logo

OpenSSL January 2026 Security Update: CMS and PKCS#12 Buffer Overflows

ID: 3d33daf1-a5f1-5af7-b8bb-bb21f8a9c44f

STIX ID: report--3d33daf1-a5f1-5af7-b8bb-bb21f8a9c44f

Feed Name: Datadog Security Labs

Threat Score
65/100

Date Published: 2026-01-27

Date Updated: 2026-04-27

...
...

OpenSSL disclosed multiple vulnerabilities (including high-severity CVE-2025-15467 and moderate CVE-2025-11187) affecting 1.0.2, 1.1.1, and 3.x releases that allow crafted CMS or PKCS#12 inputs to cause crashes and, in one case, potential remote code execution; the advisory lists impacted versions, reproduction examples, affected attack surfaces (e.g., S/MIME gateways, certificate import services), and recommends upgrading runtimes that bundle OpenSSL while noting exploitability is constrained by platform mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.