logo

OpenSSL Security Patches Fix Remote Code Execution Risk

ID: 403ce355-abd1-5cfb-ac63-a576a5aedf97

STIX ID: report--403ce355-abd1-5cfb-ac63-a576a5aedf97

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-06-10

Date Updated: 2026-06-10

Author: Do Son

...
...

**Executive Summary:** This advisory details an emergency OpenSSL maintenance release addressing multiple high-severity vulnerabilities — most notably a PKCS#7/S/MIME use-after-free (CVE-2026-45447) that can be triggered remotely and may lead to remote code execution, an AES-OCB nonce-reuse flaw (CVE-2026-45445) that breaks confidentiality and enables forgery, and several QUIC/OCSP-related denial-of-service and memory corruption issues; administrators are urged to apply patches (e.g., 4.0.1 or supported 1.1.1 updates) and review dependency trees immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.