OpenSSL fixes high-severity PKCS#7 use-after-free and broad library flaws
OpenSSL disclosed a broad set of vulnerabilities affecting ASN.1 parsing, PKCS#12, CMS/PKCS#7, QUIC, OCSP, CMP/CRMF, DH key validation, AEAD cipher handling, and certificate and email validation across the 4.0, 3.6, 3.5, 3.4, and 3.0 branches. The most severe issue, CVE-2026-45447, is a high-severity heap use-after-free in PKCS7_verify() that can be triggered by specially crafted PKCS#7 or S/MIME signed messages and could lead to crashes, heap corruption, or potentially remote code execution.
The advisory also details moderate-severity flaws that could enable forged CMS AuthEnvelopedData messages, denial-of-service conditions in QUIC and OCSP processing, a TLS client double-free via OCSP stapling, a QUIC server NULL dereference, and cryptographic failures in AES-OCB when applications use the EVP_Cipher() one-shot API, alongside numerous lower-severity parsing, validation, and bounds-checking bugs. OpenSSL said most issues were fixed in 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21, with 1.1.1zh and 1.0.2zq issued for supported legacy customers; most flaws were reported as outside the OpenSSL FIPS module boundary, except CVE-2026-42770, which affects FIPS modules in multiple supported branches.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
2 events from the most recent confirmed update back to the earliest known activity.
OpenSSL releases patched versions for affected branches
The advisory states that fixes were made available in OpenSSL 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21, with 1.1.1zh and 1.0.2zq also provided for older premium-support branches where applicable. OpenSSL recommended upgrading to these versions to address the disclosed flaws.
OpenSSL discloses multiple vulnerabilities in security advisory
On 2026-06-09, OpenSSL published a security advisory covering numerous vulnerabilities across PKCS#7, CMS, QUIC, OCSP, ASN.1, PKCS#12, CMP/CRMF, DH key validation, AEAD cipher handling, and certificate/email validation. The most severe issue disclosed was CVE-2026-45447, a high-severity heap use-after-free in PKCS7_verify() that could lead to crashes, heap corruption, or potentially remote code execution.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
7 references tracked. Mallory keeps watching after this page renders.
Critical OpenSSL Vulnerabilities Enables Remote Code Execution Attacks
cybersecuritynews.com
Open sourceOpenSSL Security Patches Fix Remote Code Execution Risk
securityonline.info
Open source[no-title]
openssl-library.org
Open sourceVulnerabilities 4.0 | OpenSSL Library
openssl-library.org
Open sourceCVE-2026-7383 - Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion
cvefeed.io
Open source[no-title]
freebsd.org
Open sourceoss-sec: OpenSSL Security Advisory
seclists.org
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


