logo

Warning: Critical vulnerability in OpenVPN client and a validation bypass vulnerability in OpenVPN server, Patch immediately!

ID: 42b8c47d-8e1d-5d15-b189-e3f791380e2b

STIX ID: report--42b8c47d-8e1d-5d15-b189-e3f791380e2b

Feed Name: CCB Advisories Feed

Threat Score
78/100

Date Published: 2025-12-02

Date Updated: 2026-07-24

...
...

OpenVPN published security advisories for two vulnerabilities: CVE-2025-12106 (heap buffer over-read allowing denial-of-service / potential remote impact; CVSS 9.1) affecting OpenVPN client 2.7_alpha1–2.7_rc1 and server 2.6.0–2.6.15 and 2.7_alpha1–2.7_rc1, and CVE-2025-13086 (source IP validation bypass) which may allow bypassing server-side checks. The advisory recommends prioritizing patches, increasing monitoring/detection, and reporting incidents to the national CERT.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.