Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
open-source-dependency-vulnerabilitywidely-deployed-product-advisorypatch-regressionendpoint-software-vulnerability

OpenSSL Releases Patch Multiple CVEs Across Supported Branches

Updated 2mo agoFirst seen Apr 8, 20264 sources

The OpenSSL Project released updated versions across multiple supported branches to fix a set of security flaws in the SSL/TLS toolkit, with OpenSSL 3.6.2 carrying the broadest set of patches. The updates address issues including incorrect failure handling in RSA KEM RSASVE encapsulation, an out-of-bounds read in AES-CFB-128 on x86-64 systems with AVX-512 support, a potential use-after-free in DANE client code, several NULL pointer dereference bugs, and a heap buffer overflow in hexadecimal conversion. OpenSSL said the most severe issue in the release was rated Moderate.

Additional releases — 3.5.6, 3.4.5, 3.3.7, 3.0.20, 1.1.1zg, and 1.0.2zp — also shipped with security fixes and minor bug corrections, though older branches received smaller subsets of the patches. The 3.6.2 release also repaired two regressions introduced in 3.6.0 affecting X509_V_FLAG_CRL_CHECK_ALL behavior and stapled OCSP response handling that could trigger handshake failures. Administrators running OpenSSL 3.6.x on x86-64 systems with AVX-512 enabled were specifically urged to prioritize the AES-CFB-128 fix because of memory-read exposure.

Share:
OpenSSL Releases Patch Multiple CVEs Across Supported Branches
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Apr 7, 20263mo ago

OpenSSL 3.6.2 patches multiple CVEs and 3.6.0 regressions

The 3.6.2 release fixed the broadest set of issues, including flaws in RSA KEM RSASVE failure handling, an AVX-512-related AES-CFB-128 out-of-bounds read, a DANE client use-after-free, several NULL dereferences, and a heap buffer overflow in hexadecimal conversion. It also repaired two regressions introduced in OpenSSL 3.6.0 affecting CRL checking behavior and stapled OCSP response handling.

OpenSSL releases 3.6.2 and other supported branch updates

On April 7, 2026, the OpenSSL Project released OpenSSL 3.6.2, 3.5.6, 3.4.5, 3.3.7, 3.0.20, 1.1.1zg, and 1.0.2zp to address multiple security vulnerabilities and minor bugs across supported branches.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

OpenSSL Releases Patch Multiple CVEs Across Supported Branches | Mallory