logo

27-Year-Old OpenBSD Vulnerability Exposed: Remote Auth Bypass Disclosed

ID: 5b532cd4-a33a-5818-9379-3375222ae43a

STIX ID: report--5b532cd4-a33a-5818-9379-3375222ae43a

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-06-17

Date Updated: 2026-06-24

...
...

A critical logic flaw in OpenBSD's sppp_pap_input() allows attackers to bypass PAP authentication and intercept PPPoE traffic. The bug, present since a 1999 FreeBSD import, was discovered by Argus-Systems and OpenBSD has released a patch; users are urged to apply it immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.