CVE-2025-15467Patch(openssl / openssl)

CRITICALCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 18 mentions and remains active

Immediate actions

  • Patch openssl openssl systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs. Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue. OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787CWE-120

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssl

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 75 mentions across 26 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 8 signals
  • Patch or workaround mentioned in 35 signals
  • Technical details provided in 55 signals
  • Disclosure: 23 classified signals
  • General: 10 classified signals
  • Peaked 24d ago at 18 mentions (2026-01-28); latest day: 1
  • 75 total mentions across 26 days

Affected systems

Vendors
Products
openssl

Deep dive

Activity timeline75 mentions / 26d
0591418Mentions · 2026-01-27: 5Mentions · 2026-01-28: 18Mentions · 2026-01-29: 11Mentions · 2026-01-30: 11Mentions · 2026-01-31: 2Mentions · 2026-02-01: 1Mentions · 2026-02-03: 4Mentions · 2026-02-04: 2Mentions · 2026-02-09: 1Mentions · 2026-02-17: 1Mentions · 2026-02-18: 1Mentions · 2026-02-19: 1Mentions · 2026-02-23: 1Mentions · 2026-02-26: 2Mentions · 2026-03-06: 1Mentions · 2026-03-11: 2Mentions · 2026-03-15: 1Mentions · 2026-03-19: 1Mentions · 2026-03-24: 1Mentions · 2026-05-08: 1Mentions · 2026-06-23: 1Mentions · 2026-06-24: 1Mentions · 2026-07-28: 1Mentions · 2026-07-29: 1Mentions · 2026-07-30: 2Mentions · 2026-08-04: 1PoC Mentioned / Linked · 2026-01-27: 1PoC Mentioned / Linked · 2026-01-29: 2PoC Mentioned / Linked · 2026-02-03: 3PoC Mentioned / Linked · 2026-02-26: 1PoC Mentioned / Linked · 2026-05-08: 1Exploit Tool / Code · 2026-01-28: 1Exploit Tool / Code · 2026-01-29: 1Exploit Tool / Code · 2026-02-03: 2Exploit Tool / Code · 2026-05-08: 1Active Exploitation · 2026-02-26: 1Active Exploitation · 2026-03-19: 1Patch / Workaround · 2026-01-27: 3Patch / Workaround · 2026-01-28: 12Patch / Workaround · 2026-01-29: 7Patch / Workaround · 2026-01-30: 4Patch / Workaround · 2026-02-03: 1Patch / Workaround · 2026-02-04: 2Patch / Workaround · 2026-02-18: 1Patch / Workaround · 2026-03-06: 1Patch / Workaround · 2026-07-28: 1Patch / Workaround · 2026-07-29: 1Patch / Workaround · 2026-07-30: 1Patch / Workaround · 2026-08-04: 1Technical Details · 2026-01-27: 3Technical Details · 2026-01-28: 16Technical Details · 2026-01-29: 8Technical Details · 2026-01-30: 10Technical Details · 2026-01-31: 1Technical Details · 2026-02-03: 2Technical Details · 2026-02-04: 2Technical Details · 2026-02-17: 1Technical Details · 2026-02-18: 1Technical Details · 2026-02-26: 2Technical Details · 2026-03-06: 1Technical Details · 2026-03-11: 2Technical Details · 2026-03-15: 1Technical Details · 2026-03-19: 1Technical Details · 2026-06-23: 1Technical Details · 2026-06-24: 1Technical Details · 2026-07-30: 201-2701-2901-3102-0302-0902-1802-2303-0603-1503-2406-2307-2807-3008-04
Signal classification5 categories
Patch
3344.0%
Disclosure
2330.7%
General
1013.3%
PoC
79.3%
Active Exploitation
22.7%
Referenced assets59 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-275
Disclosure2Patch2PoC1
2026-01-2818
Disclosure5General1Patch12
2026-01-2911
General2Patch7PoC2
2026-01-3011
Disclosure5General2Patch4
2026-01-312
Disclosure2
2026-02-011
General1
2026-02-034
Patch1PoC3
2026-02-042
Patch2
2026-02-091
General1
2026-02-171
Disclosure1
2026-02-181
Disclosure1
2026-02-191
General1
2026-02-231
Patch1
2026-02-262
Active Exploitation1General1
2026-03-061
Disclosure1
2026-03-112
Disclosure2
2026-03-151
Disclosure1
2026-03-191
Active Exploitation1
2026-03-241
Disclosure1
2026-05-081
PoC1
2026-06-231
Disclosure1
2026-06-241
Disclosure1
2026-07-281
Patch1
2026-07-291
Patch1
2026-07-302
General1Patch1
2026-08-041
Patch1
Full discourse20 posts
  • International Cyber Digest@IntCyberDigest
    PoC

    🚨 CRITICAL OPENSSL SECURITY ALERT 🚨 CVE-2025-15467 affects OpenSSL's processing of CMS/S/MIME messages. An unauthenticated remote attacker can cause DoS or execute code remotely by crafting a specific message. We estimate the CVSS score is 9.8. We developed a working PoC (!) and recommend updating to the latest version ASAP.

