CVE-2026-84732
8.7OpenVPN · OpenVPN
OpenVPN contains an integer overflow in the handling of ACK packet ID retransmissions, allowing unauthenticated remote attackers to trigger a denial of service via crafted network inputs.
Executive summary
An unauthenticated remote denial of service vulnerability in OpenVPN allows attackers to crash the service by triggering a timeout integer overflow.
Vulnerability
This vulnerability involves an integer overflow condition within the retransmission logic of ACK packet IDs. By sending crafted inputs, an unauthenticated remote attacker can cause a timeout integer overflow, leading to a service crash.
Business impact
With a CVSS score of 8.7, this vulnerability poses a significant risk to network availability. A successful denial of service attack can disrupt critical remote access infrastructure, preventing legitimate users from connecting to internal resources and resulting in substantial operational downtime.
Remediation
Immediate Action: Update OpenVPN to version 2.7.7 or the corresponding 2.6.x security updates provided by the vendor.
Proactive Monitoring: Review system and application logs for unusual spikes in retransmission requests or sudden service terminations.
Compensating Controls: Use network level access controls to restrict OpenVPN traffic to known, trusted source IP addresses to minimize the attack surface.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this flaw necessitates immediate attention to maintain network resilience. Organizations should prioritize updating all instances of OpenVPN to the patched versions specified by the vendor to eliminate the risk of remote service disruption.