan, Censys, or nmap targeting default OpenVPN ports (UDP/1194 or configured alternatives).
  2. Craft malicious ACK packets: Construct UDP packets containing ACK packet IDs with retransmission patterns designed to trigger the integer overflow in the timeout calculation logic.
  3. Send crafted packets: Transmit the malicious ACK retransmission packets to the target OpenVPN server. No authentication or prior session establishment is required.
  4. Trigger integer overflow: The server's timeout counter overflows due to the crafted inputs, causing the OpenVPN daemon to crash or enter an unresponsive state, resulting in denial of service for all connected clients.

Indicators of compromise

  • Network: Unusual volume of UDP packets targeting the OpenVPN port (default 1194) from a single or distributed source; repeated ACK packets with anomalous packet ID sequences or retransmission patterns.
  • Logs: OpenVPN daemon logs showing unexpected crashes, restarts, or timeout-related error messages; entries referencing packet ID handling failures or integer-related errors in /var/log/openvpn.log or equivalent.
  • Process: Unexpected termination or restart of the openvpn process; watchdog or init system logs (e.g., systemd) recording repeated service restarts in a short timeframe.

Mitigation and workarounds

Upgrade OpenVPN to a version newer than 2.6.22 (in the 2.6.x branch) or newer than 2.7.6 (in the 2.7.x branch) — OpenVPN 2.7.7 was released with fixes for this and six other security flaws (Linuxiac). Red Hat users should apply patches referenced in the Red Hat Bugzilla entry (Red Hat Bugzilla). FreeBSD ports have also been updated via the VuXML and openvpn port commits. As a temporary network-level workaround, restrict access to the OpenVPN port using firewall rules to trusted IP ranges to reduce exposure until patching is feasible.

Community reactions

The OpenVPN project published a security announcement addressing CVE-2026-84732 alongside six other vulnerabilities fixed in the 2.7.7 release (OpenVPN Community). Security news outlets including CyberSecurityNews and The Daily Tech Feed covered the broader OpenVPN 2.7.7 release, highlighting the seven security fixes (CyberSecurityNews). The Canadian Centre for Cyber Security (CCCS) issued advisory AV26-889 regarding the OpenVPN vulnerabilities (CCCS). Community discussion on the OpenVPN forums acknowledged the release and encouraged prompt upgrades (OpenVPN Forums).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

openvpn

Affected

sid

openvpn: 2.7.7-1

Fixed

trixie

openvpn

Affected

Ubuntu

Unknown

bionic (esm-infra)

openvpn

Unknown

devel

openvpn

Unknown

focal (esm-infra)

openvpn

Unknown

jammy

openvpn

Unknown

noble

openvpn

Unknown

resolute

openvpn

Unknown

trusty (esm-infra-legacy)

openvpn

Unknown

xenial (esm-infra-legacy)

openvpn

Unknown

Alpine

Fixed

edge

openvpn: 2.7.7-r0

Fixed

SourceThis report was generated using AI

Related OpenVPN vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-84732HIGH8.7
  • OpenVPN logoOpenVPN
  • openvpn-devel
NoYesSep 07, 2026
CVE-2026-84226HIGH8.5
  • OpenVPN logoOpenVPN
  • cpe:2.3:a:openvpn:openvpn
NoYesSep 07, 2026
CVE-2026-84256HIGH7.7
  • OpenVPN logoOpenVPN
  • cpe:2.3:a:openvpn:openvpn
NoYesSep 07, 2026
CVE-2026-82325MEDIUM6.8
  • OpenVPN logoOpenVPN
  • cpe:2.3:a:openvpn:openvpn
NoNoSep 07, 2026
CVE-2026-82312LOW1.8
  • OpenVPN logoOpenVPN
  • cpe:2.3:a:openvpn:openvpn
NoYesSep 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management