    Post summary

    The text warns about a critical OpenSSL CVE that permits remote code execution or DoS, shares a PoC, and urges immediate patching.

    71701474031573.1K
    92.4K followersView on X
  • JFrog Security@JFrogSecurity
    Patch

    ⚡ Potentially Critical RCE Vulnerability in OpenSSL - CVE-2025-15467 ⚡ The JFrog Security Research team is tracking a newly disclosed OpenSSL stack overflow vulnerability rated as High by OpenSSL, that may lead to remote code execution (RCE). This vulnerability was patched with other 11 moderate and low severity vulnerabilities. The stack overflow can be triggered by sending a crafted CMS AuthEnvelopedData message with malicious AEAD parameters. While no official CVSS score has been assigned yet, based on its characteristics, we assess it may be rated at least High or even Critical by NVD. Our team reproduced the issue by invoking the CMS_decrypt API directly, confirming that OpenSSL applications parsing untrusted CMS data via this API are vulnerable. Exploitation is also possible when using the `openssl cms` CLI to decrypt untrusted input. A contextual analysis scanner for this CVE is now available for JFrog Advanced Security customers:

    Post summary

    A recently disclosed OpenSSL stack overflow could lead to RCE; the vulnerability has been patched and technical details are outlined, with exploitation possible via CMS_decrypt API or the openssl CMS CLI.

    16135164.2K
    3.1K followersView on X
  • FOFA@fofabot
    Patch

    ⚠️⚠️ CVE-2025-15467 in OpenSSL allows for unauthenticated stack overflows via crafted CMS messages. Potential for Remote Code Execution (RCE) makes this a priority patch for sysadmins. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJPcGVuU1NMIg%3D%3D 🎯23M+ Results are found on the https://en.fofa.info nearly year. FOFA Query: app="OpenSSL" 🔖Refer: https://securityonline.info/pre-auth-rce-risk-openssl-patches-high-severity-stack-overflow-cve-2025-15467/ #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    CVE-2025-15467 triggers a stack overflow in OpenSSL that may allow remote code execution; a patch is urgently required for affected systems.

    010025122.5K
    13.6K followersView on X
  • Wazuh@wazuh
    Patch

    OpenSSL is affected by a critical stack buffer overflow CVE-2025-15467 in CMS parsing, which may cause DoS and potential RCE. It affected 3.x versions up to 3.6.0. Update to 3.0.19, 3.3.6, 3.4.4, 3.5.5, or 3.6.1. Read more: https://ow.ly/HcKz50Y7CHu https://t.co/UWa3E5tZMs

    Post summary

    OpenSSL CVE-2025-15467 is a critical stack buffer overflow that can cause DoS or RCE, affecting versions up to 3.6.0; users should update to the listed patched releases.

    01201821.1K
    7.8K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    CVE-2025-15467: OpenSSL CMS AuthEnvelopedData Stack Buffer Overflow PoC https://github.com/guiimoraes/CVE-2025-15467

    Post summary

    A proof‑of‑concept for CVE‑2025‑15467, a stack buffer overflow in OpenSSL’s CMS AuthEnvelopedData, has been published with a GitHub link to the exploit code.

    0501793.1K
    151.3K followersView on X
  • JFrog Security@JFrogSecurity
    General

    🔗 Full technical analysis: https://research.jfrog.com/post/potential-rce-vulnerabilityin-openssl-cve-2025-15467/

    Post summary

    The tweet points to a technical analysis article about CVE‑2025‑15467 but provides no additional details, PoC, exploit code, or mitigation information.

    0501641.9K
    3.1K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    OpenSSL Security Advisory 27th January 2026 https://www.openwall.com/lists/oss-security/2026/01/27/7 12 CVEs, 2 stack-based buffer overflows CVE-2025-15467 Stack buffer overflow in CMS AuthEnvelopedData parsing (High) CVE-2025-11187 Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (Moderate)

    Post summary

    The advisory announces 12 CVEs in OpenSSL, highlighting two stack‑based buffer overflows with severity ratings, but contains no PoC, exploit code, active exploitation claims, or patch information.

