Denial of Service Vulnerability in OpenVPN by OpenVPN Technologies
CVE-2026-84732

8.7HIGH

Key Information:

Vendor

Openvpn

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-84732?

CVE-2026-84732 is a Denial of Service (DoS) vulnerability affecting OpenVPN, a widely used open-source software solution that facilitates secure point-to-point or site-to-site connections in routed or bridged configurations. The vulnerability arises from the mishandling of retransmissions of acknowledgment (ACK) packet IDs in specific versions of OpenVPN (2.6.22 and 2.7.6). When exploited, this flaw allows remote attackers to send specially crafted input that can trigger a timeout integer overflow, leading to service disruptions. The negative impact on organizations could be significant, as such an attack may lead to interruption of VPN services, making secure communications inaccessible and potentially exposing sensitive data.

Potential impact of CVE-2026-84732

  1. Service Disruption: Successful exploitation of this vulnerability could result in prolonged interruptions of VPN services, impacting users who rely on OpenVPN for secure communications and connectivity.

  2. Increased Operational Costs: Organizations may face increased costs in addressing the downtime caused by this vulnerability, including potential loss of revenue and additional resources required for remediation and recovery.

  3. Reputation Damage: Affected organizations may experience damage to their reputation as reliability and security are critical factors for users relying on VPN services. Prolonged outages can lead to a loss of customer trust and confidence.

Affected Version(s)

OpenVPN 0 <= 2.6.22

OpenVPN 0 <= 2.7.6

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.