CVE-2026-13117Patch(openvpn / openvpn)

LOWCVSS 8.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch openvpn openvpn systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openvpn

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-06-27); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
openvpn

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-06-27: 1Mentions · 2026-07-04: 1Mentions · 2026-07-05: 1Mentions · 2026-07-10: 1PoC Mentioned / Linked · 2026-07-05: 1Patch / Workaround · 2026-07-04: 1Patch / Workaround · 2026-07-10: 1Technical Details · 2026-07-04: 1Technical Details · 2026-07-05: 106-2707-0407-0507-10
Signal classification3 categories
Patch
250.0%
General
125.0%
Disclosure
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-271
General1
2026-07-041
Patch1
2026-07-051
Disclosure1
2026-07-101
Patch1
Full discourse4 posts
  • trace37@trace37_labs
    Patch

    Latest CVE assigned to trace37. OpenVPN - A use-after-free in OpenVPN's tls-crypt-v2. The safety check meant to stop the server sending a client freed memory has a blind spot, so during a routine key renegotiation OpenVPN frees a buffer it's about to send — and hands whatever now sits in that memory to the client. Remediated by maintainer in version 2.7.5. https://labs.trace37.com/cves/cve-2026-13117/

    Post summary

    Trace37 reports a use‑after‑free flaw in OpenVPN's tls‑crypt‑v2, fixed in OpenVPN 2.7.5.

    0401681.8K
    1.0K followersView on X
  • ‍ ‍‍‍ᓭ cryptostorm ᓯ@cryptostorm_is
    Patch

    v4.01 of our Windows client is at https://cryptostorm.is/windows#widget See attached for client-side fixes. Servers were updated to OpenVPN 2.7.5 on the 2nd, and v4.01 bundles 2.7.5, so we're good on CVE-2026-12996, CVE-2026-13117, CVE-2026-12932, and CVE-2026-13698. https://t.co/7VvcXvxk70

    Post summary

    A new Windows client version 4.01 bundled with OpenVPN 2.7.5 is released, claiming to fix CVE‑2026‑12996, ‑13117, ‑12932, and ‑13698 through the update and attached client‑side fixes.

    000100830
    6.0K followersView on X
  • trace37@trace37_labs
    General

    And, another CVE for @trace37_labs CVE-2026-13117 Under embargo currently.

    Post summary

    The text only announces that CVE-2026-13117 for trace37_labs is under embargo, providing no further details.

    10040423
    999 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Disclosure

    🚨 #CVE-2026-13117: OpenVPN's tls-crypt-v2 Heap Use-After-Free — How a Single Blind Spot in a Safety Check Opens the Door to RCE + Video https://undercodetesting.com/cve-2026-13117-openvpns-tls-crypt-v2-heap-use-after-free-how-a-single-blind-spot-in-a-safety-check-opens-the-door-to-rce-video/ Educational Purposes!

    Post summary

    The article announces a new OpenVPN tls‑crypt‑v2 heap use‑after‑free flaw (CVE‑2026‑13117) that can cause remote code execution, includes a video demonstration, but provides no evidence of active exploitation, patches, or false‑positive status.

    0000059
    650 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenvpnopenvpn---

Explore more