Out-of-Bounds Write Vulnerability in OpenVPN on Windows
CVE-2026-81738

2.3LOW

Key Information:

Vendor

Openvpn

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-81738?

A vulnerability in OpenVPN versions 2.5.0 through 2.7.6 on Windows allows attackers to exploit the tap-windows6 driver. By crafting specific DOMAIN-SEARCH entries, an out-of-bounds write can be triggered, potentially compromising the system's integrity and security. Users are advised to update their OpenVPN installations to mitigate potential risks.

Affected Version(s)

OpenVPN Windows 2.5.0 <= 2.7.6

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.