
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-84732 is a denial-of-service vulnerability in OpenVPN caused by a timeout integer overflow triggered through crafted ACK packet retransmissions. It affects OpenVPN versions through 2.6.22 and through 2.7.6, and allows remote unauthenticated attackers to crash or hang the OpenVPN service without any user interaction. The vulnerability was published on September 7, 2026, and is currently awaiting full NVD analysis. It carries a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Red Hat Bugzilla).
The root cause is an integer overflow or wraparound (CWE-190) in OpenVPN's handling of ACK packet ID retransmissions. When an attacker sends crafted ACK packets with specific retransmission patterns, the timeout calculation overflows, causing the service to enter an unresponsive or crashed state. The attack requires no authentication, no privileges, no user interaction, and no special network positioning — it is exploitable directly over the network with low complexity. This maps to CAPEC-92 (Forced Integer Overflow) (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation results in a denial of service, causing the OpenVPN service to crash or become unresponsive. This would disrupt all VPN tunnels relying on the affected server, potentially cutting off remote access for users and systems dependent on the VPN for connectivity. There is no evidence of confidentiality or integrity impact — the vulnerability is limited to availability, with a high impact on the vulnerable system and a low subsequent impact on dependent systems (GitHub Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment classifies exploitation as "none" at this time, though the attack is rated as automatable due to its network-accessible, unauthenticated nature. The EPSS score is approximately 0.54%, placing it in the 44th percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. A Nessus detection plugin (ID 342763) is available (Tenable).
/var/log/openvpn.log or equivalent.openvpn process; watchdog or init system logs (e.g., systemd) recording repeated service restarts in a short timeframe.Upgrade OpenVPN to a version newer than 2.6.22 (in the 2.6.x branch) or newer than 2.7.6 (in the 2.7.x branch) — OpenVPN 2.7.7 was released with fixes for this and six other security flaws (Linuxiac). Red Hat users should apply patches referenced in the Red Hat Bugzilla entry (Red Hat Bugzilla). FreeBSD ports have also been updated via the VuXML and openvpn port commits. As a temporary network-level workaround, restrict access to the OpenVPN port using firewall rules to trusted IP ranges to reduce exposure until patching is feasible.
The OpenVPN project published a security announcement addressing CVE-2026-84732 alongside six other vulnerabilities fixed in the 2.7.7 release (OpenVPN Community). Security news outlets including CyberSecurityNews and The Daily Tech Feed covered the broader OpenVPN 2.7.7 release, highlighting the seven security fixes (CyberSecurityNews). The Canadian Centre for Cyber Security (CCCS) issued advisory AV26-889 regarding the OpenVPN vulnerabilities (CCCS). Community discussion on the OpenVPN forums acknowledged the release and encouraged prompt upgrades (OpenVPN Forums).
Fix availability across major Linux distributions and their releases.
bionic (esm-infra)
openvpn
devel
openvpn
focal (esm-infra)
openvpn
jammy
openvpn
noble
openvpn
resolute
openvpn
trusty (esm-infra-legacy)
openvpn
xenial (esm-infra-legacy)
openvpn
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."