Warning: Critical vulnerability in OpenVPN client and a validation bypass vulnerability in OpenVPN server, Patch immediately!
ID: 42b8c47d-8e1d-5d15-b189-e3f791380e2b
STIX ID: report--42b8c47d-8e1d-5d15-b189-e3f791380e2b
Feed Name: CCB Advisories Feed
Threat Score
OpenVPN published security advisories for two vulnerabilities: CVE-2025-12106 (heap buffer over-read allowing denial-of-service / potential remote impact; CVSS 9.1) affecting OpenVPN client 2.7_alpha1–2.7_rc1 and server 2.6.0–2.6.15 and 2.7_alpha1–2.7_rc1, and CVE-2025-13086 (source IP validation bypass) which may allow bypassing server-side checks. The advisory recommends prioritizing patches, increasing monitoring/detection, and reporting incidents to the national CERT.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