    0401441.9K
    4.4K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    OpenSSLで複数の脆弱性が修正。最も深刻なのはスタックバッファオーバーフローのCVE-2025-15467。有償サポートのみになっている1.x系列でも一部脆弱性は修正あり。 https://securityonline.info/pre-auth-rce-risk-openssl-patches-high-severity-stack-overflow-cve-2025-15467/

    Post summary

    OpenSSL has released patches for multiple vulnerabilities, most notably the stack buffer overflow CVE‑2025‑15467. The 1.x series now receives some fixes, with no evidence of PoC, exploit tool, or active exploitation.

    0201431.4K
    7.2K followersView on X
  • Mr. OS@ksg93rd
    General

    #AppSec #Threat_Research 1⃣ Abusing Cortex XDR Live https://labs.infoguard.ch/posts/abusing_cortex_xdr_live_response_as_c2 2⃣ Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability (CVE-2026-20127) https://blog.talosintelligence.com/uat-8616-sd-wan 3⃣ OpenSSL Vulnerability (CVE-2025-15467) https://seclists.org/oss-sec/2026/q1/220

    Post summary

    The post enumerates three recent CVEs with links to detailed reports, but it does not provide evidence of active exploitation, patches, or exploit code.

    03096526
    3.1K followersView on X
  • mRr3b00t@UK_Daniel_Card
    PoC

    A good example of where a CVSS base score might be high but where it might otherwise not be exploitable: https://github.com/mr-r3b00t/CVE-2025-15467

    Post summary

    The tweet points to a GitHub repository that appears to host a Proof of Concept for CVE‑2025‑15467, but no additional exploit details or vulnerability specifics are provided.

    120621.2K
    119.7K followersView on X
  • Giuseppe `N3mes1s`@N3mes1s
    General

    Just testing the new #pruva autonomous reproduction platform against CVE-2025-15467: Stack Buffer Overflow in CMS AuthEnvelopedData Parsing from @Aisle_Inc almost ready for the public :D #autonomousreproductions https://t.co/6WWzz1huyZ

    Post summary

    The text announces that a new autonomous reproduction platform is being tested against CVE-2025-15467, a stack buffer overflow, but does not provide a PoC, exploit, patch, or evidence of active exploitation.

    010711.4K
    12.8K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    A vulnerability with the potential to enable remote code execution under specific conditions, on OpenSSL (CVE-2025-15467) https://aisle.com/blog/aisle-discovered-12-out-of-12-openssl-vulnerabilities

    Post summary

    The text announces a new OpenSSL flaw (CVE-2025-15467) that could enable remote code execution under specific conditions, linking to a blog that discusses 12 related vulnerabilities.

    000351.2K
    151.4K followersView on X
  • Michał Sajdak@sajdoor
    General

    A tu więcej info: https://aisle.com/blog/openssl-stack-overflow-cve-2025-15467-deep-dive

    Post summary

    The text supplies a link to a blog post about CVE‑2025‑15467 but does not provide additional details about the vulnerability, exploitation, or mitigation.

    010501.1K
    7.0K followersView on X
  • Nana Grant CISSP, CISM@SierraSec_NG
    Disclosure

    How I Discovered OpenSSL Zero-Days That Weaponize MTN Ghana & Nigeria's Existing Breaches In January 2026, I found 12/12 OpenSSL zero-days (CVE-2025-15467: HIGH remote stack overflow pre-authentication). Some bugs lurked since 1998. OpenSSL encrypts about 2/3 of internet traffic, including MTN's MoMo transactions. MTN Ghana (April 2025) suffered a breach of about 5,700 customer records. CSEAG flagged potential insider involvement. MoMo fraud is rising as agents operate in open spaces. Y'ello Protect 419, launched in February 2026, is a reactive fraud hotline because prevention failed. @MTNGhana

    Post summary

    The author announces the discovery of a high‑severity OpenSSL zero‑day (CVE‑2025‑15467) capable of remote stack overflows before authentication, but does not provide PoC code, exploitation evidence, or patch information.

    01012241
    3.8K followersView on X
  • Stanislav Fort@stanislavfort
    Disclosure

    HIGH severity CVEs in OpenSSL average less than 1 per year. This release includes one & we discovered it: CVE-2025-15467 A stack buffer overflow that requires no authentication. Parsing untrusted CMS content could be vulnerable. Pre-auth remote code execution in OpenSSL is wild

    Post summary

    The text announces a newly discovered CVE-2025-15467 in OpenSSL, describing a stack buffer overflow that allows unauthenticated remote code execution via malicious CMS content. No exploitation evidence, patch, PoC, or tool is provided.

