← Back to news

OpenSSL issued security updates to fix 12 flaws, including Remote Code Execution

Security Affairs29/01/2026, 08:35
Read full article →

Summary

AI-Generated

Key Points:

  • OpenSSL has released security updates addressing 12 vulnerabilities, including two critical remote code execution (RCE) flaws.
  • The vulnerabilities primarily affect OpenSSL versions 3.0–3.6 and can lead to denial of service (DoS) or RCE, impacting systems that utilize the library for cryptographic functions.
  • It is recommended to update OpenSSL to the latest version immediately to mitigate these vulnerabilities and ensure secure operations.

Technical Details: The most severe vulnerabilities are CVE‑2025‑15467, which allows for a stack overflow during AEAD parsing, and CVE‑2025‑11187, which involves a stack overflow in PBMAC1 during MAC verification. Both can potentially lead to RCE under specific conditions.

MITRE ATT&CK Techniques: None mentioned

IOCs Mentioned: None mentioned

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.