Known Vulnerabilities for OpenVPN by Openvpn
Listed below are 10 of the newest known vulnerabilities associated with "OpenVPN" by "Openvpn".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-73973 json | Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0.0, c... | Not Provided | 2026-08-18 | 2026-08-19 |
| CVE-2026-72841 json | luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to ... | Not Provided | 2026-08-13 | 2026-08-18 |
| CVE-2026-71993 json | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that all... | Not Provided | 2026-08-09 | 2026-08-11 |
| CVE-2026-63650 json | OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configur... | Not Provided | 2026-08-14 | 2026-08-17 |
| CVE-2026-63649 json | The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users... | Not Provided | 2026-08-14 | 2026-08-17 |
| CVE-2026-58000 json | luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the generateKey ubu... | Not Provided | 2026-06-29 | 2026-07-14 |
| CVE-2026-45918 json | In the Linux kernel, the following vulnerability has been resolved: ovpn: tcp - don't deref NULL sk_socket member after tcp_... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2026-40215 json | A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a ... | Not Provided | 2026-06-08 | 2026-06-16 |
| CVE-2026-35058 json | Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 throug... | Not Provided | 2026-06-08 | 2026-06-08 |
| CVE-2026-19586 json | A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an Ope... | Not Provided | 2026-08-20 | 2026-08-21 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Openvpn | Openvpn | 2.8.3 | |||
| Application | Openvpn | Openvpn | 2.8.1 | |||
| Application | Openvpn | Openvpn | 2.8.0 | |||
| Application | Openvpn | Openvpn | 2.7.5 | |||
| Application | Openvpn | Openvpn | 2.7.4 | |||
| Application | Openvpn | Openvpn | 2.7.3 | |||
| Application | Openvpn | Openvpn | 2.7.0 | |||
| Application | Openvpn | Openvpn | 2.6.1 | |||
| Application | Openvpn | Openvpn | 2.5.2 | |||
| Application | Openvpn | Openvpn | 2.5.0 | |||
| Application | Openvpn | Openvpn | 2.4.9 | |||
| Application | Openvpn | Openvpn | 2.4.8 | |||
| Application | Openvpn | Openvpn | 2.4.7 | |||
| Application | Openvpn | Openvpn | 2.4.6 | |||
| Application | Openvpn | Openvpn | 2.4.5 | |||
| Application | Openvpn | Openvpn | 2.4.4 | |||
| Application | Openvpn | Openvpn | 2.4.3 | |||
| Application | Openvpn | Openvpn | 2.4.2 | |||
| Application | Openvpn | Openvpn | 2.4.1 | |||
| Application | Openvpn | Openvpn | 2.4.0 |