    10030629
    15.2K followersView on X
  • Günter Born@etguenni
    PoC

    OpenSSL-Schwachstelle - PoC verfügbar https://borncity.com/blog/2026/01/29/openssl-schwachstelle-cve-2025-15467-poc-verfuegbar/

    Post summary

    A blog post announces that a Proof of Concept for the OpenSSL CVE‑2025‑15467 vulnerability is available, but does not provide technical details, patch information, or evidence of active exploitation.

    02020465
    2.6K followersView on X
  • Marci Ujlaki@UjlakiMarci
    Patch

    when OpenSSL releases a patch for a high severity vulnerability, that usually means we have to pay attention 🟥 CVE-2025-15467, CVSS: 9.8 (Critical) OpenSSL versions 3.6, 3.5, 3.4, 3.3, and 3.0, OpenSSL. critical stack buffer overflow vulnerability attackers can exploit this by sending crafted CMS messages, potentially leading to denial of service or remote code execution the vulnerability affects applications parsing untrusted CMS or PKCS#7 content using AEAD ciphers without requiring valid key material update available https://openssl-library.org/news/secadv/20260127.txt

    Post summary

    OpenSSL released a patch for CVE‑2025‑15467, a critical stack buffer overflow that could allow remote code execution via crafted CMS messages, and the update is immediately available.

    11001328
    344 followersView on X
  • Lyiase@lyiase
    General

    CVE-2025-15467 (OpenSSL 3系のS/MIMEの脆弱性)に対応しているDocker公式Rubyイメージがまだないんだがどういうことや…。

    Post summary

    The user notes that Docker’s official Ruby image still lacks a fix for CVE‑2025‑15467, an OpenSSL 3 S/MIME vulnerability.

    11001330
    4.1K followersView on X
  • JFrog@jfrog
    Patch

    🚨Security Update: Not all patches are created equal and this OpenSSL stack overflow (CVE-2025-15467) is a high-priority fix. Learn why this #vulnerability is uniquely dangerous, how it exploits the CMS AuthEnvelopedData structure, and get the technical roadmap to verify if your applications are exposed. Stay ahead of the threat: https://bit.ly/45EJi0P #CVE

    Post summary

    The tweet announces a high‑priority patch for OpenSSL CVE‑2025‑15467, describing a stack overflow in the CMS AuthEnvelopedData structure and directing readers to a link for verification.

    01020371
    23.1K followersView on X
  • Dr.Mashari@GMashari
    Patch

    📌 ثغرات حرجة في OpenSSL تمكّن المهاجمين عن بُعد من تنفيذ تعليمات خبيثة 🛡️ الفئة: ثغرة 📝 الملخص: أصدرت OpenSSL تحديثاً لمعالجة 12 ثغرة، أبرزها الثغرة عالية الخطورة CVE-2025-15467 التي تسمح بتنفيذ تعليمات برمجية عن بُعد (RCE) عبر استغلال تجاوز سعة المكدس (Stack Overflow) أثناء تحليل بيانات CMS AuthEnvelopedData غير الموثوق بها. تستغل الثغرة إدخال معلمات ASN.1 ضخمة الحجم لتجاوز حدود الذاكرة قبل التحقق من المصادقة، ما يعرض التطبيقات التي تتعامل مع بيانات S/MIME أو PKCS#7 للخطر الشديد. تمتد الثغرات المكتشفة لتشمل الإصدارات من 3.6 وصولاً إلى 1.0.2، وتتسبب معظمها في حرمان الخدمة (DoS) أو تجاوزات في المخازن المؤقتة ضمن آليات PKCS#12. يُنصح بالتحديث الفوري لجميع الإصدارات المتأثرة (مثل 3.6.1، 3.5.5، 3.0.19) لصد محاولات الاستغلال عن بُعد. 📍 تفاصيل فنية: 🎯 الهدف: تنفيذ تعليمات عن بعد (RCE) واستهداف تطبيقات تحليل بيانات التشفير (S/MIME، CMS). 🧠 التقنية المستخدمة: استغلال تجاوز سعة المكدس (Stack Overflow) عبر معلمات ASN.1. 🚨 الإجراء المتخذ: إصدار تحديثات عاجلة للإصدارات 3.6.1 و 3.5.5 و 3.0.19 وغيرها. 🛑 التوصيات الأمنية: الترقية الفورية وتجنب تحليل مدخلات PKCS#12/CMS غير الموثوق بها. 🗓️ تاريخ النشر: 28/01/2026 🔗 للمزيد: https://cybersecuritynews.com/openssl-vulnerabilities-code-execution/

    Post summary

    The text announces OpenSSL’s patch for CVE‑2025‑15467, detailing the stack overflow vulnerability and urging immediate update to affected versions.

    01020248
    9.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensslopenssl---

Explore more